Scan results

    Notepad

    Android

    A note-taking application with biometric authentication and Google Drive backup support. Includes ad support for free usage.

    CITT SCORE
    74
    out of 100
    TRUSTish

    Quick Verdict

    Best for: Note-takers comfortable with ad-supported apps

    Not For: You prefer ad-free tools

    What It Means For You

    Usage patterns are shared with AppLovin, an advertising network, which may use that behavior to serve targeted ads. Notes can sync to Google Drive, meaning note data touches Google's servers. Local note storage has limitations that mean note content may not be fully protected if the device is compromised.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (8)

    Data Security

    4 total
    1 Critical
    2 High
    1 Medium

    Network Security

    1 total
    1 High

    Code Security

    1 total
    1 Low

    Privacy

    2 total
    2 Medium

    Third-Party Services

    AppLovin MAX, Google Drive API, Google Play Services, OkHttp3, Gson, ExoPlayer

    Security Strengths

    • No SQL injection vulnerabilities (Room ORM with parameterized queries)
    • No weak cryptography detected in app code
    • No JavaScript interfaces in WebViews (eliminates RCE vector)
    • OAuth 2.0 with PKCE for Google Drive authentication
    • All third-party SDKs on patched versions (no active CVEs)
    • Minimal user tracking (no note content sent to analytics)
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    productivity
    notes
    cloud backup
    ads
    biometric auth

    Package

    jikansoftware.com.blocdenotas

    Version

    4.0.4

    Analysis Date

    Feb 9, 2026

    0

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 4 findings (1 critical, 2 high, 1 medium)

    Network Security - 1 finding (1 high)

    Code Safety - 0 findings

    Privacy - 2 findings (2 medium)

    Privacy Concerns

    What Data is Collected

    Behavioral and usage data is collected through AppLovin MAX to support advertising. If Google Drive sync is enabled, note content is transmitted to and stored on Google's servers.

    Third-Party Data Sharing

    ServicePurpose
    AppLovin MAXAdvertising and behavioral targeting
    Google Drive APICloud note synchronization
    Google Play ServicesCore platform services

    Understanding the Scores

    CategoryScore
    Security70/100
    Privacy78/100
    Data Security55/100
    Network Security85/100
    Code Safety100/100
    Data Collection100/100
    Data Sharing100/100
    User Control88/100

    Positive Security Features

    • None identified for this version.

    Areas for Improvement

    • Local storage of notes could be better protected, reducing the risk of note content being read if the device is lost or stolen.
    • Data stored on the device is not fully secured, which means note contents may not be fully protected under certain conditions.
    • Some network communications would benefit from stronger protections to reduce the chance of interception.

    About This Analysis

    App Details

    FieldValue
    Packagejikansoftware.com.blocdenotas
    Version4.0.4
    Scan Date2026-02-09
    Developer-

    Scores reflect automated static analysis. Real-world risk depends on how the app is used and the device configuration.

    Right of Reply

    Developer not yet contacted