GPSEC Security & Privacy Scorecard

Android

60
Overall trust score
Use With Caution
55
Security
72
Privacy

Location data is a core part of how this app works, and it uses Google and OpenStreetMap services to process it. Push notifications are handled through Firebase, which means device activity reaches Google's infrastructure. User data is handled with moderate care, though there are some gaps in how it is protected at rest.

Best for

Users who need GPS tracking features

Findings

  • 1 critical
  • 2 high
  • 5 medium
  • 7 low
  • 4 info

1 issue identified across security and privacy analysis.

Top security issues

  • Release keystore password and key alias shipped in production APK, enabling re-signing of trojaned APKs
  • All GPS telemetry, authentication tokens, and SOS alerts transmitted over unencrypted HTTP
  • Database encryption key derived from public android_id and printed unconditionally to logcat

Top privacy issues

  • Real-time GPS coordinates and vehicle telemetry transmitted in cleartext HTTP, interceptable by any network observer
  • FCM notification analytics (including SOS alert engagement) activated server-side without user consent or opt-out
  • Boot-start location tracking resumes after every device reboot without in-app disclosure, including outside work hours

Full analysis

GPSEC

Version: 3.26.35 | Scan Date: 2026-03-31

What This Means for You

Location data is a core part of how this app works, and it uses Google and OpenStreetMap services to process it. Push notifications are handled through Firebase, which means device activity reaches Google's infrastructure. User data is handled with moderate care, though there are some gaps in how it is protected at rest.

Recommendation: Use With Caution

Best For: Users who need GPS tracking features

Key Findings

Data Security - 5 findings (1 critical, 1 high, 2 medium, 1 info)

Network Security - 5 findings (1 high, 1 medium, 2 low, 1 info)

Code Safety - 0 findings

Privacy - 4 findings (1 medium, 3 low)

Privacy Concerns

What Data is Collected

Precise location is collected continuously as part of the app's core function. Device identifiers and notification-related data are also gathered through push notification services.

Third-Party Data Sharing

Location and device activity passes through Google's infrastructure via Firebase Cloud Messaging and Google Maps. OpenStreetMap and its routing and geocoding services also process user location to provide mapping features.

Understanding the Scores

Category Score
Security 55/100
Privacy 72/100
Data Security 55/100
Network Security 57/100
Code Safety 84/100
Data Collection 91/100
Data Sharing 90/100
User Control 86/100

Positive Security Features

  • No notable positive security practices were identified in this version of the app.

Areas for Improvement

  • Some data stored on the device is not fully protected against access by other apps or unauthorized parties.
  • Parts of the app's network communication lack the protections needed to keep user data safe while it travels between the device and remote servers.
  • More clarity around how long location history is retained and when it is removed would give users better control over their personal information.

About This Analysis

This scorecard is based on automated static analysis of the app's code and behavior. Scores reflect the app's security and privacy practices at the time of the scan.

App Details

  • App: GPSEC
  • Package: com.gpsec.usuario
  • Version: 3.26.35 (build 131)
  • Scan Date: 2026-03-31

Versions & scan history

ScanDateOverall score
#2 (current) 60/100
#1 32/100