YONO SBI: Banking & Lifestyle Security & Privacy Scorecard

Android

28
Overall trust score
Don't Trust
25
Security
30
Privacy

Banking activity and usage patterns are tracked via Firebase Analytics, and a Google Ads SDK is present, meaning users' financial behavior can influence the ads shown to them elsewhere. Financial data is handled with weaker protections than most banking apps. Users have limited ability to control what is collected or shared.

Best for

SBI customers needing mobile banking access

Avoid if

Those unwilling to share banking data with ad networks

Findings

  • 0 critical
  • 0 high
  • 0 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Insecure WebView File Access Mode
  • Missing Content Security Policy
  • OAuth Tokens Stored in Plaintext

Top privacy issues

  • Non-Consensual Analytics Tracking
  • Google Ads SDK in Banking Application
  • Excessive SMS Permissions

Full analysis

YONO SBI: Banking & Lifestyle

com.sbi.lotusintouch | Version 2.27.04 (Build 1241110) | Scanned 2026-01-24

What This Means for You

Banking activity and usage patterns are tracked via Firebase Analytics, and a Google Ads SDK is present, meaning users' financial behavior can influence the ads shown to them elsewhere. Financial data is handled with weaker protections than most banking apps. Users have limited ability to control what is collected or shared.

Recommendation: Use With Caution

Best For: SBI customers needing mobile banking access
Avoid If: Those unwilling to share banking data with ad networks

Key Findings

Data Security - 8 findings (2 critical, 2 high, 4 medium)

Network Security - 1 finding (1 medium)

Code Safety - 0 findings

Privacy - 5 findings (1 critical, 1 high, 3 medium)

Privacy Concerns

What Data is Collected

Device identifiers, location data, and in-app activity patterns are collected. This includes how users navigate the app, when they use it, and details about their device and network connection.

Third-Party Data Sharing

User data is shared with the following third-party services:

  • Firebase Analytics - Behavioral and usage tracking
  • Google Ads SDK - Advertising and behavioral profiling
  • Firebase Cloud Messaging - Push notification delivery
  • IBM MobileFirst Platform - Mobile application backend services
  • Google Maps API - Location services
  • Google Sign-In - Authentication services
  • NPCI UPI SDK - Payment processing infrastructure

Understanding the Scores

Category Score
Security 25/100
Privacy 30/100
Data Security 20/100
Network Security 55/100
Code Safety 30/100
Data Collection 35/100
Data Sharing 40/100
User Control 25/100

Positive Security Features

  • None identified in this version.

Areas for Improvement

  • Financial activity data is shared with advertising networks. For a banking app, this means spending patterns and financial behaviors may be used to target ads shown to users elsewhere.
  • Data protections for stored financial information fall below what is typically expected from banking apps, placing personal financial data at greater risk.
  • Users have very limited ability to opt out of data collection or sharing, leaving them with little meaningful control over their financial information.

About This Analysis

This scorecard reflects the app's observable security and privacy practices based on analysis of version 2.27.04. Scores are on a 0-100 scale, where higher is better.

App Details

  • App: YONO SBI: Banking & Lifestyle
  • Package: com.sbi.lotusintouch
  • Version: 2.27.04 (Build 1241110)
  • Scan Date: 2026-01-24

Versions & scan history

ScanDateOverall score
#1 (current) 28/100