Quitty: Quit Zyn & Snus Security & Privacy Scorecard
by Victor Gustafsson · iOS
Usage patterns and in-app behavior are collected by analytics services including PostHog and Amplitude. Purchases are handled through RevenueCat, and push notifications are managed by OneSignal. Users have limited control over what data is collected, but nothing is shared with advertising networks.
Best for
Tracking habits with minimal privacy trade-offs
Findings
- 0 critical
- 0 high
- 4 medium
- 1 low
- 7 info
1 issue identified across security and privacy analysis.
Top security issues
- Weak File Protection for SDK Data
- HTTPS Enforcement (100% Compliance)
- Proper SSL/TLS Certificate Validation
Top privacy issues
- Missing App Tracking Transparency (ATT) Implementation
- Third-Party Data Sharing Without Explicit Consent
- Firebase Remote Config Without User Consent
Full analysis
What This Means for You
Usage patterns and in-app behavior are collected by analytics services including PostHog and Amplitude. Purchases are handled through RevenueCat, and push notifications are managed by OneSignal. Users have limited control over what data is collected, but nothing is shared with advertising networks.
Recommendation: Trustworthy
Best For: Tracking habits with minimal privacy trade-offs
Key Findings
Data Security - 1 finding (1 medium)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 4 findings (3 medium, 1 low)
Privacy Concerns
What Data is Collected
In-app behavior, session patterns, and habit tracking activity are collected by PostHog and Amplitude for analytics purposes. Purchase history and subscription status are processed through RevenueCat to manage the user's account. Push notification interactions are tracked through OneSignal. Feature requests and feedback submitted by users may be collected through WishKit.
Third-Party Data Sharing
Behavioral and usage data is shared with PostHog and Amplitude. Subscription and purchase data is shared with RevenueCat. Notification interaction data is shared with OneSignal. Data sharing is limited to these functional service providers, with no advertising or marketing networks receiving user data.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 98/100 |
| Privacy | 72/100 |
| Data Security | 93/100 |
| Network Security | 100/100 |
| Code Safety | 100/100 |
| Data Collection | 82/100 |
| Data Sharing | 85/100 |
| User Control | 40/100 |
Positive Security Features
- All communications with third-party services use secure, up-to-date network protocols
- The codebase consistently applies safe data handling patterns throughout
- Purchases are processed through RevenueCat, a dedicated payment platform, rather than custom-built payment handling
Areas for Improvement
- Users have limited ability to opt out of behavioral data collection. There are no clear in-app controls to restrict what PostHog and Amplitude collect about user habits and activity.
- The app integrates multiple overlapping analytics services, which increases the total volume of data collected about daily usage patterns.
- Greater transparency around data retention periods and account deletion options would give users more meaningful control over personal information held by third-party services.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect the app's technical implementation as of the scan date.
App Details
- App: victor.dev.quittyapp
- Package ID: victor.dev.quittyapp
- Version: 1.20.0 (Build 72)
- Scan Date: 2026-03-28
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 80/100 |