Reverse engineering Android apps is trivial.
Don't use "well it's not open source" as a security argument. Reverse engineers walk among you.
Conversation
One of my first RE experiences was removing cert pinning code so I could mitm Android app API calls.
2

