Unergy Security & Privacy Scorecard
Android
Identity is verified through Incode and Metamap, which collect biometric and document data. In-app behavior is recorded by UXCam and sent to Firebase, Sentry, and Statsig for analytics and crash tracking. Sensitive data stored on the device has limited protections, meaning user data may not be fully protected if the device is lost or compromised.
Best for
Energy users comfortable with identity verification
Avoid if
You prefer not to share biometric or identity data
Findings
- 4 critical
- 5 high
- 5 medium
- 1 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted Biometric Data in Room Databases
- JavaScript Interface Exposes State Control in Identity Verification WebView
- Missing Root Detection and Tamper Protection
Top privacy issues
- UXCam Session Recording Captures Government IDs and Biometric Data
- Excessive Third-Party Data Sharing
- Unknown SDK Versions - Cannot Verify CVEs
Full analysis
Unergy
Version: 9.8.12 | Analyzed: 2026-02-06
Overall Security: 45/100 | Privacy: 35/100
What This Means for You
Identity is verified through Incode and Metamap, which collect biometric and document data. In-app behavior is recorded by UXCam and sent to Firebase, Sentry, and Statsig for analytics and crash tracking. Sensitive data stored on the device has limited protections, meaning user data may not be fully protected if the device is lost or compromised.
Recommendation: Use With Caution
Best For: Energy users comfortable with identity verification
Avoid If: You prefer not to share biometric or identity data
Key Findings
Data Security - 2 findings (1 critical, 1 low)
Network Security - 4 findings (2 high, 2 medium)
Code Safety - 0 findings
Privacy - 2 findings (1 critical, 1 medium)
Privacy Concerns
What Data is Collected
Unergy collects biometric and identity document data through Incode and Metamap for identity verification. In-app behavior, including screen-level activity, is recorded by UXCam. Crash reports and performance data are collected by Sentry and Firebase.
Third-Party Data Sharing
Data is shared with the following third parties:
- Incode - Identity verification and biometric data processing
- Metamap - Identity document verification
- UXCam - In-app behavior recording and session replay
- Firebase - Analytics and app performance tracking
- Sentry - Crash and error reporting
- Statsig - Feature management and analytics
- OpenTok - Video communication services
- Google Play Services - Core platform services
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 35/100 |
| Data Security | 30/100 |
| Network Security | 75/100 |
| Code Safety | 50/100 |
| Data Collection | 40/100 |
| Data Sharing | 55/100 |
| User Control | 60/100 |
Positive Security Features
No notable positive security practices were identified in this version of the app.
Areas for Improvement
- Sensitive data stored on the device should be protected more robustly, reducing the impact if the device is lost or stolen.
- The scope of behavioral and identity data collected is broad. Clearer in-app controls for managing what is retained would provide more meaningful privacy choices.
- Some server communications could be configured more securely to better protect user data while it travels between the device and Unergy's systems.
About This Analysis
This scorecard is generated from automated static analysis of the app's code and configuration. It reflects the state of the app as of the scan date and may not account for changes introduced in later versions.
App Details
- App Name: Unergy
- Package ID: com.unergy.unergy_mobile
- Version: 9.8.12
- Platform: Android
- Scan Date: 2026-02-06
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 40/100 |