Money manager & expenses Security & Privacy Scorecard

Android

84
Overall trust score
Trustworthy
83
Security
88
Privacy

App usage data is collected by AppMetrica (Yandex), Facebook, and VK for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though some app data may travel with less protection than expected on certain connections.

Best for

Users comfortable with Yandex and Google ad-supported apps

Avoid if

Users who prefer apps with no advertising SDKs

Findings

  • 0 critical
  • 1 high
  • 4 medium
  • 1 low
  • 2 info

1 issue identified across security and privacy analysis.

Top security issues

  • Unencrypted SQLite Database Storing Core Financial Data
  • Financial Database Not Excluded from Android Auto-Backup
  • Missing FLAG_SECURE — Financial Data Visible in Screenshots and App Switcher

Top privacy issues

  • Yandex (Russian-Origin) Analytics and Advertising SDKs in Personal Finance App
  • Privacy Sandbox Ad Services Configuration Grants Unrestricted Third-Party Access
  • Financial Database Not Excluded from Android Auto-Backup

Full analysis

Money manager & expenses

What This Means for You

Your expense records and budgets stay on your device and back up to your Google account, while Yandex analytics may send your device identifiers and usage data to its servers.

Recommendation: Trustworthy

This app is a solid choice for everyday expense tracking, with your login details secured by the Android Keystore and all server connections encrypted. Yandex analytics are included as part of the app's ad-supported model, and your financial records stay on your device but back up to your Google account automatically. Users who want a feature-rich budgeting tool at no cost will find it meets their needs.

Best For: Users who want a comprehensive, free expense tracker and are comfortable with ad-supported analytics.

Key Findings

Data Security - 3 findings (1 high, 2 medium)

Network Security - 1 finding (1 low)

Code Safety - 0 findings

Privacy - 3 findings (2 medium, 1 info)

Privacy Concerns

What Data is Collected

  • Financial data: your transactions, accounts, categories, and budgets are accessed on your device and automatically backed up to your Google account
  • Device identifiers: your device ID and advertising ID may be sent to Yandex, Google, and Facebook for analytics and advertising purposes
  • App usage data: session activity, crash reports, and performance data may be sent to Firebase and Yandex AppMetrica
  • Authentication data: if you sign in with Google, your account information is used to authenticate your identity

Third-Party Data Sharing

The following third parties may receive your data:

  • Yandex (AppMetrica and Yandex Mobile Ads) - analytics and advertising, subject to Russian data laws
  • Google (Firebase Crashlytics, Remote Config, AdMob) - crash reporting, app configuration, and advertising
  • Facebook SDK - advertising and analytics
  • VK SDK - authentication services

Understanding the Scores

Security: 83/100
Privacy: 88/100

Security Breakdown

  • Data Security: 72/100 - Your financial records are stored without encryption on your device, making them readable if your device is physically accessed or your Google account is compromised.
  • Network Security: 97/100 - All connections to servers are fully encrypted and no unprotected network requests are made.
  • Code Safety: 100/100 - The app's code is built to a high safety standard, with login details protected using the Android Keystore.

Privacy Breakdown

  • Data Collection: 93/100 - Your financial records stay on your device and a limited set of analytics services receives usage and device information.
  • Data Sharing: 90/100 - Data sharing is limited to a defined set of analytics and advertising partners.
  • User Control: 93/100 - You can request that your data be deleted, and advertising measurement requires your consent before it activates.

Positive Security Features

  • Login details and passwords are stored securely on your device using the Android Keystore
  • Firebase Analytics is turned off, reducing unnecessary data collection
  • Google sign-in uses a secure code-exchange method that protects your account from interception
  • All network connections are encrypted with no exceptions
  • No sensitive service keys are embedded in the app
  • Advertising measurement is deferred until you give your consent

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. Financial Database Backup Exclusion
    Your complete financial history is included in automatic Google account backups. Excluding the database from backups would ensure your transaction history remains on your device only.

  2. Advertising Data Access Restriction
    The advertising configuration currently permits any installed app to access behavioral and attribution data. Restricting this to a defined list of approved partners would reduce unintended data exposure.

Security Enhancements

  1. On-Device Data Protection
    Your financial records are stored without encryption on the device. Enabling database encryption would protect your data if your device is lost, stolen, or physically accessed.

  2. Screen Content Protection
    Your financial screens may appear in Android's app switcher and could be captured in screenshots. Enabling screen protection would prevent this passive exposure without affecting normal app use.

  3. Production Configuration Cleanup
    A test web address is registered in the production app links configuration. Removing it would ensure all link routing works reliably on Android 12 and above.

Technical Context

App Type: Personal finance manager with ad-supported model and multiple analytics integrations
Classes Analyzed: 17,587
Third-Party Services: 12
Context Tags: financial, sensitive_data, ads


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

App Details

Developer: Orange dog d.o.o.
Version: 1.12.0 (versionCode 4237)
Analysis Date: 2026-06-13
Package: ru.innim.my_finance

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on APK version 1.12.0 analyzed on 2026-06-13
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#3 (current) 84/100