# Security & Privacy Scorecard

## OMNI.reporte

## What This Means for You

Activity and crash data are sent to Firebase and Microsoft Azure services. Location may be accessed via Google Maps. Data storage protections are limited, meaning user data may not be fully protected.

## Recommendation: Use With Caution

**Best For:** Reporting news with standard cloud analytics
**Avoid If:** You share sensitive location or personal details

## Key Findings

**Data Security** - 6 findings (1 critical, 3 high, 1 medium, 1 low)

**Network Security** - 3 findings (1 critical, 1 high, 1 medium)

**Code Safety** - 0 findings

**Privacy** - 3 findings (1 high, 2 medium)

## Privacy Concerns

### What Data is Collected

- Crash reports and diagnostic information (via Firebase Crashlytics)
- App session activity and usage patterns (via Firebase Sessions and Firebase Data Transport)
- Performance telemetry and application events (via Azure Application Insights)
- Location data (via Google Maps SDK)
- File and document content (via Azure Blob Storage and Apache Tika)

### Third-Party Data Sharing

Data is shared with the following external services:

- **Firebase (Google)** - receives crash reports, session activity, and app usage data
- **Microsoft Azure** - receives performance data; files may be stored in Azure Blob Storage
- **Google Maps** - accesses location to support mapping features
- **Apache Tika** - processes documents users interact with inside the app

## Understanding the Scores

| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 55/100 |
| Data Security | 30/100 |
| Network Security | 40/100 |
| Code Safety | 35/100 |
| Data Collection | 70/100 |
| Data Sharing | 50/100 |
| User Control | 60/100 |

## Positive Security Features

- No specific positive security practices were identified for this version of the app.

## Areas for Improvement

- **Data storage protections** are limited, meaning user data stored by the app may not be fully protected.
- **Network communications** lack sufficient safeguards, meaning data sent between the app and its servers travels with less protection than expected.
- **Privacy transparency** could be improved so users have a clearer picture of what is collected and meaningful options to limit it.

---

## About This Analysis

This scorecard reflects a static analysis of the app's code and configuration. It evaluates data handling practices, network communication patterns, third-party integrations, and storage behavior.

### App Details

- **App:** OMNI.reporte
- **Package ID:** com.primer_impacto.reporte_pi
- **Version:** 4.35.2
- **Scan Date:** 2026-02-04
- **Developer:** Not specified
