RuPaul's Drag Race Superstar Security & Privacy Scorecard
Android
Gaming activity and device identifiers are shared with over a dozen advertising networks including Facebook, AppLovin, Google AdMob, Unity Ads, and Chartboost. Analytics data flows through Firebase and Unity to track in-app behavior. Singular handles install attribution across these ad partners.
Best for
Casual racing fans comfortable with ad-supported gameplay
Findings
- 0 critical
- 0 high
- 1 medium
- 2 low
- 2 info
1 issue identified across security and privacy analysis.
Top security issues
- Unity Ads WebView Universal File Access Enabled with JavaScript Bridge
- Privacy Sandbox AdServices Configuration Grants Unrestricted Third-Party Access
- Extensive Third-Party Ad SDK Data Collection via 10+ Network Adapters
Top privacy issues
- Extensive Third-Party Ad SDK Data Collection via 10+ Network Adapters
- Facebook SDK Transmits In-App Purchase Amounts and Game Events to Meta
- Data Safety Form Declares Location Collection Without a Location Permission
Full analysis
RuPaul's Drag Race Superstar
What This Means for You
Your in-app purchases and gameplay activity may be shared with more than 10 advertising networks, including Meta, to serve you targeted ads across the broader ad ecosystem.
Recommendation: Trustworthy
Trustworthy choice for casual gamers. Well-protected by HTTPS and Google Play Integrity verification. Monetized through ads and purchase tracking, the standard for ad-supported games.
Best For: Casual mobile gamers comfortable with ad-supported entertainment
Key Findings
Data Security - 0 findings
Network Security - 1 finding (1 medium)
Code Safety - 0 findings
Privacy - 4 findings (2 low, 2 info)
Privacy Concerns
What Data is Collected
- Advertising identifier: shared with 10+ ad networks for targeting and measurement
- Gameplay events and app activity: shared with analytics and advertising services
- In-app purchase amounts and currency: shared with Meta and other ad partners
- Approximate location: may be inferred from your IP address by ad network servers, and cannot be revoked through Android's location permission controls
Third-Party Data Sharing
The following third parties may receive your data:
- AppLovin MAX - ad mediation platform coordinating multiple ad networks
- Meta (Facebook Audience Network) - advertising and in-app purchase event tracking
- Google AdMob - advertising
- Unity Ads - in-game video advertising
- IronSource (Unity LevelPlay) - advertising
- Vungle (Liftoff) - advertising
- Chartboost - advertising
- InMobi - advertising and IP-based location inference
- Mintegral - advertising
- Tapjoy - advertising
- Fyber/DT Exchange - advertising
- Singular - attribution and analytics
- Firebase (Google) - analytics, crash reporting, and cloud messaging
Understanding the Scores
Security: 88/100
Privacy: 79/100
Security Breakdown
- Data Security: 100/100 - Sensitive data is handled securely throughout the app.
- Network Security: 88/100 - All communications travel over HTTPS with strong protections. One ad SDK's embedded browser component uses a permissive file access configuration that could be tightened.
- Code Safety: 100/100 - The app's own code follows strong safety practices with no identified weaknesses.
Privacy Breakdown
- Data Collection: 79/100 - Advertising identifiers and behavioral data may be collected across 10+ ad network SDKs, which is typical for ad-supported games but represents a broad data footprint.
- Data Sharing: 82/100 - Purchase amounts and gameplay activity may be shared with several advertising partners, including Meta, for targeting and attribution.
- User Control: 82/100 - Android's Ad ID opt-out provides some control, though certain data flows through ad network servers may persist beyond that setting.
Positive Security Features
- All network traffic is encrypted using HTTPS
- Google Play Integrity API verifies device and app authenticity before sensitive operations
- Consent management infrastructure (AppLovin CMP) is present in the SDK bundle to support privacy regulation compliance
- SafeDK brand safety monitoring is active to filter ad content quality
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
Privacy Sandbox Access Controls
Restricting which ad SDKs can independently access Android's Topics, Custom Audiences, and Attribution APIs would give the developer more oversight of how interest-based profiles are built from your data, rather than allowing all 10+ embedded ad SDKs unrestricted access.Consent Flow Verification
The consent management infrastructure is present in the SDK bundle, but its invocation before ad SDK initialization could not be fully verified through code analysis. Confirming that consent is collected before any data collection begins would strengthen compliance for users in regulated regions.Location Disclosure Clarity
The Play Store Data Safety section declares location as a collected data type, but this refers to IP-based location inferred by ad network servers rather than GPS or network location controlled by Android permissions. Clearer disclosure would help users understand exactly what they can and cannot control.
Security Enhancements
Ad SDK Browser Component Configuration
Tightening the file access settings in the Unity Ads embedded browser component would reduce the theoretical risk of cross-origin file reads in the unlikely event that the ad network's configuration response were intercepted.Data Deletion Support
The Play Store Data Safety form indicates that collected data cannot be deleted upon user request. Providing a data deletion mechanism would improve user control and align with CCPA and GDPR requirements.
Technical Context
App Type: Lifestyle simulation game (Teen-rated, ad-supported with in-app purchases)
Classes Analyzed: Not available for this build
Third-Party Services: 26 identified
Context Tags: ads, gaming, financial
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
App Details
Developer: Eastside Games Inc
Version: 1.22.0 (versionCode 761)
Analysis Date: 2026-06-21
Package: com.eastsidegames.dragrace
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on APK version 1.22.0 analyzed on 2026-06-21
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 82/100 |