Capital One Mobile Security & Privacy Scorecard
Android
Activity is tracked by Kochava and Google Ads for marketing purposes, and behavioral data flows to Firebase and New Relic for performance monitoring. Financial interactions and usage patterns are shared with multiple third-party services. Network connections are well protected, but the data footprint extends beyond Capital One itself.
Best for
Capital One customers comfortable with standard analytics
Findings
- 3 critical
- 6 high
- 9 medium
- 3 low
- 4 info
0 issues identified across security and privacy analysis.
Top security issues
- QA API Key and Environment URLs in Production Build
- Unencrypted Room Database Storage
- Multiple Google API Keys Exposed Without Restrictions
Top privacy issues
- Medallia Session Recording Capability - Potential Sensitive Data Capture
- Pre-Consent Analytics Tracking - GDPR Violation
- Customer/Profile Reference IDs in Analytics Events
Full analysis
Capital One Mobile
com.konylabs.capitalone | Version 6.37.5 | Scanned 2026-01-31
What This Means for You
Activity is tracked by Kochava and Google Ads for marketing purposes, and behavioral data flows to Firebase and New Relic for performance monitoring. Financial interactions and usage patterns are shared with multiple third-party services. Network connections are well protected, but the data footprint extends beyond Capital One itself.
Recommendation: Acceptable
Best For: Capital One customers comfortable with standard analytics
Key Findings
Data Security - 5 findings (2 high, 2 medium, 1 low)
Network Security - 1 finding (1 medium)
Code Safety - 0 findings
Privacy - 7 findings (2 critical, 3 high, 2 medium)
Privacy Concerns
What Data is Collected
Capital One Mobile collects device identifiers, in-app usage patterns, financial interaction history, and behavioral data. This information supports both core app functionality and third-party marketing and analytics purposes.
Third-Party Data Sharing
Data is shared with multiple third-party services: Kochava and Google Ads receive data for advertising attribution and targeting; Firebase receives crash reports and usage analytics; New Relic receives performance telemetry; Medallia receives user feedback signals; Google Maps receives location context for branch and ATM features; and MiTek MiSnap processes document and image data for identity-related flows.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 78/100 |
| Privacy | 62/100 |
| Data Security | 82/100 |
| Network Security | 95/100 |
| Code Safety | 85/100 |
| Data Collection | 58/100 |
| Data Sharing | 65/100 |
| User Control | 70/100 |
Positive Security Features
- Network communications are strongly protected, reducing the risk of data being intercepted in transit.
- The app includes integrity-checking measures that make unauthorized modification significantly harder.
- Crash and error reporting is handled through established services with defined data handling practices.
Areas for Improvement
- User data reaches a broad set of advertising and analytics partners. Reducing the number of third-party recipients would better protect financial privacy.
- The app collects behavioral and usage data that extends beyond what is needed to deliver core account management features.
- Users have limited visibility into, and control over, how marketing-oriented third parties connected to the app use data after it is shared.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect observed behaviors at the time of the scan and may change with app updates.
App Details
- App Name: Capital One Mobile
- Package ID: com.konylabs.capitalone
- Version: 6.37.5 (Build 1622311000)
- Scan Date: 2026-01-31
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 70/100 |