Join 3 million users managing finances with George. Track income, expenses, and investments. Make fast payments, earn cashback, invest in ETFs and funds, apply for products, and access child-friendly banking—all in one secure app.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: Everyday banking and payments on the go
What It Means For You
App usage and analytics data is shared with PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. Device security signals are collected by ThreatMark and Innovatrics for fraud protection. Some user data may not be fully protected in all scenarios.
Quick Verdict
Best for: Everyday banking and payments on the go
What It Means For You
App usage and analytics data is shared with PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. Device security signals are collected by ThreatMark and Innovatrics for fraud protection. Some user data may not be fully protected in all scenarios.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
1 totalCode Security
2 totalPrivacy
1 totalThird-Party Risk
3 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
cz.csas.georgego
Version
26.14.24-google (versionCode: 2614242)
Analysis Date
Jun 13, 2026
Classes Analyzed
51,408
Feedback helps us improve our analysis
Trusted financial app from major Czech bank Česká spořitelna, featuring strong security systems and fraud detection. A reliable choice for comprehensive financial management, with a few areas in its security implementation and third-party data disclosures that could be strengthened.
Data Security - 2 findings (1 high, 1 medium)
Network Security - 1 finding (1 medium)
Code Safety - 2 findings (1 medium, 1 info)
Privacy - 4 findings (3 low, 1 info)
The following third parties may receive your data:
Security: 79/100
Privacy: 93/100
The app's privacy practices could be strengthened by:
Dynatrace Telemetry Disclosure
The Play Store Data Safety section states "No data shared with third parties," but app performance telemetry and potentially a pseudonymous session identifier are sent to Dynatrace LLC. Updating this disclosure to reflect the third-party monitoring relationship would improve transparency for users in the EU.
PostHog Analytics Destination Clarity
Behavioral analytics events are routed through the bank's own proxy, making the final destination uncertain. Clarifying whether these events are ultimately forwarded to PostHog's US-based service would allow users to make fully informed decisions.
Background Location Tracking Visibility
The TravelHub travel insurance feature re-registers location monitoring after every device reboot without user re-engagement. A clear opt-in reminder following a restart would give users better visibility and control over this ongoing background access.
Stronger Key Material Generation
The system that generates the primary key protecting all stored security data uses a very limited random value, creating a small but real theoretical window on compromised devices. Using a properly sized random value here would substantially reduce this risk.
Web Content Bridge Restrictions
The bridge connecting the app's web content to its core functions accepts a broad range of actions and network requests without a defined list of what is and is not permitted. Restricting this to an explicit allowed set would contain any impact if the bank's web content were ever compromised.
App Type: Financial banking application (high data sensitivity)
Classes Analyzed: 51,408
Third-Party Services: 13 identified
Context Tags: financial, sensitive_data, location, biometrics
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
Developer: Česká spořitelna, a.s.
Version: 26.14.24-google (versionCode: 2614242)
Analysis Date: 2026-06-13
Package: cz.csas.georgego
Developer not yet contacted