AppXpose AppXpose
← All scans
MEDIUM Risk · Score 37/100

Spotify

com.spotify.music

Spotify is a legitimate, well-established music streaming service with 9 verified trackers (Firebase Analytics, Google AdMob, Meta SDK, Branch Attribution, and others) and 5 dangerous permissions granted, including location and microphone access. While the app's core functionality justifies some permissions, the combination of ad-tech SDKs, location tracking, and metadata collection typical of a freemium service creates moderate privacy exposure.

37
out of 100
9
Trackers Found
5
Dangerous Permissions
8
Risk Factors
0
Known Breaches
Score Breakdown

+6
Unexpected Dangerous Permissions

Location, camera, phone state - not core to music streaming

+2
High-Risk Permissions Outside Scope

RECORD_AUDIO + location enable behavioral profiling beyond playback

+8
Verified Trackers (9 total)

Firebase, AdMob, Meta SDK, Branch - heavy ad-tech and attribution stack

+5
Ad-Tech Business Model

Freemium with aggressive ad insertion on free tier

+4
Data Sharing with Third Parties

Listening history, device IDs, location shared with ad networks

-3
Developer Reputation (Spotify AB)

Major publicly-traded company, transparent privacy policy

-2
GDPR Compliance

EU-based (Sweden), full GDPR rights, in-app privacy controls

-1
Encryption in Transit

All traffic uses TLS/HTTPS

Trackers

9 SDKs detected

Hidden inside the code.

Firebase Analytics Analytics
Google Firebase Analytics
Google AdMob Advertising
Meta SDK Advertising
Branch Attribution
Firebase Crashlytics Crash Reporting
Firebase Cloud Messaging Push
Google Sign-In Social
Google Maps Location
Permissions

5 flagged

What it asks for.

high
ACCESS_FINE_LOCATION

Precise GPS - why does a music app need this?

medium
ACCESS_COARSE_LOCATION

Approximate location for regional content

medium
READ_PHONE_STATE

Pauses during calls but also enables fingerprinting

medium
CAMERA

Profile photos and Spotify Codes scanning

high
RECORD_AUDIO

Voice commands - but microphone access on a music app is unusual

Evidence

From the scan.

Spotify scan  - Freemium pricing model and paywall analysis
Freemium pricing model and paywall analysis
Spotify scan  - AI analysis summary with risk score 37
AI analysis summary with risk score 37
Spotify scan  - 9 verified trackers detected by DEX analysis
9 verified trackers detected by DEX analysis

Scan Spotify yourself.

Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.