Polarsteps Security & Privacy Scorecard
Android
User activity is shared with several analytics and marketing platforms, including AppsFlyer and Mixpanel, which track app usage to target users with campaigns. Push notifications are managed by Urban Airship and Braze, which have visibility into user engagement patterns. Location and trip data are processed with protection in transit.
Best for
Travel enthusiasts comfortable with standard analytics
Findings
- 0 critical
- 3 high
- 6 medium
- 3 low
- 3 info
1 issue identified across security and privacy analysis.
Top security issues
- Unencrypted Authentication Token Storage
- Unencrypted Room Database
- HTTP Deep Links Accepted Alongside HTTPS
Top privacy issues
- Pre-Consent Analytics and Marketing SDK Initialization
- Consent Management System Not Enforced
- PII Collection in Analytics Events
Full analysis
Polarsteps
Version: 9.20.0 (2000008456)
Scan Date: 2026-03-05
What This Means for You
User activity is shared with several analytics and marketing platforms, including AppsFlyer and Mixpanel, which track app usage to target users with campaigns. Push notifications are managed by Urban Airship and Braze, which have visibility into user engagement patterns. Location and trip data are processed with protection in transit.
Recommendation: Acceptable
Best For: Travel enthusiasts comfortable with standard analytics
Key Findings
Data Security - 5 findings (1 high, 1 medium, 2 low, 1 info)
Network Security - 2 findings (1 medium, 1 info)
Code Safety - 0 findings
Privacy - 4 findings (2 high, 2 medium)
Privacy Concerns
What Data is Collected
Polarsteps collects location data, trip details, and behavioral usage patterns. The app tracks how users interact with its features and links activity across sessions using device identifiers.
Third-Party Data Sharing
User data is shared with multiple third-party services:
- AppsFlyer and Mixpanel receive behavioral data for marketing attribution and campaign targeting
- Braze and Urban Airship manage push notifications and track user engagement patterns
- RudderStack aggregates and routes activity data to additional platforms
- Firebase and Google Play Services collect app performance and usage data
- Mapbox processes location data for map rendering
Understanding the Scores
| Category | Score |
|---|---|
| Security | 84/100 |
| Privacy | 74/100 |
| Data Security | 84/100 |
| Network Security | 96/100 |
| Code Safety | 96/100 |
| Data Collection | 81/100 |
| Data Sharing | 100/100 |
| User Control | 79/100 |
Positive Security Features
- Network communications are well-protected, keeping data safe while it travels between the device and Polarsteps servers
- The app's code follows safe practices that limit exposure to common software risks
- Third-party data sharing is scoped to services directly supporting the app's core functionality
Areas for Improvement
- Location and trip data are shared with advertising and analytics platforms beyond what the core travel-tracking experience requires, giving users limited control over how that data is used downstream
- Push notification services retain insight into in-app engagement patterns, and fully opting out of this tracking is not straightforward
- Greater transparency about which third parties receive user data, and for what purpose, would help users make more informed choices before sharing personal information
About This Analysis
This scorecard is generated from static analysis of the app's code and configuration. Scores reflect the app's security and privacy posture at the time of the scan.
App Details
- App: Polarsteps
- Package: com.polarsteps
- Version: 9.20.0 (2000008456)
- Scan Date: 2026-03-05
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 79/100 |