Money Lover: Money Manager Security & Privacy Scorecard

by Finsify JSC · iOS

47
Overall trust score
Unsafe
42
Security
58
Privacy

Financial records and spending habits are shared with multiple advertising and analytics companies, including Facebook and location-data services. Personal financial data is handled with weaker-than-expected protections given what the app holds. Users may see targeted ads based on their money management activity.

Best for

Casual expense tracking with low financial sensitivity

Avoid if

Users storing full financial account details

Findings

  • 2 critical
  • 6 high
  • 8 medium
  • 3 low
  • 7 info

0 issues identified across security and privacy analysis.

Top security issues

  • Unencrypted SQLite Database Exposes All Financial Data
  • App Transport Security Completely Disabled
  • Password Hashes Stored in Local Database Instead of Keychain

Top privacy issues

  • Pre-Consent SDK Initialization Cannot Be Verified
  • No GDPR Consent Management Platform Detected
  • Location Data May Be Shared with Ad SDKs

Full analysis

What This Means for You

Financial records and spending habits are shared with multiple advertising and analytics companies, including Facebook and location-data services. Personal financial data is handled with weaker-than-expected protections given what the app holds. Users may see targeted ads based on their money management activity.

Recommendation: Use With Caution

Best For: Casual expense tracking with low financial sensitivity

Avoid If: Users storing full financial account details

Key Findings

Data Security - 6 findings (1 critical, 2 high, 2 medium, 1 low)

Network Security - 2 findings (1 critical, 1 medium)

Code Safety - 0 findings

Privacy - 5 findings (3 high, 1 medium, 1 low)

Privacy Concerns

What Data is Collected

The app collects behavioral and usage data through multiple analytics services, including Firebase Analytics, CleverTap, and the Facebook SDK. Location-related data is gathered via Foursquare. Advertising identifiers and device information are sent to Google AdMob. Crash reports and performance metrics are collected via Firebase Crashlytics and Firebase Performance.

Third-Party Data Sharing

User data is shared with a broad network of third parties: Google (Firebase Analytics, Crashlytics, Messaging, Remote Config, Performance, Dynamic Links, AdMob, and Sign-In), Facebook, CleverTap for behavioral marketing, Foursquare for location services, Salted Edge and Finsify for financial data connectivity, and additional advertising infrastructure via the User Messaging Platform.

Understanding the Scores

  • Security: 42/100
  • Privacy: 58/100
  • Data Security: 38/100
  • Network Security: 55/100
  • Code Safety: 78/100
  • Data Collection: 75/100
  • Data Sharing: 82/100
  • User Control: 70/100

Positive Security Features

No notable positive security practices were identified during this analysis.

Areas for Improvement

  • Financial data could be better protected in transit and at rest, reducing the chance of it being accessed by unintended parties.
  • The number of advertising and analytics services receiving user spending behavior is high for a finance app. Reducing this would give users more control over who sees their financial activity.
  • Network communication practices have room to be strengthened so that user data is better protected as it travels between the app and external services.

About This Analysis

This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect the security and privacy posture observed at the time of the scan.

App Details

  • Package ID: me.moneylover.ios.Money-Lover
  • Version: 8.64.0 (Build 9187)
  • Scan Date: 2026-03-27

Versions & scan history

ScanDateOverall score
#1 (current) 47/100