SUUUUUU Security & Privacy Scorecard
Android
User authentication flows through Google Sign-In, Apple Sign-In, and SmartAuth, a third-party phone verification service. App usage data is sent to Firebase Analytics, and user content is stored in Google's Firestore cloud database. Push notification delivery is handled by Firebase Cloud Messaging.
Best for
Users comfortable with Google and Firebase cloud services
Findings
- 0 critical
- 0 high
- 0 medium
- 1 low
- 1 info
0 issues identified across security and privacy analysis.
Top security issues
- SmartAuth SDK Hardcodes Georgian Locale During Phone Verification
Top privacy issues
- Google Advertising ID Collected via Firebase Analytics Without GDPR Consent Management
Full analysis
SUUUUUU
What This Means for You
Your messages are sent securely over encrypted connections, and the app may share your advertising ID with Google for analytics purposes.
Recommendation: Very Secure
This app demonstrates strong security with enforced encryption and app integrity verification. Ideal for safe, casual messaging with friends.
Best For: Casual users who want a fun, low-stakes novelty messaging app with friends
Key Findings
Data Security - 0 findings
Network Security - 0 findings
Code Safety - 1 finding (1 low)
Privacy - 1 finding (1 info)
Privacy Concerns
What Data is Collected
- Contact information: accessed on your device to help you find and connect with friends
- Account information (email or phone number): shared with Google Firebase to authenticate your account
- Advertising ID: shared with Google Analytics to measure app usage
- Usage data: shared with Google Firebase Analytics to understand how the app is used
Third-Party Data Sharing
The following third parties may receive your data:
- Google (Firebase) - authentication, data storage, push notifications, and usage analytics
- SmartAuth by fman.ge - phone number verification for SMS-based sign-in
Understanding the Scores
Security: 99/100
Privacy: 96/100
Security Breakdown
- Data Security: 100/100 - Excellent data protection. Your information is handled with best-in-class security practices throughout the app.
- Network Security: 100/100 - All communication between your device and the service uses encrypted connections, keeping your data safe in transit.
- Code Safety: 99/100 - The app's code follows strong security practices with no meaningful risks to your device.
Privacy Breakdown
- Data Collection: 94/100 - The app collects minimal data, focusing on what is needed to deliver the service.
- Data Sharing: 100/100 - Data shared with third parties is limited to what is essential for the app to function.
- User Control: 97/100 - You have strong control over your data, including the ability to request its deletion.
Positive Security Features
- All data sent between your device and the service travels over encrypted connections
- The app verifies its own integrity before connecting to backend services, protecting against unauthorized modifications
- No confidential data or secrets are embedded in the app code
- Backend access requires that users be properly signed in, protecting your account
- No components are exposed that could allow other apps to access your data without permission
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
- Consent Management for Analytics
Adding a consent management platform would let users opt in or out of advertising ID collection before Firebase Analytics activates. This is a recommended practice for apps serving users in the EU, where GDPR applies to the developer (Pixplicity B.V., based in the Netherlands).
Security Enhancements
- SmartAuth SDK Configuration
The included SmartAuth SDK contains a configuration that overrides the device language to Georgian during phone number verification. Updating to a newer version of the SDK or working with the provider to address this would improve the experience for all international users.
Technical Context
App Type: Casual social messaging, low sensitivity
Classes Analyzed: 340
Third-Party Services: 14
Context Tags: social, contacts, ads
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
App Details
Developer: Pixplicity B.V.
Version: 1.1.7 (versionCode 41)
Analysis Date: 2026-06-16
Package: com.pixplicity.suuu
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on APK version 1.1.7 analyzed on 2026-06-16
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 97/100 |