Money manager & expenses Security & Privacy Scorecard
Android
App usage data is collected by AppMetrica (Yandex), Facebook, and VK for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though some app data may travel with less protection than expected on certain connections.
Best for
Users comfortable with Yandex and Google ad-supported apps
Avoid if
Users who prefer apps with no advertising SDKs
Findings
- 0 critical
- 1 high
- 4 medium
- 1 low
- 2 info
1 issue identified across security and privacy analysis.
Top security issues
- Unencrypted SQLite Database Storing Core Financial Data
- Financial Database Not Excluded from Android Auto-Backup
- Missing FLAG_SECURE — Financial Data Visible in Screenshots and App Switcher
Top privacy issues
- Yandex (Russian-Origin) Analytics and Advertising SDKs in Personal Finance App
- Privacy Sandbox Ad Services Configuration Grants Unrestricted Third-Party Access
- Financial Database Not Excluded from Android Auto-Backup
Full analysis
Money manager & expenses
What This Means for You
Your expense records and budgets stay on your device and back up to your Google account, while Yandex analytics may send your device identifiers and usage data to its servers.
Recommendation: Trustworthy
This app is a solid choice for everyday expense tracking, with your login details secured by the Android Keystore and all server connections encrypted. Yandex analytics are included as part of the app's ad-supported model, and your financial records stay on your device but back up to your Google account automatically. Users who want a feature-rich budgeting tool at no cost will find it meets their needs.
Best For: Users who want a comprehensive, free expense tracker and are comfortable with ad-supported analytics.
Key Findings
Data Security - 3 findings (1 high, 2 medium)
Network Security - 1 finding (1 low)
Code Safety - 0 findings
Privacy - 3 findings (2 medium, 1 info)
Privacy Concerns
What Data is Collected
- Financial data: your transactions, accounts, categories, and budgets are accessed on your device and automatically backed up to your Google account
- Device identifiers: your device ID and advertising ID may be sent to Yandex, Google, and Facebook for analytics and advertising purposes
- App usage data: session activity, crash reports, and performance data may be sent to Firebase and Yandex AppMetrica
- Authentication data: if you sign in with Google, your account information is used to authenticate your identity
Third-Party Data Sharing
The following third parties may receive your data:
- Yandex (AppMetrica and Yandex Mobile Ads) - analytics and advertising, subject to Russian data laws
- Google (Firebase Crashlytics, Remote Config, AdMob) - crash reporting, app configuration, and advertising
- Facebook SDK - advertising and analytics
- VK SDK - authentication services
Understanding the Scores
Security: 83/100
Privacy: 88/100
Security Breakdown
- Data Security: 72/100 - Your financial records are stored without encryption on your device, making them readable if your device is physically accessed or your Google account is compromised.
- Network Security: 97/100 - All connections to servers are fully encrypted and no unprotected network requests are made.
- Code Safety: 100/100 - The app's code is built to a high safety standard, with login details protected using the Android Keystore.
Privacy Breakdown
- Data Collection: 93/100 - Your financial records stay on your device and a limited set of analytics services receives usage and device information.
- Data Sharing: 90/100 - Data sharing is limited to a defined set of analytics and advertising partners.
- User Control: 93/100 - You can request that your data be deleted, and advertising measurement requires your consent before it activates.
Positive Security Features
- Login details and passwords are stored securely on your device using the Android Keystore
- Firebase Analytics is turned off, reducing unnecessary data collection
- Google sign-in uses a secure code-exchange method that protects your account from interception
- All network connections are encrypted with no exceptions
- No sensitive service keys are embedded in the app
- Advertising measurement is deferred until you give your consent
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
Financial Database Backup Exclusion
Your complete financial history is included in automatic Google account backups. Excluding the database from backups would ensure your transaction history remains on your device only.Advertising Data Access Restriction
The advertising configuration currently permits any installed app to access behavioral and attribution data. Restricting this to a defined list of approved partners would reduce unintended data exposure.
Security Enhancements
On-Device Data Protection
Your financial records are stored without encryption on the device. Enabling database encryption would protect your data if your device is lost, stolen, or physically accessed.Screen Content Protection
Your financial screens may appear in Android's app switcher and could be captured in screenshots. Enabling screen protection would prevent this passive exposure without affecting normal app use.Production Configuration Cleanup
A test web address is registered in the production app links configuration. Removing it would ensure all link routing works reliably on Android 12 and above.
Technical Context
App Type: Personal finance manager with ad-supported model and multiple analytics integrations
Classes Analyzed: 17,587
Third-Party Services: 12
Context Tags: financial, sensitive_data, ads
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
App Details
Developer: Orange dog d.o.o.
Version: 1.12.0 (versionCode 4237)
Analysis Date: 2026-06-13
Package: ru.innim.my_finance
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on APK version 1.12.0 analyzed on 2026-06-13
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 84/100 |