All data transmission happens over secure communication channels (over HTTPS).
The app does not have any issues with its authentication APIs.
A remote attacker can potentially access user data due to vulnerability in the server endpoints.
The app allows the users to edit their information in the app and delete the account.