The basics that cover most risk

Security practices we build in by default
PracticeWhat it means in a Flutter app
No secrets in the appAPI keys that grant privileged access live on the server; the app gets scoped, short-lived tokens
Secure token storageKeystore and Keychain through secure storage packages, never shared preferences
Server-side rulesAnything involving money, permissions or other users' data is checked on the backend
Security rules with testsFirestore and Storage rules per collection, verified with emulator tests
Transport securityHTTPS only; certificate pinning where the threat model justifies it
Least privilegeRequest permissions only when a feature needs them, and explain why

Privacy by design

The safest data is data you never collect. Several of our apps process photos and video entirely on the device; nothing is uploaded, which simplifies both security and the store privacy forms. Our MetaClean app exists because shared media leaks location and device data through metadata, and it strips that data locally with an audit trail. Ask for each feature whether the data needs to leave the phone at all.

SDK hygiene

  • Keep an inventory of every SDK and what it collects
  • Prefer first-party or well-maintained packages; remove unused ones
  • Update dependencies on a schedule and read their changelogs for data changes
  • Match the Data safety form and privacy labels to the inventory on every release

Authentication and sessions

  • Use a managed identity provider rather than custom password handling
  • Refresh tokens securely and expire sessions on sign-out and account deletion
  • Offer biometric unlock for sensitive local data, as our MetaClean history vault does
  • Rate limit and validate every public endpoint on the backend

Before launch

Run a dependency audit, review security rules, check that release builds have obfuscation and no debug endpoints, and confirm that the privacy policy and store forms describe the app as built. Security is also a maintenance task: revisit it on every release that adds an SDK or a new kind of data.