ColorNote Notepad Notes Security & Privacy Scorecard
Android
Notes are stored with weaker-than-expected protections, raising concern for users who write down passwords, financial details, or personal information. Firebase and Facebook SDKs are embedded, meaning user activity touches Google and Facebook infrastructure. Data collection exposure is minimal, but how notes are secured locally is a real tradeoff.
Best for
Note-takers comfortable with Firebase and Facebook SDKs
Avoid if
You store sensitive personal information in notes
Findings
- 3 critical
- 4 high
- 4 medium
- 1 low
- 0 info
1 issue identified across security and privacy analysis.
Top security issues
- Exported ContentProvider Allows Unrestricted Access to All Notes
- Hardcoded Google OAuth Client Secret
- OAuth Tokens Stored in Plaintext Database
Top privacy issues
- Unencrypted SQLite Database Contains Sensitive Data
- Geolocation Data Stored Without Clear User Consent
- Full Database Backup Enabled Without Strong Encryption
Full analysis
ColorNote Notepad Notes
Version: 4.7.9 | Platform: Android | Scan Date: 2026-03-05
Overall Security Score: 43/100 | Privacy Score: 98/100
What This Means for You
Notes are stored with weaker-than-expected protections, raising concern for users who write down passwords, financial details, or personal information. Firebase and Facebook SDKs are embedded, meaning user activity touches Google and Facebook infrastructure. Data collection exposure is minimal, but how notes are secured locally is a real tradeoff.
Recommendation: Use With Caution
Best For: Note-takers comfortable with Firebase and Facebook SDKs
Avoid If: You store sensitive personal information in notes
Key Findings
Data Security - 7 findings (2 critical, 3 high, 2 medium)
Network Security - 1 finding (1 medium)
Code Safety - 0 findings
Privacy - 1 finding (1 medium)
Privacy Concerns
What Data is Collected
The app's data collection footprint is minimal, rated 98/100. Usage information is gathered to support core app functions and third-party integrations, but the scope of personal data collected is limited.
Third-Party Data Sharing
In-app activity is processed through the following third-party services:
- Google Play Billing
- Firebase Remote Config
- Firebase Installations
- Firebase Realtime Database
- Google Play Services
- Facebook SDK
Both Google and Facebook infrastructure handle data generated by use of the app. Data sharing is rated 100/100, reflecting that data flows through Google and Facebook infrastructure via the embedded services listed above.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 43/100 |
| Privacy | 98/100 |
| Data Security | 26/100 |
| Network Security | 88/100 |
| Code Safety | 76/100 |
| Data Collection | 98/100 |
| Data Sharing | 100/100 |
| User Control | 98/100 |
Positive Security Features
- No positive security practices were identified in this version of the app.
Areas for Improvement
- The way notes are protected on the device needs significant strengthening. If someone gains access to the phone, saved notes may be more accessible than users would expect.
- The presence of Facebook SDK means in-app behavior may be observable to Facebook, even for users who do not personally use Facebook services.
- Stronger local data protections would meaningfully reduce the risk to users who rely on this app for sensitive personal notes.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect the state of the app at the time of analysis and may change with future updates.
App Details
- App Name: ColorNote Notepad Notes
- Package ID: com.socialnmobile.dictapps.notepad.color.note
- Version: 4.7.9
- Scan Date: 2026-03-05
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 70/100 |