ENX Money • Enterprenex Solutions Pvt Ltd
Google Play Third-Party Code Governance • VerifiedDevelopers are responsible for the data practices of every third-party SDK embedded in the app — not just their own first-party code. This audit tracks every SDK, what it collects, and whether it’s actually necessary.
Google Play specifically scrutinizes the following categories of third-party SDKs commonly embedded in mobile applications:
| SDK | Purpose | Data Collected | Required? | Privacy Impact | In Data Safety? | Status in ENX Money |
|---|---|---|---|---|---|---|
| Firebase | Analytics / Telemetry | Device IDs, IP, app events | No | Medium | Declared Not Collected | NOT INTEGRATED |
| AdMob | In-app advertising | Advertising ID (AAID), Device info | No | High | Declared Not Collected | NOT INTEGRATED (100% Ad-Free) |
| Google Maps SDK | Location services | Precise / Coarse Location | No | High | Declared Not Collected | NOT INTEGRATED (Dropdowns used) |
| Payment SDKs (Razorpay/Stripe) | Card/UPI payments | Card numbers, UPI VPAs, billing data | No | High | Declared Not Collected | NOT INTEGRATED (Zero fee utility) |
| Sentry | Error monitoring | Crash logs, device metadata | No | Medium | Declared Not Collected | NOT INTEGRATED (Internal logging) |
| Facebook SDK | Social tracking / login | User profile, device advertising ID | No | High | Declared Not Collected | NOT INTEGRATED |
| OneSignal | Push messaging | Push tokens, player IDs, device info | No | Medium | Declared Not Collected | NOT INTEGRATED (System intents used) |
| External AI APIs | Cloud ML processing | User queries, ledger data | No | High | Declared Not Collected | NOT INTEGRATED (Deterministic logic) |
| Social Login SDKs | Social authentication | Social profiles, OAuth tokens | No | Medium | Declared Not Collected | NOT INTEGRATED (Email OTP auth) |
| Package / Library | Version | Purpose | Data Collected / Transmitted | Required? | Privacy Impact |
|---|---|---|---|---|---|
| Flutter Framework | ^3.13.1 | Core UI engine & widget rendering | None | Yes | None |
| flutter_localizations | sdk | Multi-language localization support | None | Yes | None |
| http | ^1.2.2 | REST API communication with secure backend | Network payloads (Auth, ledger entries) | Yes | Low |
| shared_preferences | ^2.3.0 | Local storage for session token & theme | On-device key-values (App sandbox) | Yes | Low |
| local_auth | ^2.3.0 | Biometric fingerprint / Face Unlock on device | Hardware challenge only; stays in TEE | Yes | High (Secured) |
| uuid | ^4.5.1 | RFC4122 v4 transaction idempotency keys | None (Deterministic algorithm) | Yes | None |
| url_launcher | ^6.3.0 | Launch external legal URLs & OS dialer | None | Yes | Low |
| ^3.11.1 | Offline client-side invoice / report PDF render | None (In-memory) | Yes | Low | |
| printing | ^5.13.2 | Native Android print manager invocation | Document stream to local printer spooler | Yes | Low |
| fl_chart | ^0.69.0 | Vector charts for financial analytics UI | None (Client-side rendering) | Yes | None |
| excel | ^4.0.6 | Offline ledger spreadsheet export (.xlsx) | None (In-memory file creation) | Yes | Low |
| path_provider | ^2.1.4 | Locates app-specific storage directory | None (Sandbox directory query) | Yes | Low |
| share_plus | ^10.0.2 | Android system Share Sheet for ledger receipts | Text snippet or file URI to OS chooser | Yes | Low |
| provider | ^6.1.2 | Reactive state management | None (In-memory state) | Yes | None |
| google_fonts | ^6.2.1 | Typography & aesthetic UI fonts | HTTP font asset caching | Yes | Low |
| intl | ^0.20.3 | Indian Rupee currency & date formatting | None | Yes | None |
| cupertino_icons | ^1.0.8 | UI vector iconography | None | Yes | None |