1Password: Password Manager Security & Privacy Scorecard
Android
Vault data stays on the device and is not sold or shared with advertisers. Sentry receives crash reports if the app encounters an error, and Google services handle push notifications and on-screen rendering. Passwords, notes, and payment details are not sent to third-party marketing or analytics platforms.
Best for
Anyone managing passwords across devices and teams
Findings
- 0 critical
- 0 high
- 2 medium
- 5 low
- 9 info
1 issue identified across security and privacy analysis.
Top security issues
- BackupAgent registers account details in plaintext SharedPreferences accessible via adb backup over USB
- Permissive network security config base policy permits cleartext HTTP for all non-1password.com domains
- Deep link handler performs scheme-only validation, allowing any installed app to inject arbitrary URIs into routing
Top privacy issues
- Sentry SDK session replay capability compiled into production build — active status unconfirmed but could capture vault UI if enabled
- Firebase Analytics explicitly disabled and no behavioral tracking SDKs present — strong privacy posture
- Google Places SDK collects location coordinates when the location sharing feature is actively used
Full analysis
1Password: Password Manager
com.onepassword.android | Version 8.11.18 | Android | Analyzed February 17, 2026
Security Score: 92/100 (A)
Privacy Score: 88/100 (B+)
What This Means for You
Vault data stays on the device and is not sold or shared with advertisers. Sentry receives crash reports if the app encounters an error, and Google services handle push notifications and on-screen rendering. Passwords, notes, and payment details are not sent to third-party marketing or analytics platforms.
Recommendation: Very Secure
Best For: Anyone managing passwords across devices and teams
Key Findings
Data Security - 5 findings (1 medium, 4 info)
Network Security - 2 findings (1 medium, 1 info)
Code Safety - 0 findings
Privacy - 2 findings (1 low, 1 info)
Privacy Concerns
What Data is Collected
1Password requests access to the device camera for scanning documents, the clipboard for copying and pasting saved items, and biometric sensors for unlocking the app.
Third-Party Data Sharing
The following third-party services receive limited operational data from this app:
- Sentry - Receives anonymized crash reports when the app encounters a problem. Vault contents are not included.
- Firebase Cloud Messaging - Handles push notifications for account alerts and sync events.
- Google Play Services - Provides core Android device integration.
- Google Places SDK - Supports location features for travel card display.
- Google ML Kit Vision - Powers camera-based document and code scanning.
- Google Play Billing - Manages in-app subscription and purchase flows.
- Glide - Loads website logos and app icons displayed in the vault.
- Kolide MDM - Provides device health checks for enterprise-managed deployments.
- Apollo GraphQL - Handles structured data exchange with 1Password servers.
- Google Accompanist - Supports on-screen layout and rendering.
Stored passwords, secure notes, and payment details are not accessible to any of these services.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 92/100 |
| Privacy | 88/100 |
| Data Security | 95/100 |
| Network Security | 88/100 |
| Code Safety | 95/100 |
| Data Collection | 100/100 |
| Data Sharing | 100/100 |
| User Control | 100/100 |
Positive Security Features
- Vault contents are protected with strong local encryption, keeping stored items readable only to the account holder
- Data sharing with third parties is limited to operational functions: crash reporting, push notifications, billing, and enterprise device health
- Users retain complete control over their vault, including the ability to export or permanently delete data
- The app earns top marks for data collection scope, data sharing restraint, and user control
Areas for Improvement
- Some network communication settings could be configured more strictly to provide stronger protection when using public or untrusted networks.
- A small number of internal storage practices could be made more conservative to reduce the chance of sensitive metadata being retained longer than needed.
About This Analysis
This scorecard is produced through automated static analysis of the published Android package. Scores reflect the security and privacy posture of the code at the time of the scan.
App Details
- App: 1Password: Password Manager
- Package ID: com.onepassword.android
- Version: 8.11.18 (build 81118036)
- Platform: Android
- Scan Date: February 17, 2026
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #10 (current) | 90/100 | |
| #9 | 82/100 | |
| #7 | 92/100 | |
| #6 | 71/100 | |
| #5 | 78/100 | |
| #4 | 92/100 | |
| #3 | 100/100 | |
| #2 | 83/100 |