Skip to content

Can I trust Revolut: Spend, Save, Trade?

TRUSTish 80 iOS Version 10.142 (build 32112) Store version released: Last checked: Revolut Ltd com.revolut.revolut Scanned

This app did not meet one of the trust checks that applied to it, with no red flags.

Best for
Everyday banking and international transfers
Avoid if
Users who want no ad-network SDKs in a banking app
What it means for you
The build includes code that restricts financial transaction data and app behavior to Revolut's own infrastructure; Firebase Analytics is disabled, so the build contains no code path to send transaction activity to Google. The build includes code that may send install attribution data to AppsFlyer and Branch.io, and includes code to send crash reports to Firebase Crashlytics. Google AdMob, an advertising network, is also linked in the build.
Main concern
Ad tracking infrastructure in a financial app risks linking payment behavior to ad profiles
The developer's description
Join 75+ million users worldwide. Revolut offers multi-currency accounts, virtual/physical cards, peer-to-peer payments, stock trading, savings, budgeting tools, and fraud protection. Includes card freezing, spending notifications, and kids financial learning accounts.
Third-party services
19
Findings rated low or higher
4

How the score and the label work

Full findings

Open this scan in your dashboard

The account that ran this scan sees every finding and the Rescan button there.

Trust checks

  • Secure by Design

    Strong

    Strong security foundation

    Why this result

    This check looks for security issues at high severity or above in the code of this build, and none were recorded. Its scope covers stored credentials, how the app protects data on the device, and how it protects data in transit.

    Revolut applies multiple layers of protection: all network connections require encryption with no cleartext exceptions declared anywhere in the bundle, Apple AppAttest device integrity verification is active in production to block tampered or emulated clients, and an NTP time-synchronization library prevents timestamp replay attacks against time-bounded tokens. A certificate pinning library adds an additional layer against network interception. Authentication flows use the sandboxed system browser rather than an embedded browser that could be hijacked. Sensitive financial screens are protected from screen capture. The bundled cryptographic library is at a current, patched version with no active critical vulnerabilities. No critical or high-severity security defects were identified in any of the available binary artifacts.

  • Data Minimization

    Strong

    Tracking done right

    Why this result

    The check looks at analytics and attribution code for companies other than the developer: the data it reads, the companies named in code as recipients, and whether a consent step runs before that code. In this build, either no such code was recorded, or a consent step runs before it and the app's own disclosures describe the collection.

    An offline analytics event queue is bundled in the app, raising the question of whether events accumulate before the user responds to the tracking consent prompt. The app does link Apple's App Tracking Transparency framework and declares an explicit advertising purpose in the associated permission string, indicating a consent prompt is presented before the advertising identifier can be accessed. Behavioral analytics via Firebase is explicitly disabled, so financial activity does not flow to Google.

  • Manifest Mismatch

    One criterion not met

    Disclosure incomplete or contradicted

    Why this result

    The check compares the app's privacy disclosures against what the code does, and at least one claim did not match in this build. Mismatches of this kind include a data category collected but not disclosed, a recipient the disclosure omits, and an identifier attached to data the disclosure describes as anonymous.

  • User Control

    Strong

    No lock-in

    Why this result

    The check looks for a way to export the data an account has accumulated and a way to delete the account itself. In this build, either both were found, or the app has no account of its own and keeps its data on the device. For an app without an account, the developer has no server-side copy to export or delete, and deleting the app removes the data in its own storage.

    No proprietary data formats designed to trap user data or artificial obstacles to leaving the service were found in the available code. As a regulated financial institution operating under GDPR, Revolut is legally required to honor data portability and account deletion requests. Nothing in the available binary artifacts suggests barriers to switching financial providers.

Strengths

  • Firebase Analytics disabled — financial transactions and app behavior do not flow to Google
  • All network traffic uses HTTPS with no cleartext exceptions declared anywhere in the bundle
  • Sensitive screens (balances, card details) are protected against screenshots and screen recording
  • Apple AppAttest active in production — server can cryptographically verify genuine, unmodified device
  • OAuth authentication flows use system browser isolation, preventing any in-app WebView credential exposure
  • Data sharing across Revolut apps is restricted entirely to Revolut's own first-party infrastructure (Team ID QUZEZSEARC)
  • NTP-synchronized timestamps via Kronos prevent replay attacks on time-sensitive tokens
  • Help and FAQ content loads in SFSafariViewController — isolated from host app cookies and JS bridge

What the app contains

  • 19 services

    Third-party services the scan names in the build:

    • AppsFlyer SKAdNetwork
    • Branch.io
    • Google AdMob
    • Firebase Crashlytics
    • Firebase Cloud Messaging
    • Firebase Remote Config
    • Onfido
    • Incode (IncdOnboarding)
    • SEON
    • TwilioVoice
    • Licel ios_runtime (RASP)
    • TrustKit
    • Authada (German eID)
    • ItrustEkycLibrary (Cybertrust Japan)
    • Trustdock
    • AppAuthCore
    • GTMAppAuth
    • Kronos
    • OpenSSL

Method and limits

Static analysis: the decompiled code, manifest and resources of this build, read file by file. Network traffic at run time is established by a capture of the running app.

Scan date
13 August 2026

Corrections

No correction is published for this app.

Developer response

No response is published for this app.

Report an error Opens an email to [email protected] that names this app and this scan.