Scan results

    RuPaul's Drag Race Superstar

    Android

    RuPaul's Drag Race Superstar is a single-player simulation game featuring fashion, drag artistry, and entertainment. Build and manage your superstar through ads, in-app purchases, and engaging gameplay.

    NOT ASSESSED

    This app has an open trust check or a verdict held for review.

    The five trust checks

    CITT SCORE
    82
    out of 100
    NOT ASSESSED

    Quick Verdict

    Best for: Casual racing fans comfortable with ad-supported gameplay

    What It Means For You

    Gaming activity and device identifiers are shared with over a dozen advertising networks including Facebook, AppLovin, Google AdMob, Unity Ads, and Chartboost. Analytics data flows through Firebase and Unity to track in-app behavior. Singular handles install attribution across these ad partners.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (5)

    Network Security

    1 total
    1 Medium

    Privacy

    1 total
    1 Low

    Third-Party Risk

    3 total
    1 Low
    2 Info

    Third-Party Services

    Firebase Analytics, Firebase Remote Config, Firebase Crashlytics, Firebase Cloud Messaging, Firebase Installations, AppLovin MAX, Unity Ads, Facebook Audience Network, Facebook SDK, Vungle (Liftoff), Chartboost, IronSource (Unity LevelPlay), InMobi, Mintegral, Tapjoy, Fyber/DT Exchange, Google AdMob, Singular, SafeDK, IAB OMID, PairIP, Google Play Integrity, Google Play Games, Bugsnag, Unity Services Analytics, Unity Purchasing (IAP)

    Security Strengths

    • All network communications use HTTPS
    • Google Play Integrity attestation implemented for device and app verification
    • Digital Turbine auth token stored with AES-GCM encryption
    • AppLovin CMP (consent management) infrastructure present in SDK bundle
    • SafeDK brand safety monitoring active for ad content
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    ads
    gaming
    financial

    Package

    com.eastsidegames.dragrace

    Version

    1.22.0 (versionCode 761)

    Analysis Date

    Jun 21, 2026

    0

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Trustworthy

    Trustworthy choice for casual gamers. Well-protected by HTTPS and Google Play Integrity verification. Monetized through ads and purchase tracking, the standard for ad-supported games.

    Key Findings

    Data Security - 0 findings

    Network Security - 1 finding (1 medium)

    Code Safety - 0 findings

    Privacy - 4 findings (2 low, 2 info)

    Privacy Concerns

    What Data is Collected

    • Advertising identifier: shared with 10+ ad networks for targeting and measurement
    • Gameplay events and app activity: shared with analytics and advertising services
    • In-app purchase amounts and currency: shared with Meta and other ad partners
    • Approximate location: may be inferred from your IP address by ad network servers, and cannot be revoked through Android's location permission controls

    Third-Party Data Sharing

    The following third parties may receive your data:

    • AppLovin MAX - ad mediation platform coordinating multiple ad networks
    • Meta (Facebook Audience Network) - advertising and in-app purchase event tracking
    • Google AdMob - advertising
    • Unity Ads - in-game video advertising
    • IronSource (Unity LevelPlay) - advertising
    • Vungle (Liftoff) - advertising
    • Chartboost - advertising
    • InMobi - advertising and IP-based location inference
    • Mintegral - advertising
    • Tapjoy - advertising
    • Fyber/DT Exchange - advertising
    • Singular - attribution and analytics
    • Firebase (Google) - analytics, crash reporting, and cloud messaging

    Understanding the Scores

    Security: 88/100
    Privacy: 79/100

    Security Breakdown

    • Data Security: 100/100 - Sensitive data is handled securely throughout the app.
    • Network Security: 88/100 - All communications travel over HTTPS with strong protections. One ad SDK's embedded browser component uses a permissive file access configuration that could be tightened.
    • Code Safety: 100/100 - The app's own code follows strong safety practices with no identified weaknesses.

    Privacy Breakdown

    • Data Collection: 79/100 - Advertising identifiers and behavioral data may be collected across 10+ ad network SDKs, which is typical for ad-supported games but represents a broad data footprint.
    • Data Sharing: 82/100 - Purchase amounts and gameplay activity may be shared with several advertising partners, including Meta, for targeting and attribution.
    • User Control: 82/100 - Android's Ad ID opt-out provides some control, though certain data flows through ad network servers may persist beyond that setting.

    Positive Security Features

    • All network traffic is encrypted using HTTPS
    • Google Play Integrity API verifies device and app authenticity before sensitive operations
    • Consent management infrastructure (AppLovin CMP) is present in the SDK bundle to support privacy regulation compliance
    • SafeDK brand safety monitoring is active to filter ad content quality

    Areas for Improvement

    GDPR / CCPA Compliance

    The app's privacy practices could be strengthened by:

    1. Privacy Sandbox Access Controls
      Restricting which ad SDKs can independently access Android's Topics, Custom Audiences, and Attribution APIs would give the developer more oversight of how interest-based profiles are built from your data, rather than allowing all 10+ embedded ad SDKs unrestricted access.

    2. Consent Flow Verification
      The consent management infrastructure is present in the SDK bundle, but its invocation before ad SDK initialization could not be fully verified through code analysis. Confirming that consent is collected before any data collection begins would strengthen compliance for users in regulated regions.

    3. Location Disclosure Clarity
      The Play Store Data Safety section declares location as a collected data type, but this refers to IP-based location inferred by ad network servers rather than GPS or network location controlled by Android permissions. Clearer disclosure would help users understand exactly what they can and cannot control.

    Security Enhancements

    1. Ad SDK Browser Component Configuration
      Tightening the file access settings in the Unity Ads embedded browser component would reduce the theoretical risk of cross-origin file reads in the unlikely event that the ad network's configuration response were intercepted.

    2. Data Deletion Support
      The Play Store Data Safety form indicates that collected data cannot be deleted upon user request. Providing a data deletion mechanism would improve user control and align with CCPA and GDPR requirements.

    Technical Context

    App Type: Lifestyle simulation game (Teen-rated, ad-supported with in-app purchases)
    Classes Analyzed: Not available for this build
    Third-Party Services: 26 identified
    Context Tags: ads, gaming, financial


    About This Analysis

    This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

    App Details

    Developer: Eastside Games Inc
    Version: 1.22.0 (versionCode 761)
    Analysis Date: 2026-06-21
    Package: com.eastsidegames.dragrace

    Analysis Limitations

    • Static analysis only (code review without running the app)
    • Based on APK version 1.22.0 analyzed on 2026-06-21
    • May not reflect server-side security controls
    • Cannot detect all runtime behaviors

    Right of Reply

    Developer not yet contacted