I'm not totally thrilled about having a 'secret' key embedded in the app that's distributed publicly.
I had a brief skim over the code and I can't see any access control stuff so I'm guessing this key has full access.
If that's the case, I can't see how this could ever be suitable for use in any real app.