Pocket Casts - Podcast App Security & Privacy Scorecard
Android
Listening habits and in-app activity are tracked by Firebase Analytics and shared with Google. Crash reports sent to Sentry may include device and session details. Account data stored on-device may not be fully protected, so using this app on a shared device puts account information at greater risk.
Best for
Podcast listeners comfortable with standard analytics
Avoid if
You log in on shared or work-managed devices
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Weak Encryption for Authentication Tokens
- Unencrypted Database Containing Sensitive User Data
- Downloaded Podcast Files Stored Unencrypted
Top privacy issues
- Google Engage SDK Shares Sensitive Listening History
- Unencrypted Database Containing Sensitive User Data
- ExoPlayer Cache Contains Partial Episode Audio
Full analysis
Pocket Casts - Podcast App
What This Means for You
Listening habits and in-app activity are tracked by Firebase Analytics and shared with Google. Crash reports sent to Sentry may include device and session details. Account data stored on-device may not be fully protected, so using this app on a shared device puts account information at greater risk.
Recommendation: Use With Caution
Best For: Podcast listeners comfortable with standard analytics
Avoid If: Logging in on shared or work-managed devices
Key Findings
Data Security - 4 findings (1 critical, 2 high, 1 medium)
Network Security - 5 findings (1 medium, 2 low, 2 info)
Code Safety - 0 findings
Privacy - 1 finding (1 medium)
Privacy Concerns
What Data is Collected
The app collects listening activity, in-app behavior, and usage patterns. Crash reports include device identifiers and session details. Account information is stored locally on the device.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Firebase Analytics (Google) - behavioral analytics and usage tracking
- Sentry - crash reporting, which may include device and session details
- Google Engage SDK - engagement and activity data
- Google Play Billing - purchase and subscription data
- Google Sign-In - account authentication data
- Chromecast - playback activity when casting
- Google Wear OS - activity data when using wearable integration
Understanding the Scores
| Category | Score |
|---|---|
| Security | 42/100 |
| Privacy | 48/100 |
| Data Security | 35/100 |
| Network Security | 78/100 |
| Code Safety | 72/100 |
| Data Collection | 75/100 |
| Data Sharing | 70/100 |
| User Control | 82/100 |
Positive Security Features
- No additional security measures beyond standard platform defaults were observed for this app.
Areas for Improvement
- How account information is stored on-device could be strengthened to better protect it if the device is accessed by someone else.
- Some outgoing connections could benefit from stronger safeguards to reduce the chance of data being intercepted in transit.
- The range of third-party services receiving usage data is broad. Users for whom privacy is a priority should weigh this before using the app.
About This Analysis
App Details
| Field | Value |
|---|---|
| App | Pocket Casts - Podcast App |
| Package ID | au.com.shiftyjelly.pocketcasts |
| Version | 7.101 (Build 9386) |
| Scan Date | 2026-01-20 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 45/100 | |
| #1 | 42/100 |