Capital One Mobile Security & Privacy Scorecard

Android

70
Overall trust score
Acceptable
78
Security
62
Privacy

Activity is tracked by Kochava and Google Ads for marketing purposes, and behavioral data flows to Firebase and New Relic for performance monitoring. Financial interactions and usage patterns are shared with multiple third-party services. Network connections are well protected, but the data footprint extends beyond Capital One itself.

Best for

Capital One customers comfortable with standard analytics

Findings

  • 3 critical
  • 6 high
  • 9 medium
  • 3 low
  • 4 info

0 issues identified across security and privacy analysis.

Top security issues

  • QA API Key and Environment URLs in Production Build
  • Unencrypted Room Database Storage
  • Multiple Google API Keys Exposed Without Restrictions

Top privacy issues

  • Medallia Session Recording Capability - Potential Sensitive Data Capture
  • Pre-Consent Analytics Tracking - GDPR Violation
  • Customer/Profile Reference IDs in Analytics Events

Full analysis

Capital One Mobile

com.konylabs.capitalone | Version 6.37.5 | Scanned 2026-01-31

What This Means for You

Activity is tracked by Kochava and Google Ads for marketing purposes, and behavioral data flows to Firebase and New Relic for performance monitoring. Financial interactions and usage patterns are shared with multiple third-party services. Network connections are well protected, but the data footprint extends beyond Capital One itself.

Recommendation: Acceptable

Best For: Capital One customers comfortable with standard analytics

Key Findings

Data Security - 5 findings (2 high, 2 medium, 1 low)

Network Security - 1 finding (1 medium)

Code Safety - 0 findings

Privacy - 7 findings (2 critical, 3 high, 2 medium)

Privacy Concerns

What Data is Collected

Capital One Mobile collects device identifiers, in-app usage patterns, financial interaction history, and behavioral data. This information supports both core app functionality and third-party marketing and analytics purposes.

Third-Party Data Sharing

Data is shared with multiple third-party services: Kochava and Google Ads receive data for advertising attribution and targeting; Firebase receives crash reports and usage analytics; New Relic receives performance telemetry; Medallia receives user feedback signals; Google Maps receives location context for branch and ATM features; and MiTek MiSnap processes document and image data for identity-related flows.

Understanding the Scores

Category Score
Security 78/100
Privacy 62/100
Data Security 82/100
Network Security 95/100
Code Safety 85/100
Data Collection 58/100
Data Sharing 65/100
User Control 70/100

Positive Security Features

  • Network communications are strongly protected, reducing the risk of data being intercepted in transit.
  • The app includes integrity-checking measures that make unauthorized modification significantly harder.
  • Crash and error reporting is handled through established services with defined data handling practices.

Areas for Improvement

  • User data reaches a broad set of advertising and analytics partners. Reducing the number of third-party recipients would better protect financial privacy.
  • The app collects behavioral and usage data that extends beyond what is needed to deliver core account management features.
  • Users have limited visibility into, and control over, how marketing-oriented third parties connected to the app use data after it is shared.

About This Analysis

This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect observed behaviors at the time of the scan and may change with app updates.

App Details

  • App Name: Capital One Mobile
  • Package ID: com.konylabs.capitalone
  • Version: 6.37.5 (Build 1622311000)
  • Scan Date: 2026-01-31
  • Platform: Android

Versions & scan history

ScanDateOverall score
#1 (current) 70/100