Trackwallet: Budget & Expenses Security & Privacy Scorecard

Android

74
Overall trust score
Acceptable
72
Security
78
Privacy

Usage data and session activity is sent to Firebase Analytics. An advertising identifier is collected and shared with Google's ad attribution services. Locally stored financial data may not be fully protected, which is worth considering if the device could be accessed by others.

Best for

Personal income tracking with standard analytics

Avoid if

Users handling sensitive financial data on shared devices

Findings

  • 0 critical
  • 1 high
  • 1 medium
  • 0 low
  • 0 info

1 issue identified across security and privacy analysis.

Top security issues

  • Unencrypted SQLite Database Stores Complete Financial Transaction History

Top privacy issues

  • Active Advertising Attribution Infrastructure Contradicts 'No Data Collection' Marketing Claim

Full analysis

Trackwallet: Budget & Expenses

What This Means for You

If you turn on cloud backup, your complete financial history including all transactions and account balances is sent to Google's servers without the database file itself being encrypted. Ad tracking tools running in the background also contradict the app's marketing claim of no data collection.

Recommendation: Acceptable

Trackwallet works well as an offline budget tracker, but there is a meaningful gap between its privacy marketing and actual behavior. If you enable the optional cloud backup, your complete financial database is uploaded to Google's servers without the file being protected first. Ad attribution infrastructure also runs in the background despite the app claiming no ads and no data collection.

Best For: Users who track expenses locally, skip the cloud backup feature, and are comfortable with ad attribution tools being present in the app.

Key Findings

Data Security - 1 finding (1 high)

Network Security - 0 findings

Code Safety - 0 findings

Privacy - 1 finding (1 medium)

Privacy Concerns

What Data is Collected

  • Financial data (transactions, account balances, budgets): accessed on your device and stored locally. If you enable cloud backup, a copy is sent to Google (Firebase Storage) without the file being separately encrypted.
  • Advertising ID: sent to Google's ad services to support ad attribution tracking.
  • App usage data: may be sent to Google (Firebase Analytics) for performance and usage reporting.

Third-Party Data Sharing

The following third parties may receive your data:

  • Google (Firebase) - receives your financial database if you enable cloud backup, and may receive app usage data through analytics services
  • Google Advertising - receives your advertising ID and device information for ad attribution tracking
  • Google Privacy Sandbox - receives app conversion events through the Attribution API

Understanding the Scores

Security: 72/100
Privacy: 78/100

Security Breakdown

  • Data Security: 60/100 - Your financial data is stored without protection on your device, and the optional cloud backup sends an unprotected copy of that database to Google's servers.
  • Network Security: 100/100 - All network connections use secure, encrypted communication.
  • Code Safety: 100/100 - The app's code follows sound development practices with no concerning patterns identified.

Privacy Breakdown

  • Data Collection: 78/100 - The app sends your advertising ID to Google and may upload usage data, which conflicts with its "no data collection" marketing language.
  • Data Sharing: 87/100 - Data sharing with third parties is limited, primarily through the optional cloud backup and Google's ad attribution infrastructure.
  • User Control: 83/100 - Cloud backup is entirely opt-in and crash reporting has been disabled by the developer, giving you meaningful control over what leaves your device.

Positive Security Features

  • Firebase Crashlytics is explicitly disabled, so crash data is not sent to Google.
  • All network communication uses HTTPS, protecting data while it travels between your device and servers.
  • Cloud backup is entirely opt-in; your financial data stays local if you never enable it.
  • Core budgeting features work fully offline without requiring any network access.

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. Accurate Marketing Language
    The in-app "NO ADS - NO DATA COLLECTION" claim is inconsistent with the active ad attribution infrastructure present in the app. Aligning the marketing language with actual behavior would help users make informed privacy decisions and avoid potential consumer protection concerns.

  2. Consistent Data Safety Disclosures
    The Play Store data safety section acknowledges data collection, but this is not reflected in the in-app marketing. Consistent disclosures across all surfaces would better meet transparency expectations under GDPR and CCPA.

Security Enhancements

  1. Financial Data Protection
    Adding a protection layer to the stored financial database would safeguard your transactions and balances if your phone were accessed by someone without your permission.

  2. Secure Cloud Backup
    Protecting the financial database file before it is uploaded to cloud storage would ensure your complete transaction history remains private even after it leaves your device.

Technical Context

App Type: Personal finance and budgeting (sensitive financial data)
Classes Analyzed: 650
Third-Party Services: 17 identified
Context Tags: financial, sensitive_data, ads


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

App Details

Developer: Trackwallet Expenses & Budget Tracker
Version: 6.1.9
Analysis Date: 2026-06-13
Package: pw.ninthfi.myincome

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on APK version 6.1.9 analyzed on 2026-06-13
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#1 (current) 74/100