Clash Royale Security & Privacy Scorecard
Android
Gameplay activity and device details are shared with analytics and attribution services including AppsFlyer and Snowplow. Crash reports may be sent to Sentry. In-app purchases are processed through Google Play Billing.
Best for
Mobile gamers comfortable with standard analytics
Findings
- 0 critical
- 2 high
- 6 medium
- 5 low
- 7 info
1 issue identified across security and privacy analysis.
Top security issues
- Hardcoded Initialization Vector in AES-CBC Encryption
- Android Backup Exposes Encrypted Authentication Tokens
- AES ECB Mode Used for Preference Key Encryption
Top privacy issues
- Pre-Consent Analytics Initialization
- Advertising ID Collection Without Active Advertising
- Snowplow Analytics Behavioral Tracking
Full analysis
Clash Royale
Developer: Supercell
Version: 130300033
Platform: Android
Scan Date: February 15, 2026
What This Means for You
Gameplay activity and device details are shared with analytics and attribution services including AppsFlyer and Snowplow. Crash reports may be sent to Sentry. In-app purchases are processed through Google Play Billing.
Recommendation: Trustworthy
Best For: Mobile gamers comfortable with standard analytics
Key Findings
Data Security - 5 findings (2 high, 3 medium)
Network Security - 1 finding (1 medium)
Code Safety - 0 findings
Privacy - 4 findings (1 medium, 3 low)
Privacy Concerns
What Data is Collected
- Gameplay activity and session data
- Device identifiers and hardware details
- In-app purchase history
- Crash reports and error logs
- App installation and attribution data
Third-Party Data Sharing
| Service | Purpose |
|---|---|
| AppsFlyer | Install attribution and marketing analytics |
| Snowplow Analytics | Behavioral analytics and event tracking |
| Firebase Installations | Device registration and messaging |
| Firebase Messaging | Push notifications |
| Sentry | Crash reporting and error monitoring |
| Google Play Billing | In-app purchase processing |
| Google Play Games | Game progress and leaderboards |
| Usercentrics | Consent management |
| Helpshift | In-app customer support |
| Promon SHIELD | App protection services |
| reCAPTCHA | Bot and fraud prevention |
Understanding the Scores
| Category | Score |
|---|---|
| Security | 82/100 |
| Privacy | 92/100 |
| Data Security | 78/100 |
| Network Security | 95/100 |
| Code Safety | 92/100 |
| Data Collection | 94/100 |
| Data Sharing | 93/100 |
| User Control | 92/100 |
Positive Security Features
- Built-in app protection against unauthorized modification via Promon SHIELD
- Bot and fraud prevention through reCAPTCHA integration
- Consent management via Usercentrics, giving users control over data preferences
- Secure in-app purchase processing through Google Play Billing
Areas for Improvement
- Some data stored on the device could be better protected from access by other apps.
- A small number of network connections use configurations that could be strengthened.
- Minor improvements to how certain data is handled during transmission would further reduce risk.
About This Analysis
This scorecard reflects automated static analysis of the app's code and configuration. Scores represent observed security and privacy practices at the time of the analysis.
App Details
| Field | Value |
|---|---|
| Package ID | com.supercell.clashroyale |
| Version | 130300033 |
| Platform | Android |
| Scan Date | February 15, 2026 |
| Analysis Type | Static Code Analysis |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #4 (current) | 87/100 |