OTP Mobile Banking Moldova Security & Privacy Scorecard
by MOBIASBANCA - OTP GROUP S. A. · iOS
Connections to the bank's servers are well protected and user data is not shared with advertisers. Some concerns exist around how account information is safeguarded while stored on the device itself. The app uses Firebase for push notifications and Google Maps for branch locations, but collects minimal personal data beyond what banking requires.
Best for
OTP Direkt customers managing accounts on mobile
Avoid if
Users on shared or family devices who stay logged in
Findings
- 0 critical
- 1 high
- 4 medium
- 1 low
- 8 info
1 issue identified across security and privacy analysis.
Top security issues
- iTunes File Sharing Enabled for Banking App
- Unvalidated Token Parameter in Custom URL Scheme Handler
- App Group Data Sharing Without Documented Security Controls
Top privacy issues
- Privacy Screen Protection Disabled
- Device Fingerprinting via Persistent localStorage
- iTunes File Sharing Enabled for Banking App
Full analysis
Security: 64/100 | Privacy: 52/100
What This Means for You
Connections to the bank's servers are well protected and user data is not shared with advertisers. Some concerns exist around how account information is safeguarded while stored on the device itself. The app uses Firebase for push notifications and Google Maps for branch locations, but collects minimal personal data beyond what banking requires.
Recommendation: Use With Caution
Best For: OTP Direkt customers managing accounts on mobile
Avoid If: Users on shared or family devices who stay logged in
Key Findings
Data Security - 2 findings (1 high, 1 medium)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 2 findings (2 medium)
Privacy Concerns
What Data is Collected
The app collects the account and transaction information required for banking services. Data collection is limited to what is necessary for the app to function. Location data may be accessed when users use the branch and ATM locator feature powered by Google Maps.
Third-Party Data Sharing
User personal data is not shared with advertising or marketing companies. Firebase Cloud Messaging is used to deliver push notifications from the bank to the device. Google Maps is used solely to display branch and ATM locations. The authentication framework used for secure login does not share user personal data with third parties for commercial purposes.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 64/100 |
| Privacy | 52/100 |
| Data Security | 48/100 |
| Network Security | 100/100 |
| Code Safety | 85/100 |
| Data Collection | 97/100 |
| Data Sharing | 100/100 |
| User Control | 92/100 |
Positive Security Features
- All communication between the app and the bank's servers is fully protected during transmission
- User data is not shared with advertisers or marketing companies
- The app collects only what is necessary to provide banking services
- Strong user controls are in place for managing accounts and app settings
Areas for Improvement
- Account information stored locally on the device could benefit from stronger protection, particularly if the phone is lost or stolen
- Local data storage practices could be hardened to better protect users who share devices or remain logged in
- Additional safeguards around locally cached account data would improve security for all users
About This Analysis
This scorecard is based on static analysis of the app's code and behavior patterns. Scores reflect the app's practices at the time of analysis and may change with future updates.
App Details
- App: md.mobiasbanca.otpdirekt
- Version: 3.1.10 (Build 30110)
- Scan Date: 2026-03-27
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 56/100 |