Finance · Privacy report
Navy Federal icon
Navy Federal Credit Union
Free · ★4.9 · Navy Federal Credit Union

Is Navy Federal safe?

It leans heavily on third-party trackers.

Our take. Navy Federal is built with more third-party tracking code than 90% of the finance we have scanned.

Privacy footprint · vs 80 financeHeavy
Trackers from other companies12 · a lot
typical finance: 3.5
Data the app links to you0 types · little
typical finance: 6 · from its own privacy label
What it collects about you

It links almost nothing to you.

Navy Federal's own App Store privacy label declares it links no data to your identity. That is rare, and it is a good sign.
Who else is inside

It carries trackers from 2 companies.

Third-party SDKs found in the app, matched to the company that publishes each. Present in the code; we do not observe what they transmit.

🏢Other third partiesanalytics
A third-party SDK.
9
SDKs
🇺🇸GoogleAnalytics
Firebase, AdMob and Google analytics SDKs, built to record how you use the app and serve ads.
3
SDKs
How it compares

Where it sits among finance.

Every one of these apps we have scanned, on the two measures above: third-party trackers it carries (across) and data it links to you on its own label (up). Toward the top right is more invasive.

Each dot is one finance app. Navy Federal sits to the right, carrying more third-party tracking than most.

The evidence

What it's built from.

All 34 SDKs in the app, grouped by what they are for. 12 are third-party trackers.

12
1
21
12analytics
1crash reporting
21standard libraries

12 of the 34 are third-party trackers. The rest are the app's own code and standard open-source building blocks.

Show the full SDK list
Other third partiesanalytics
LaunchDarkly · Salesforce Marketing Cloud · Salesforce Marketing Cloud SDK · Adobe Analytics · Adobe Experience Platform · Adobe Identity · Adobe Lifecycle · Adobe Rules Engine · Adobe Services
GoogleAnalytics · USA
Firebase Core · Firebase Remote Config Interop · Firebase Sessions
Standard libraries21 · on-device
The app's own code plus open-source interface, storage and networking libraries.

How we know this

Counterspy downloads the app from the App Store and statically analyzes its compiled binary. Embedded SDKs are matched against a signature database and resolved to the company that operates each. We also read the developer's App Store privacy label, which lists the data the app says it collects and links to you. We do not run the app or intercept its traffic, so we report capabilities present in the code and the developer's own disclosures, not proven transmission. We assess privacy and data collection, not malware, security flaws, or developer intent. Reports are automated and never edited for payment. Scan v2026.3.2, 2026-04-01.

  1. Third-party trackers are advertising, analytics and attribution SDKs detected by static signature matching. Presence shows a capability is compiled in, not that it ran or transmitted data.
  2. "Data the app links to you" is the count of data categories the developer declares as Data Linked To You in its App Store privacy label. Labels are self-reported and not verified by Apple.
  3. Comparison across the 80 finance in our corpus. Trackers: median 3.5. Data linked to you: median 6.