Tiimo: To Do List & AI Planner Security & Privacy Scorecard

by tiimo · iOS

84
Overall trust score
Trustworthy
88
Security
82
Privacy

Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.

Best for

General use with standard privacy expectations

Findings

  • 0 critical
  • 0 high
  • 2 medium
  • 6 low
  • 11 info

1 issue identified across security and privacy analysis.

Top security issues

  • ATS Exception Allows Insecure HTTP and TLS 1.1 for All tiimoapp.com Subdomains
  • Staging and Development API Endpoints Compiled into Production Binary
  • Braze WebView Bridge Exposes Native SDK Operations to HTML In-App Message JavaScript

Top privacy issues

  • App-Level Privacy Manifest Missing NSPrivacyCollectedDataTypes
  • Extensive Third-Party Analytics Stack in Neurodivergent Health/Productivity App
  • Mixpanel Analytics Present in All Targets — Not Declared in App-Level Privacy Manifest

Full analysis

<!-- TRUSTEDVERDICTHEADER -->

Not yet TRUSTED

One area below did not meet the trust standard, so the app is not TRUSTED yet.

Trust Pillars

  • Secure by Design: Under review. We could not fully verify this area yet.
  • Data Respect: Under review. We could not fully verify this area yet.
  • Honest Experience: Needs work. Falls short of our standard here and needs improvement.
  • User Control: Strong. Meets a high bar in this area.
  • Child-Safe: Not applicable. Does not apply to this app.

<!-- /TRUSTEDVERDICTHEADER -->

Security & Privacy Scorecard

com.tiimo.app

What This Means for You

Usage data and device activity may be shared with the app developer and the services it integrates with. The category summary below shows the scope so people can decide whether it fits their needs.

Recommendation: Trustworthy

This app generally follows good security and privacy practices.

Best For: Neurodivergent users comfortable with standard analytics trade-offs and EU data routing

Avoid If: Users wanting minimal third-party data sharing or strict control over behavioral and health data

Key Findings

Data Security: 2 findings (2 info)

Network Security: 2 findings (1 medium, 1 info)

Code Safety: 0 findings

Privacy: 4 findings (1 medium, 2 low, 1 info)

Privacy Concerns

What Data is Collected

Review the app's store listing and in-app privacy notices for a full data collection disclosure.

Third-Party Data Sharing

The following third parties may receive user data:

  • AppsFlyerLib
  • BrazeKit
  • PurchaseConnector
  • RevenueCat
  • RevenueCatUI
  • Mixpanel
  • Sentry
  • Firebase Crashlytics
  • Firebase Installations
  • Google Sign-In
  • Auth0
  • Alamofire
  • Kingfisher
  • Lottie
  • SnapKit
  • EmojiKit
  • ZIPFoundation
  • Factory
  • CoreStore
  • KeychainAccess

Understanding the Scores

Security: 88/100
Privacy: 82/100

Security Breakdown

  • Data Security: 97/100. How the app handles stored data.
  • Network Security: 65/100. How the app handles data in transit.
  • Code Safety: 96/100. Overall code hygiene signals.

Privacy Breakdown

  • Data Collection: 87/100. Scope of data collected.
  • Data Sharing: 91/100. Third-party data sharing behavior.
  • User Control: 88/100. Controls the app offers over personal data.

Positive Security Features

  • Credentials stored using biometric-bound hardware keychain with App Attest device integrity verification
  • Marketing attribution properly gated behind ATT consent prompt — IDFA only accessed after user approval
  • External web content opens in sandboxed Safari view the app cannot intercept or inject into
  • Firebase Analytics disabled — only crash data collected via Crashlytics
  • Braze and Mixpanel route to EU servers, supporting data residency for European users
  • HealthKit mood data stored on-device with no evidence of off-device transmission to third parties

Areas for Improvement

  • Review the category summary above for where the app could strengthen its practices.
  • Keep the app updated to receive the latest security improvements from the developer.

About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

App Details

Developer: Unknown developer
Version: 3.61.0 (Build 1434)
Analysis Date: 2026-07-11
Package: com.tiimo.app

Versions & scan history

ScanDateOverall score
#3 (current) 84/100
#2 83/100