The basics that cover most risk
| Practice | What it means in a Flutter app |
|---|---|
| No secrets in the app | API keys that grant privileged access live on the server; the app gets scoped, short-lived tokens |
| Secure token storage | Keystore and Keychain through secure storage packages, never shared preferences |
| Server-side rules | Anything involving money, permissions or other users' data is checked on the backend |
| Security rules with tests | Firestore and Storage rules per collection, verified with emulator tests |
| Transport security | HTTPS only; certificate pinning where the threat model justifies it |
| Least privilege | Request permissions only when a feature needs them, and explain why |
Privacy by design
The safest data is data you never collect. Several of our apps process photos and video entirely on the device; nothing is uploaded, which simplifies both security and the store privacy forms. Our MetaClean app exists because shared media leaks location and device data through metadata, and it strips that data locally with an audit trail. Ask for each feature whether the data needs to leave the phone at all.
SDK hygiene
- Keep an inventory of every SDK and what it collects
- Prefer first-party or well-maintained packages; remove unused ones
- Update dependencies on a schedule and read their changelogs for data changes
- Match the Data safety form and privacy labels to the inventory on every release
Authentication and sessions
- Use a managed identity provider rather than custom password handling
- Refresh tokens securely and expire sessions on sign-out and account deletion
- Offer biometric unlock for sensitive local data, as our MetaClean history vault does
- Rate limit and validate every public endpoint on the backend
Before launch
Run a dependency audit, review security rules, check that release builds have obfuscation and no debug endpoints, and confirm that the privacy policy and store forms describe the app as built. Security is also a maintenance task: revisit it on every release that adds an SDK or a new kind of data.