mydealz – Gutscheine, Angebote Security & Privacy Scorecard
Android
User activity is shared with multiple advertising networks including Facebook, Google, and others to show targeted ads. User behavior is tracked by Adjust to measure how the app was found and how it is used. Several data protection practices mean stored data and network traffic carry more risk than typical apps.
Best for
Deal hunters comfortable with ad-supported browsing
Avoid if
You prefer not to see targeted ads from multiple ad networks
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted Database Storage Enables Account Takeover
- Facebook Ads WebView File Access Enables Universal XSS
- Facebook Ads SSL Certificate Validation Completely Bypassed
Top privacy issues
- Recombee Behavioral Profiling Without Explicit Consent
- Unencrypted Analytics Database Stores PII and Behavioral Data
- Pre-Consent SDK Initialization (GDPR Violation)
Full analysis
mydealz - Gutscheine, Angebote
What This Means for You
User activity is shared with multiple advertising networks including Facebook, Google, and others to show targeted ads. User behavior is tracked by Adjust to measure how the app was found and how it is used. Several data protection practices mean stored data and network traffic carry more risk than typical apps.
Recommendation: Use With Caution
Best For: Deal hunters comfortable with ad-supported browsing
Avoid If: You prefer not to see targeted ads from multiple ad networks
Key Findings
Data Security - 7 findings (2 critical, 4 medium, 1 info)
Network Security - 4 findings (1 critical, 1 high, 2 low)
Code Safety - 0 findings
Privacy - 10 findings (3 high, 3 medium, 4 info)
Privacy Concerns
What Data is Collected
mydealz collects behavioral data including browsing activity, deal interactions, and usage patterns within the app. This data is used to personalize the deal feed and serve targeted advertising.
Third-Party Data Sharing
User data is shared with the following third-party services:
- Facebook Audience Network - Advertising targeting
- Google AdMob - Advertising targeting
- PubMatic - Advertising targeting
- Moloco - Advertising targeting
- Vungle - Advertising targeting
- Iterable - Marketing communications
- Recombee - Content personalization
- Adjust - Attribution and behavioral analytics
- Firebase - App analytics and crash reporting
- Usercentrics - Consent management
- Apollo GraphQL - Data transport layer
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 52/100 |
| Data Security | 25/100 |
| Network Security | 30/100 |
| Code Safety | 40/100 |
| Data Collection | 60/100 |
| Data Sharing | 55/100 |
| User Control | 65/100 |
Positive Security Features
- No notable positive security practices were identified in this version of the app.
Areas for Improvement
- Data stored on the device is not adequately protected, increasing the risk if the device is accessed by someone else.
- Network traffic lacks protections that would shield user activity from third parties sharing the same connection.
- The number of advertising and analytics partners means behavioral data flows to many companies beyond the user's direct control.
About This Analysis
This scorecard is generated from automated static analysis of the app. Results reflect security and privacy practices observed in the app code and configuration.
App Details
| Field | Value |
|---|---|
| App Name | mydealz - Gutscheine, Angebote |
| Package ID | com.tippingcanoe.mydealz |
| Version | 8.08.02 |
| Scan Date | 2026-02-07 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 44/100 |