I fail to find an answer on google and I am concerned about my keyPassword, storePassword, and other information which is clearly visible on my build.gradle(Module:app).
I have gone throught the following documentation link but wasn't convinced:
https://developer.android.com/studio/publish/app-signing.html
It states:
Because the debug certificate is created by the build tools and is insecure by design, most app stores (including the Google Play Store) will not accept an APK signed with a debug certificate for publishing.
Does this mean anyone who finds my debug app, which is installed directly from Android Studio, will be able to find my signing information such as keyPassword and storePassword?
I appreciate any thoughts on this matter.