Join 75+ million users worldwide to spend, send, and save smarter. Pay with physical/virtual cards, Google or Apple Pay, send 25+ currencies, trade stocks from $1, and access 55k ATMs globally.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: Everyday banking with financial data routed only to Revolut
What It Means For You
Financial transaction data is routed exclusively to Revolut's own servers; advertising networks and data brokers do not receive financial information. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. Identity verification data is shared with third-party providers during account onboarding.
Quick Verdict
Best for: Everyday banking with financial data routed only to Revolut
What It Means For You
Financial transaction data is routed exclusively to Revolut's own servers; advertising networks and data brokers do not receive financial information. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. Identity verification data is shared with third-party providers during account onboarding.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
3 totalNetwork Security
1 totalCode Security
5 totalPrivacy
1 totalThird-Party Risk
2 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.revolut.revolut
Version
10.142 (versionCode: 1030142101)
Analysis Date
Aug 13, 2026
Classes Analyzed
257,401
Feedback helps us improve our analysis
CITT assesses this app Trustworthy (82/100). Build 10.142 implements hardware-backed encryption for financial data, anchors all API connections to Revolut's server certificates, and globally blocks unencrypted network traffic.
Data Security: 3 findings (1 medium, 2 low)
Network Security: 1 finding (1 medium)
Code Safety: 5 findings (2 medium, 3 low)
Privacy: 3 findings (3 medium)
No sensitive data was identified as processed exclusively on the device in this analysis.
Third parties that may receive data from the app:
Security: 82/100
Privacy: 83/100
Observations about disclosure, each stated against the published guidance so a reader can compare:
Third-party data sharing disclosure
The Play Store Data Safety label (as retrieved 2026-08-11) declares "No data shared with third parties." Build 10.142 links the SEON fraud detection SDK; SEON's published documentation describes its data collection scope as including device hardware fingerprint, installed-app list, network characteristics, SIM data, and behavioral signals transmitted to SEON's servers. Whether SEON processes this data solely as a service provider under Revolut's direction or also as an independent data controller could not be determined from the binary alone. Readers may wish to review Revolut's privacy policy for clarification on this relationship.
Installed-app list disclosure
The Data Safety label does not list "Installed apps" as a collected data type. Build 10.142 uses a permission granting access to all installed applications and performs a full device package scan on each app foreground. What portion of this scan result is transmitted off the device could not be determined from static analysis alone.
Database integrity configuration
Build 10.142 includes a configuration that disables per-page integrity checking on encrypted databases. Enabling this check would provide an additional layer of protection against undetected modification of stored financial records.
Receipt image storage
Transaction receipt images are written to a shared storage location accessible via file management apps on older Android versions. Storing these images in the app's private directory would limit access to the app itself.
Web component file access
Several embedded web components have file system access enabled where it is not functionally required. Restricting file access to only components that load local content would reduce the surface area of the embedded web functionality.
Payment link routing
The manifest registers both encrypted and unencrypted URL schemes for payment-related domains. Using only the encrypted scheme would strengthen Android's guarantee that incoming payment links originate from the correct source.
App Type: Finance - full-service neobanking, payments, savings, and investment
Classes Analyzed: 257,401
Third-Party Services: 26
Context Tags: financial, sensitive_data, location, camera
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of Android applications, intended to help people make informed decisions about app security and privacy.
Developer: Revolut Ltd
Version: 10.142 (Build 1030142101)
Analysis Date: 2026-08-13
Package: com.revolut.revolut
Developer not yet contacted