Money Lover: Money Manager Security & Privacy Scorecard
by Finsify JSC · iOS
Financial records and spending habits are shared with multiple advertising and analytics companies, including Facebook and location-data services. Personal financial data is handled with weaker-than-expected protections given what the app holds. Users may see targeted ads based on their money management activity.
Best for
Casual expense tracking with low financial sensitivity
Avoid if
Users storing full financial account details
Findings
- 2 critical
- 6 high
- 8 medium
- 3 low
- 7 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted SQLite Database Exposes All Financial Data
- App Transport Security Completely Disabled
- Password Hashes Stored in Local Database Instead of Keychain
Top privacy issues
- Pre-Consent SDK Initialization Cannot Be Verified
- No GDPR Consent Management Platform Detected
- Location Data May Be Shared with Ad SDKs
Full analysis
What This Means for You
Financial records and spending habits are shared with multiple advertising and analytics companies, including Facebook and location-data services. Personal financial data is handled with weaker-than-expected protections given what the app holds. Users may see targeted ads based on their money management activity.
Recommendation: Use With Caution
Best For: Casual expense tracking with low financial sensitivity
Avoid If: Users storing full financial account details
Key Findings
Data Security - 6 findings (1 critical, 2 high, 2 medium, 1 low)
Network Security - 2 findings (1 critical, 1 medium)
Code Safety - 0 findings
Privacy - 5 findings (3 high, 1 medium, 1 low)
Privacy Concerns
What Data is Collected
The app collects behavioral and usage data through multiple analytics services, including Firebase Analytics, CleverTap, and the Facebook SDK. Location-related data is gathered via Foursquare. Advertising identifiers and device information are sent to Google AdMob. Crash reports and performance metrics are collected via Firebase Crashlytics and Firebase Performance.
Third-Party Data Sharing
User data is shared with a broad network of third parties: Google (Firebase Analytics, Crashlytics, Messaging, Remote Config, Performance, Dynamic Links, AdMob, and Sign-In), Facebook, CleverTap for behavioral marketing, Foursquare for location services, Salted Edge and Finsify for financial data connectivity, and additional advertising infrastructure via the User Messaging Platform.
Understanding the Scores
- Security: 42/100
- Privacy: 58/100
- Data Security: 38/100
- Network Security: 55/100
- Code Safety: 78/100
- Data Collection: 75/100
- Data Sharing: 82/100
- User Control: 70/100
Positive Security Features
No notable positive security practices were identified during this analysis.
Areas for Improvement
- Financial data could be better protected in transit and at rest, reducing the chance of it being accessed by unintended parties.
- The number of advertising and analytics services receiving user spending behavior is high for a finance app. Reducing this would give users more control over who sees their financial activity.
- Network communication practices have room to be strengthened so that user data is better protected as it travels between the app and external services.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect the security and privacy posture observed at the time of the scan.
App Details
- Package ID: me.moneylover.ios.Money-Lover
- Version: 8.64.0 (Build 9187)
- Scan Date: 2026-03-27
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 47/100 |