AppXpose AppXpose
← All scans
MEDIUM Risk · Score 42/100

Uber

com.ubercab

Uber is a legitimate ride-sharing platform with significant data collection practices. Known aggressive data harvesting, metadata collection, and a documented history of privacy incidents elevate the risk profile. The 2016 breach affecting 57 million users was covered up for over a year, and multiple regulatory fines followed.

42
out of 100
5
Trackers Found
2
Dangerous Permissions
8
Risk Factors
1
Known Breaches
Warning

Data Breach: Uber

2016-10-01 · 57,000,000 accounts affected

In 2016, 57 million Uber rider and driver accounts were breached. Uber paid the hackers $100,000 to delete the data and covered up the breach for over a year.

Email addressesNamesPhone numbersDriver license numbers

Regulatory & Legal

2016 data breach affecting 57M users, covered up until 2017. FTC settlement (2017) for deceptive privacy practices. GDPR fines (2018, 2022) for unauthorized tracking and cookie violations.

Score Breakdown

+12
Aggressive location and behavioral data collection

Continuous location tracking, device motion patterns, travel behavior collected beyond rides

+9
Known privacy incidents and fines

2016 breach (57M users, covered up), FTC settlements, GDPR fines (2018, 2022)

+8
Ad and analytics SDKs

5 trackers enable behavioral profiling and cross-app attribution

+7
Metadata sharing with law enforcement

Trip data and location shared without consistent warrant requirements

+6
Payment data handling

Financial data shared with processors, fraud vendors, and analytics firms

-5
No dangerous permissions in manifest

Zero declared dangerous permissions; location via system-level APIs

-4
Frequent security updates

Regular update schedule addresses vulnerabilities

-3
GDPR compliance mechanisms

Data export, deletion requests, consent management - enforcement inconsistent

Trackers

5 SDKs detected

Hidden inside the code.

Google Analytics Analytics
Firebase Analytics Analytics
AppsFlyer Attribution
Google AdMob Advertising
Crashlytics Crash Reporting
Permissions

2 flagged

What it asks for.

high
LOCATION (persistent)

Collects location data even when idle - beyond ride-matching necessity

high
PAYMENT_DATA

Credit cards, bank accounts shared with payment processors and analytics

Scan Uber yourself.

Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.