TrackWay - Outdoor Navigation Security & Privacy Scorecard
Android
Saved routes and location history may not be adequately protected on the device, as the app has a critical issue in how it stores data locally. Ads are served through Google, meaning in-app activity contributes to ad targeting. Data is not forwarded to outside parties beyond Firebase and Google services.
Best for
Casual hiking and trail tracking outdoors
Avoid if
Storing sensitive personal location history
Findings
- 1 critical
- 2 high
- 5 medium
- 2 low
- 1 info
11 issues identified across security and privacy analysis.
Top security issues
- Hardcoded Firebase Shared Authentication Credentials
- Unencrypted OAuth Token Storage
- Unrestricted Backup Exposure of Sensitive Data
Top privacy issues
- Unencrypted GPS Track Data in SharedPreferences
- Firebase Analytics Initialized Without User Consent
- GPX Files Stored Without Encryption
Full analysis
TrackWay - Outdoor Navigation
nl.dibarto.trackway | Version 1.3 (build 95) | Scanned 2026-03-25
Overall Security: 35/100 | Privacy: 52/100
What This Means for You
Saved routes and location history may not be adequately protected on the device, as the app has a critical issue in how it stores data locally. Ads are served through Google, meaning in-app activity contributes to ad targeting. Data is not forwarded to outside parties beyond Firebase and Google services.
Recommendation: Use With Caution
Best For: Casual hiking and trail tracking outdoors
Avoid If: Storing sensitive personal location history
Key Findings
Data Security - 4 findings (1 critical, 2 medium, 1 info)
Network Security - 1 finding (1 high)
Code Safety - 0 findings
Privacy - 4 findings (3 medium, 1 low)
Privacy Concerns
What Data is Collected
The app collects GPS location and route data as part of its navigation features. Firebase Analytics captures in-app usage patterns. Connecting a Strava account allows activity data to flow between the two services.
Third-Party Data Sharing
Usage data is processed by Google and Firebase services, covering analytics and advertising. Google Mobile Ads uses in-app behavior to serve targeted advertisements. No data is shared with outside parties beyond Firebase and Google services.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 52/100 |
| Data Security | 30/100 |
| Network Security | 78/100 |
| Code Safety | 88/100 |
| Data Collection | 82/100 |
| Data Sharing | 100/100 |
| User Control | 87/100 |
Positive Security Features
- This version of the app did not demonstrate notable security hardening practices in the areas reviewed.
Areas for Improvement
- Local storage of route data and location history needs stronger protections to prevent other apps or unauthorized parties from reading it off the device.
- Advertising through Google means in-app behavior contributes to ad targeting. Removing or limiting ad services would reduce the data collected about user activity.
- The Strava integration should offer clearer controls so users can decide exactly which activity data is shared between the two services.
About This Analysis
This scorecard is generated from automated analysis of the app and reflects security and privacy practices observed in the code. It does not require installing the app on a device.
App Details
- App: TrackWay - Outdoor Navigation
- Package: nl.dibarto.trackway
- Version: 1.3 (build 95)
- Scan Date: 2026-03-25
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 40/100 |