Intuit QuickBooks for Business Security & Privacy Scorecard
Android
Business invoices, expenses, and usage activity are shared with multiple analytics and marketing services, including Kochava, Braze, and Segment, which track how users interact with the app. Stored financial data may not be fully protected, which could put sensitive business records at risk.
Best for
Small business owners managing finances on the go
Avoid if
You store sensitive client financial records
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted OAuth Token Storage
- Debug Build in Production
- Universal File Access in WebViews
Top privacy issues
- Pre-Consent Analytics Tracking - Kochava
- Pre-Consent Session Recording - Embrace
- Google Advertising ID Cross-App Tracking
Full analysis
Intuit QuickBooks for Business
Package ID: com.intuit.quickbooks
Version: 29.44.0+1
Security Score: 25/100
Privacy Score: 30/100
Scan Date: January 30, 2026
What This Means for You
Business invoices, expenses, and usage activity are shared with multiple analytics and marketing services, including Kochava, Braze, and Segment, which track how users interact with the app. Stored financial data may not be fully protected, which could put sensitive business records at risk.
Recommendation: Use With Caution
Best For: Small business owners managing finances on the go
Avoid If: You store sensitive client financial records
Key Findings
Data Security - 2 findings (1 critical, 1 high)
Network Security - 1 finding (1 high)
Code Safety - 0 findings
Privacy - 8 findings (2 critical, 4 high, 2 medium)
Privacy Concerns
What Data is Collected
The app collects financial records including invoices, expenses, and transaction history. It also gathers detailed behavioral data on how users use the app, including which screens they visit, how long they spend on each feature, and what actions they take. Device identifiers and technical information about the device are collected to support fraud detection and account security functions.
Third-Party Data Sharing
Activity data is shared with a broad network of third-party services. Kochava and Segment receive behavioral and attribution data to track user engagement across marketing channels. Braze receives data to power targeted messaging and in-app communications. Firebase collects usage and stability data. ThreatMetrix receives device and behavioral signals for fraud analysis. Instabug receives diagnostic reports. Plaid and Stripe handle banking connection and payment data for core financial features.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 25/100 |
| Privacy | 30/100 |
| Data Security | 20/100 |
| Network Security | 55/100 |
| Code Safety | 15/100 |
| Data Collection | 40/100 |
| Data Sharing | 35/100 |
| User Control | 45/100 |
Security (25/100): Financial records are stored and handled in ways where user data may not be fully protected. The technical safeguards around sensitive business data are insufficient for an app handling this type of information.
Privacy (30/100): Usage data is distributed to a large number of third-party services, with limited controls for users to restrict that sharing.
Data Security (20/100): The protections around stored financial records and business data fall short. Sensitive information entered into the app may not be fully protected at rest.
Network Security (55/100): Some protections are in place for data sent over the network, though user data may not be fully protected in certain circumstances, including on public Wi-Fi.
Code Safety (15/100): The app's internal code protections are minimal, making it easier for unauthorized parties to analyze and misuse the app in ways that affect how financial data is handled.
Data Collection (40/100): The app collects a broader range of data than its core financial features require, including behavioral and usage signals used for advertising and analytics purposes.
Data Sharing (35/100): User data is routinely passed to multiple third-party services, each with their own data retention and use policies outside users' control.
User Control (45/100): Users have some options to manage account data, but meaningful control over what is shared with marketing and analytics services is limited.
Positive Security Features
- No positive security practices were identified for this version of the app.
Areas for Improvement
- The protections around stored financial records need substantial strengthening. Business data including invoices, expenses, and client records deserve a higher level of protection than this version provides.
- Usage and behavioral data is shared with an unusually large number of third-party services, including multiple marketing and analytics providers. Reducing this sharing or providing clear opt-out controls would better protect user privacy.
- The app's internal code protections are minimal. Stronger safeguards would reduce the risk that financial data could be accessed or misused through the app's design.
About This Analysis
This scorecard reflects a static analysis of the app's code, configuration, and data handling practices. Scores represent the security and privacy posture of the specific version analyzed.
App Details
| Field | Value |
|---|---|
| App Name | Intuit QuickBooks for Business |
| Package ID | com.intuit.quickbooks |
| Version | 29.44.0+1 |
| Platform | Android |
| Scan Date | January 30, 2026 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 28/100 |