GPSEC Security & Privacy Scorecard
Android
Location data is a core part of how this app works, and it uses Google and OpenStreetMap services to process it. Push notifications are handled through Firebase, which means device activity reaches Google's infrastructure. User data is handled with moderate care, though there are some gaps in how it is protected at rest.
Best for
Users who need GPS tracking features
Findings
- 1 critical
- 2 high
- 5 medium
- 7 low
- 4 info
1 issue identified across security and privacy analysis.
Top security issues
- Release keystore password and key alias shipped in production APK, enabling re-signing of trojaned APKs
- All GPS telemetry, authentication tokens, and SOS alerts transmitted over unencrypted HTTP
- Database encryption key derived from public android_id and printed unconditionally to logcat
Top privacy issues
- Real-time GPS coordinates and vehicle telemetry transmitted in cleartext HTTP, interceptable by any network observer
- FCM notification analytics (including SOS alert engagement) activated server-side without user consent or opt-out
- Boot-start location tracking resumes after every device reboot without in-app disclosure, including outside work hours
Full analysis
GPSEC
Version: 3.26.35 | Scan Date: 2026-03-31
What This Means for You
Location data is a core part of how this app works, and it uses Google and OpenStreetMap services to process it. Push notifications are handled through Firebase, which means device activity reaches Google's infrastructure. User data is handled with moderate care, though there are some gaps in how it is protected at rest.
Recommendation: Use With Caution
Best For: Users who need GPS tracking features
Key Findings
Data Security - 5 findings (1 critical, 1 high, 2 medium, 1 info)
Network Security - 5 findings (1 high, 1 medium, 2 low, 1 info)
Code Safety - 0 findings
Privacy - 4 findings (1 medium, 3 low)
Privacy Concerns
What Data is Collected
Precise location is collected continuously as part of the app's core function. Device identifiers and notification-related data are also gathered through push notification services.
Third-Party Data Sharing
Location and device activity passes through Google's infrastructure via Firebase Cloud Messaging and Google Maps. OpenStreetMap and its routing and geocoding services also process user location to provide mapping features.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 55/100 |
| Privacy | 72/100 |
| Data Security | 55/100 |
| Network Security | 57/100 |
| Code Safety | 84/100 |
| Data Collection | 91/100 |
| Data Sharing | 90/100 |
| User Control | 86/100 |
Positive Security Features
- No notable positive security practices were identified in this version of the app.
Areas for Improvement
- Some data stored on the device is not fully protected against access by other apps or unauthorized parties.
- Parts of the app's network communication lack the protections needed to keep user data safe while it travels between the device and remote servers.
- More clarity around how long location history is retained and when it is removed would give users better control over their personal information.
About This Analysis
This scorecard is based on automated static analysis of the app's code and behavior. Scores reflect the app's security and privacy practices at the time of the scan.
App Details
- App: GPSEC
- Package: com.gpsec.usuario
- Version: 3.26.35 (build 131)
- Scan Date: 2026-03-31
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 60/100 | |
| #1 | 32/100 |