City Walks Security & Privacy Scorecard
Android
Usage patterns and crash data are shared with Firebase, Google's analytics and crash-reporting platform. In-app purchases are processed through Google Play Billing. Beyond that, data stays within the app and is not shared with advertising or marketing companies.
Best for
City explorers comfortable with Firebase analytics
Findings
- 0 critical
- 1 high
- 3 medium
- 2 low
- 3 info
1 issue identified across security and privacy analysis.
Top security issues
- Google Play Purchase Tokens Stored Without Encryption
- Firebase Firestore Configured for Emulator in Release Build
- HTTP Logging Interceptor Enabled in Production Build
Top privacy issues
- GDPR Consent Stored in Unencrypted SharedPreferences
- App Configuration Stored in Unencrypted DataStore
- Excellent Privacy Practices - GDPR Compliant
Full analysis
City Walks
Package: eu.walkthecity
Version: 3.5.0 (Build 84)
Platform: Android
Analyzed: March 5, 2026
What This Means for You
Usage patterns and crash data are shared with Firebase, Google's analytics and crash-reporting platform. In-app purchases are processed through Google Play Billing. Beyond that, data stays within the app and is not shared with advertising or marketing companies.
Recommendation: Trustworthy
Best For: City explorers comfortable with Firebase analytics
Key Findings
Data Security - 1 finding (1 high)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 3 findings (1 medium, 1 low, 1 info)
Privacy Concerns
What Data is Collected
The app collects usage patterns and performance data through Firebase Analytics, Firebase Performance Monitoring, and Firebase Remote Config. Crash reports, including device state at the time of a crash, are sent to Firebase Crashlytics. In-app purchase transactions are handled by Google Play Billing. Map interactions are powered by the Google Maps SDK.
Third-Party Data Sharing
Usage and crash data is shared with Google through Firebase services. No advertising networks or marketing companies receive user data.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 88/100 |
| Privacy | 96/100 |
| Data Security | 88/100 |
| Network Security | 100/100 |
| Code Safety | 90/100 |
| Data Collection | 97/100 |
| Data Sharing | 100/100 |
| User Control | 97/100 |
Positive Security Features
- No advertising or marketing tracking networks detected in the app
- Network communications follow current secure practices
- Data sharing is limited to core functionality services, with no third-party data brokers or marketing companies involved
Areas for Improvement
- How the app stores certain data on the device could be strengthened to better protect that information.
- The range of behavioral data collected through Firebase could be communicated more clearly to provide a fuller picture of what activity is tracked during walks.
- Some privacy-related data collection practices could offer more granular controls, giving users greater say over what information is gathered.
About This Analysis
This scorecard is generated through automated static analysis of the app's code and configuration. Scores reflect the security and privacy practices observed in the analyzed version.
App Details
- App Name: City Walks
- Package ID: eu.walkthecity
- Version: 3.5.0 (Version Code 84)
- Scan Date: March 5, 2026
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 92/100 | |
| #2 | 100/100 |