₹

6. SDK Audit

ENX Money • Enterprenex Solutions Pvt Ltd

Google Play Third-Party Code Governance • Verified

Purpose

Developers are responsible for the data practices of every third-party SDK embedded in the app — not just their own first-party code. This audit tracks every SDK, what it collects, and whether it’s actually necessary.

6.1 Common SDKs Requiring Review

Google Play specifically scrutinizes the following categories of third-party SDKs commonly embedded in mobile applications:

6.2 SDK Register

Part A: Common Sensitive Third-Party SDK Review

SDK Purpose Data Collected Required? Privacy Impact In Data Safety? Status in ENX Money
FirebaseAnalytics / TelemetryDevice IDs, IP, app eventsNoMediumDeclared Not CollectedNOT INTEGRATED
AdMobIn-app advertisingAdvertising ID (AAID), Device infoNoHighDeclared Not CollectedNOT INTEGRATED (100% Ad-Free)
Google Maps SDKLocation servicesPrecise / Coarse LocationNoHighDeclared Not CollectedNOT INTEGRATED (Dropdowns used)
Payment SDKs (Razorpay/Stripe)Card/UPI paymentsCard numbers, UPI VPAs, billing dataNoHighDeclared Not CollectedNOT INTEGRATED (Zero fee utility)
SentryError monitoringCrash logs, device metadataNoMediumDeclared Not CollectedNOT INTEGRATED (Internal logging)
Facebook SDKSocial tracking / loginUser profile, device advertising IDNoHighDeclared Not CollectedNOT INTEGRATED
OneSignalPush messagingPush tokens, player IDs, device infoNoMediumDeclared Not CollectedNOT INTEGRATED (System intents used)
External AI APIsCloud ML processingUser queries, ledger dataNoHighDeclared Not CollectedNOT INTEGRATED (Deterministic logic)
Social Login SDKsSocial authenticationSocial profiles, OAuth tokensNoMediumDeclared Not CollectedNOT INTEGRATED (Email OTP auth)

Part B: Verified Build Dependencies (client/pubspec.yaml)

Package / Library Version Purpose Data Collected / Transmitted Required? Privacy Impact
Flutter Framework^3.13.1Core UI engine & widget renderingNoneYesNone
flutter_localizationssdkMulti-language localization supportNoneYesNone
http^1.2.2REST API communication with secure backendNetwork payloads (Auth, ledger entries)YesLow
shared_preferences^2.3.0Local storage for session token & themeOn-device key-values (App sandbox)YesLow
local_auth^2.3.0Biometric fingerprint / Face Unlock on deviceHardware challenge only; stays in TEEYesHigh (Secured)
uuid^4.5.1RFC4122 v4 transaction idempotency keysNone (Deterministic algorithm)YesNone
url_launcher^6.3.0Launch external legal URLs & OS dialerNoneYesLow
pdf^3.11.1Offline client-side invoice / report PDF renderNone (In-memory)YesLow
printing^5.13.2Native Android print manager invocationDocument stream to local printer spoolerYesLow
fl_chart^0.69.0Vector charts for financial analytics UINone (Client-side rendering)YesNone
excel^4.0.6Offline ledger spreadsheet export (.xlsx)None (In-memory file creation)YesLow
path_provider^2.1.4Locates app-specific storage directoryNone (Sandbox directory query)YesLow
share_plus^10.0.2Android system Share Sheet for ledger receiptsText snippet or file URI to OS chooserYesLow
provider^6.1.2Reactive state managementNone (In-memory state)YesNone
google_fonts^6.2.1Typography & aesthetic UI fontsHTTP font asset cachingYesLow
intl^0.20.3Indian Rupee currency & date formattingNoneYesNone
cupertino_icons^1.0.8UI vector iconographyNoneYesNone

6.3 Audit Process

6.4 Key Rule

Key Rule: “The SDK collected the data, not us” is not an acceptable justification. Google places responsibility for third-party code and its data practices on the developer.

Sign-off Checklist