# Security & Privacy Scorecard

## com.mobilefootie.fotmobpro

## What This Means for You

Your usage data and device activity may be shared with the app developer and any services it integrates with. Review the category summary below to decide if it fits your needs.

## Recommendation: Trustworthy

This app generally follows good security and privacy practices.

**Best For:** Football fans comfortable with ad tracking who want comprehensive live scores and stats

**Avoid If:** Privacy-conscious users, those on public Wi-Fi, or paying subscribers who expect tracking-free experience

## Key Findings

**Data Security** - 1 finding (1 medium)

**Network Security** - 3 findings (1 medium, 2 low)

**Code Safety** - 0 findings

**Privacy** - 3 findings (1 medium, 2 low)

## Privacy Concerns

### What Data is Collected

Review the app's store listing and in-app privacy notices for a full data collection disclosure.

### Third-Party Data Sharing

**The following third parties may receive your data:**
- AppsFlyer
- Facebook Audience Network
- Meta SDK (FBSDKCoreKit, FBSDKLoginKit)
- Amazon TAM (DTBiOSSDK)
- NimbusKit (Amazon)
- Google Mobile Ads
- Google Ad Manager
- Google IMA SDK
- VungleAds (Liftoff)
- Fyber Marketplace (InnerActive)
- BlazeSDK
- MolocoSDK
- Firebase Crashlytics
- Firebase Remote Config
- Firebase Dynamic Links
- Google Analytics / App Measurement
- Google UMP (UserMessagingPlatform)
- RevenueCat
- Google Sign-In (AppAuth/GTMAppAuth)
- Twitter OAuth
- SDWebImage
- Alamofire

## Understanding the Scores

**Security:** 88/100
**Privacy:** 87/100

### Security Breakdown

- **Data Security:** 93/100 - how the app handles data at rest
- **Network Security:** 87/100 - how the app handles data in transit
- **Code Safety:** 97/100 - overall code hygiene signals

### Privacy Breakdown

- **Data Collection:** 89/100 - scope of data collected
- **Data Sharing:** 90/100 - third-party data sharing behavior
- **User Control:** 90/100 - controls the app offers you

## Positive Security Features

- Authentication tokens (SYNC_ACCESS_TOKEN) stored in Keychain with AfterFirstUnlockThisDeviceOnly protection
- ATT consent properly implemented with custom pre-prompt UI
- Google UMP GDPR consent management present
- Firebase Analytics disabled (IS_ANALYTICS_ENABLED=false)
- Facebook auto-event logging disabled (FacebookAutoLogAppEventsEnabled=false)
- All first-party API endpoints use HTTPS
- Apple DCAppAttestService (App Attest) integrated for API integrity
- AppsFlyer tracking domains declared as ATT-gated in NSPrivacyTrackingDomains
- Google no-consent fallback state implemented in binary (gad_idless:1, analytics_storage:denied)

## Areas for Improvement

- Review the category summary above for where the app could strengthen its practices.
- Keep the app updated so you receive the latest security improvements from the developer.

---

## About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

### App Details

**Developer:** Unknown developer
**Version:** 1230.0 (Build 16212)
**Analysis Date:** 2026-04-17
**Package:** com.mobilefootie.fotmobpro
