Structured: Daily Planner Todo Security & Privacy Scorecard

by unorderly GmbH · iOS

80
Overall trust score
Acceptable
80
Security
80
Privacy

Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.

Best for

General use with standard privacy expectations

Findings

  • 0 critical
  • 1 high
  • 2 medium
  • 7 low
  • 9 info

0 issues identified across security and privacy analysis.

Top security issues

  • Apple In-App Purchase Private Key Embedded in Distributed App Bundle
  • No Default Data Protection Entitlement — App Files Default to Class B (Unlocked-Once) Protection
  • Universal Link Registered on Third-Party Vercel-Hosted Domain

Top privacy issues

  • PostHog Session Replay Module Linked — Screen and Touch Capture Capability Present
  • App-Level Privacy Manifest Declares Zero Data Collection While Linked SDKs Collect Analytics, Attribution, and Subscription Data
  • PostHog Analytics SDK Bundles Both EU and US Region Endpoints — Active Region Unverifiable

Full analysis

<!-- TRUSTEDVERDICTHEADER -->

Did not meet TRUSTED criteria

The app was assessed and did not meet all of the criteria for the TRUSTED mark. The specific items are listed below so the result can be weighed before installing.

Trust Pillars

  • Secure by Design: Not met. Did not meet one criterion in this area.
  • Data Respect: Under review. This area was not fully assessed in this version.
  • Honest Experience: Not met. Did not meet one criterion in this area.
  • User Control: Strong. Strong result in this area.
  • Child-Safe: Not applicable. Does not apply to this app.

<!-- /TRUSTEDVERDICTHEADER -->

Security & Privacy Scorecard

Structured

What This Means for You

Analytics and subscription data are sent to PostHog and RevenueCat; task schedules and HealthKit health data are processed on the device and stay there.

Recommendation: Trustworthy

Strong encryption and HTTPS-only networking provide a solid security foundation. Analytics and subscription data are sent to named third parties, and a subscription service key bundled inside the app is worth the developer's attention. On-device AI processing keeps scheduling intelligence local with no data transmitted.

Best For: Productivity users who want a polished task scheduler and are comfortable with analytics and subscription tracking

Key Findings

Data Security: 2 findings (1 high, 1 low)

Network Security: 1 finding (1 low)

Code Safety: 1 finding (1 low)

Privacy: 1 finding (1 medium)

Privacy Concerns

What Data is Collected

  • Task schedules and calendar data: processed on the device and kept locally
  • HealthKit health data (accessed via the Cycle Seasons feature): accessed on the device and kept locally
  • Analytics and usage data: sent to PostHog
  • Subscription and purchase state: sent to RevenueCat
  • Crash and error data: may be sent to Sentry

Third-Party Data Sharing

Third parties that may receive data from the app:

  • PostHog - analytics, usage tracking, and session replay capability
  • RevenueCat - subscription and in-app purchase management
  • Sentry - crash and error reporting
  • ConfigCat - remote feature flag configuration
  • Supabase - backend data sync
  • Apple AdServices / SKAdNetwork - privacy-preserving attribution

Understanding the Scores

Security: 80/100
Privacy: 80/100

Security Breakdown

  • Data Security: 86/100. Task schedules and HealthKit health data are handled on the device. A subscription service key is bundled inside the distributed app, which could allow modification of subscription state by someone who extracts it from a downloaded copy.
  • Network Security: 97/100. All network connections enforce HTTPS with no exceptions, providing strong protection for data in transit.
  • Code Safety: 96/100. Modern encryption algorithms are used throughout the app for data protection.

Privacy Breakdown

  • Data Collection: 75/100. Analytics and usage data are sent to PostHog; task schedules and HealthKit health data remain on the device.
  • Data Sharing: 85/100. Data is shared with a small named set of third parties for analytics, crash reporting, subscription management, and backend sync.
  • User Control: 87/100. The advertising identifier is not requested, and privacy-preserving attribution via SKAdNetwork is used in its place.

Positive Security Features

  • All network connections enforce HTTPS with no App Transport Security exceptions
  • Advertising identifier not requested; privacy-preserving attribution used instead
  • On-device AI processing via FoundationModels and CoreML keeps scheduling intelligence local with no data transmitted
  • OAuth flows use Apple-recommended authentication views with no custom browser overrides
  • Modern encryption in use throughout the app, including ChaCha20-Poly1305 and Curve25519

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. Analytics Data Residency Clarity
    PostHog is configured with both EU and US region routing. Clarifying and enforcing which region handles data from EU users would improve compliance with GDPR data residency expectations.

  2. Privacy Manifest Completeness
    Adding an app privacy manifest could make the App Store privacy label more complete by formally declaring the data practices of linked SDKs.

Security Enhancements

  1. Subscription Service Key Storage
    The in-app purchase service key is currently bundled inside the distributed app. Moving it to a secure server would prevent it from being accessible to anyone who downloads a copy of the app.

  2. Stronger Default File Protection
    Applying the highest file protection class to app-created files would ensure task schedules and imported calendar data remain inaccessible while the device is locked, adding a layer of protection if the device is lost.

Technical Context

App Type: Productivity scheduler with task management, calendar features, and HealthKit integration
Classes Analyzed: 0
Third-Party Services: 10
Context Tags: health, sensitive_data, ads


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of iOS applications, intended to help people make informed decisions about app security and privacy.

App Details

Developer: Leo Mehlig
Version: 4.5.2 (Build 1866)
Analysis Date: 2026-07-17
Package: com.leomehlig.today

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on IPA version 4.5.2 (Build 1866) analyzed on 2026-07-17
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#5 (current) 80/100
#4 88/100
#3 81/100