Scan results

    Strava: Run, Bike, Walk

    Android

    unTRUSTED

    This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.

    The five trust checks

    Truly LocalNot applicable
    CITT SCORE
    64
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Uses that keep sensitive information out of this build. It carries 10 findings at high severity.

    Not For: Anyone handling information on this device that they would want kept to themselves. The analysis recorded 10 issues at high severity in Code Security, Network Security, Data Security and Privacy.

    What It Means For You

    Whether this build can be trusted turns on what it shares, and on 10 findings recorded alongside that. The code sends precise location to Strava, Android platform geocoding service and 8 other recipients, and approximate location to Strava and Mapbox. Another 21 data points are sent out, each to the recipients its own findings name. Whether the user was asked first is unrecorded for 895 of the 988 flows the analysis traced. Of the 1,954 findings recorded, 10 sit at high severity or above, spread across 4 categories, worth reading before this build handles anything a user would want kept to themselves. The analysis also recorded two findings at high severity or above that this page does not count against the build: an adversarial review did not sustain them. Of the 1,954, 202 record a question the code available left open rather than something the build was found to do.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (1952)

    Data Security

    117 total
    3 High
    35 Medium
    79 Low

    Network Security

    196 total
    3 High
    50 Medium
    143 Low

    Code Security

    352 total
    2 High
    66 Medium
    284 Low

    Privacy

    496 total
    2 High
    150 Medium
    344 Low

    Third-Party Risk

    713 total
    73 Medium
    640 Low

    Permission Usage

    78 total
    17 Medium
    61 Low
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Package

    com.strava

    Analysis Date

    Sep 8, 2026

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    What This App Collects

    The code sends precise location to Strava, Android platform geocoding service, Geocode Earth (vendor-a) via Strava, Google Maps and 6 other recipients; approximate location to Strava and Mapbox; credentials to Strava, Branch Metrics, Sentry and Strava GraphQL backend; and authentication tokens to Strava, Firebase Installations (Google), Custom Tabs browser (external app), Google and 6 other recipients. Another 19 data points are sent out, each to the recipients its own findings name.

    Other findings record data the code reads on the device without the analysis tracing it further, data arriving from a server and flows whose direction the available code left open.

    Stream (io.getstream.chat.android) receives account identifiers. The same recipient receives messages and microphone input.

    Stream (getstream.io) receives account identifiers. The same recipient receives messages.

    Can This Be Trusted

    Read what this build shares first, and 10 findings with it.

    The code sends data out of the device on 400 traced flows, reaching 99 distinct recipients. On 9 of those flows the analysis looked for a consent gate and could not locate one. Six more sit on a path that runs before the app could have asked. On the rest the question was left open.

    Of the 1,954 findings recorded, 10 sit at high severity or above, worth reading before this build handles anything a user would want kept to themselves. They fall mostly under Third-Party Risk, Privacy and Code Security.

    The analysis also recorded two findings at high severity or above that this page does not count against the build: an adversarial review did not sustain them. The detailed findings carry them in full, with what the review made of them.

    An adversarial review also weakened nine findings at high severity or above that this page does count: the review did not sustain them as written and kept them in a smaller form, and nothing in the analysis rewrites the wording to that smaller form. The detailed findings carry them with what the review made of them.

    What Needs Attention

    This build has 10 findings that need attention. Three are about how data is stored on the device, three about how the app connects to servers, two about how the app is built and two about the personal information collected. The detailed report states each of these in full.

    Scores

    • Overall: 64/100
    • Security: 63/100. Held down by how the app talks to servers and by how the app is put together.
    • Privacy: 67/100. Held down by the amount collected and by how little of it is recorded as consented to.
    • Data Security: 75/100
    • Network Security: 74/100
    • Code Safety: 72/100
    • Data Collection: 70/100
    • Data Sharing: 81/100
    • User Control: 69/100
    • Permission Usage: 87/100

    What the Score Set Aside

    Of the 1752 findings that describe something this build contains, 4 describe code inside bundled libraries that the call graph shows this build leaves unused. They keep their recorded severity and are named in full in the detailed report; the score was computed over the other 1748.

    The largest groups are play-services (3) and braze (1).

    Set aside by library:

    • play-services (3)
    • braze (1)

    How This Was Checked

    CITT examined 3,984 files, traced 988 data flows and recorded 1,954 findings.

    Whether the user was asked first is mostly unrecorded, across the 988 flows recorded, not only the outbound ones: 895 were recorded without establishing whether the user had been asked at that point; 37 record a flow the analysis looked for a consent gate on and could not locate one; 20 sit on a path reachable before the app could have prompted; 34 run after the user granted permission; 2 run after the user declined.

    An unsettled consent state is a gap in what the analysis could trace, and it is a different thing from a record that the user agreed.

    About This Analysis

    This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.

    Right of Reply

    Developer not yet contacted