# Security & Privacy Scorecard

## AnyList: Grocery Shopping List

**Security Score:** 55/100 | **Privacy Score:** 45/100

## What This Means for You

In-app behavior is tracked by Segment and Mixpanel, and usage data flows to Firebase Analytics. Crash reports are sent to Bugsnag. Grocery lists and shopping habits are shared with eMeals, a meal planning partner.

## Recommendation: Use With Caution

**Best For:** Grocery planners comfortable with standard analytics

## Key Findings

**Data Security** - 2 findings (2 medium)

**Network Security** - 3 findings (1 critical, 1 high, 1 medium)

**Code Safety** - 0 findings

**Privacy** - 5 findings (4 high, 1 medium)

## Privacy Concerns

### What Data is Collected

The app collects grocery lists, in-app activity, and device identifiers. Shopping habits and usage patterns are gathered to support analytics services and third-party integrations.

### Third-Party Data Sharing

App data is shared with the following third-party services:

- **Segment** and **Mixpanel**: behavioral analytics tracking in-app actions
- **Firebase Analytics**: usage and engagement tracking by Google
- **Firebase Cloud Messaging**: push notification delivery
- **Bugsnag**: crash and error reporting
- **Google Maps** and **Google Play Services Location**: location-based features
- **eMeals**: grocery list and shopping habit data for meal planning integration

## Understanding the Scores

| Category | Score |
|---|---|
| Security | 55/100 |
| Privacy | 45/100 |
| Data Security | 75/100 |
| Network Security | 35/100 |
| Code Safety | 60/100 |
| Data Collection | 50/100 |
| Data Sharing | 40/100 |
| User Control | 45/100 |

## Positive Security Features

- The app relies on standard platform protections without additional security-hardening measures.

## Areas for Improvement

- Network communication sends some data with less protection than expected in certain situations.
- Shopping and usage data is shared with multiple analytics providers, with limited options for users to restrict this.
- The scope of behavioral data collected and shared with partners extends beyond what is needed for core grocery list functionality.

---

## About This Analysis

### App Details

| | |
|---|---|
| **App** | AnyList: Grocery Shopping List |
| **Package** | com.purplecover.anylist |
| **Version** | 2.0.9 (Build 266) |
| **Scan Date** | 2026-01-31 |
