Instagram Security & Privacy Scorecard

by Instagram, Inc. · iOS

77
Overall trust score
Acceptable
94
Security
70
Privacy

Activity, interactions, and device data are shared extensively with Meta's analytics and advertising infrastructure. Usage is tracked across 32 declared data types, including browsing behavior and purchase signals. Payment interactions route through Stripe, Mastercard, and Shopify bridges embedded within the app.

Best for

Everyday social sharing within the Meta ecosystem

Avoid if

Users limiting Meta's access to browsing and purchase data

Findings

  • 0 critical
  • 2 high
  • 6 medium
  • 4 low
  • 3 info

1 issue identified across security and privacy analysis.

Top security issues

  • Screenshot Capture Bridge Active in Production IAB Build
  • Direct Message Content Stored in Local SQLite Without Confirmed App-Layer Encryption
  • NSAllowsArbitraryLoadsInWebContent Permits HTTP in WKWebViews Alongside Payment Bridges

Top privacy issues

  • In-App Browser Injects Login Form Field Monitor on All Third-Party Pages
  • In-App Browser Tracks Scroll Depth, Click Coordinates, Dwell Time, and Page Metadata on Third-Party Sites
  • Contact List Periodically Synced to Meta Servers with Advertising as a Declared Use

Full analysis

Instagram

What This Means for You

When you tap external links inside Instagram, the app monitors your login form interactions and browsing activity on those pages and sends that data to Meta.

Recommendation: Acceptable

Works well for casual social sharing. When clicking external links in the app, Instagram monitors login forms and browsing activity on those sites, which is reported to Meta. Staying within the Instagram feed and avoiding external links reduces the scope of data shared with Meta.

Best For: Casual social media users who browse their feed and do not click external links within the app

Key Findings

Data Security - 2 findings (2 low)

Network Security - 1 finding (1 low)

Code Safety - 2 findings (1 medium, 1 low)

Privacy - 10 findings (2 high, 5 medium, 3 info)

Privacy Concerns

What Data is Collected

  • Contact information: your contacts are periodically sent to Meta's servers and declared for both advertising and friend-suggestion purposes
  • Identity data: your name, email address, phone number, and physical address are linked to your identity and used for cross-platform advertising
  • Browsing behavior: when you open external links inside the app, your interactions on those pages, including login form activity, scroll depth, click positions, and page content, are sent to Meta
  • Payment signals: when visiting merchant checkout pages through the app, which payment methods are available and which you tap are reported to Meta
  • Device information: a persistent device identifier is stored in a shared area accessible by all Meta apps on your device and may be used for advertising attribution across Meta's platforms

Third-Party Data Sharing

The following third parties may receive your data:

  • Meta (Facebook) - analytics, advertising measurement, and cross-app identity tracking
  • Stripe - payment processing (when completing transactions through the app)
  • Mastercard - payment processing
  • Giphy - sticker content search and delivery
  • Google Cast - media casting to compatible devices
  • Spotify - music and audio integrations

Understanding the Scores

Security: 94/100
Privacy: 70/100

Security Breakdown

  • Data Security: 94/100 - Sensitive information is handled securely with strong encryption methods protecting your stored data and communications.
  • Network Security: 96/100 - All primary server communications use encrypted connections, keeping your data protected in transit.
  • Code Safety: 92/100 - The app uses modern, well-regarded encryption methods throughout its core operations.

Privacy Breakdown

  • Data Collection: 78/100 - The app collects a broad range of personal data including contacts, identity information, and behavioral signals from third-party sites you visit through the app.
  • Data Sharing: 94/100 - Data sharing is predominantly within Meta's own platforms and a small set of declared payment and content partners.
  • User Control: 74/100 - Privacy controls are available in settings, but end-to-end encryption for direct messages is opt-in rather than the default, and the consent prompt for tracking describes a narrower scope than the app's full tracking practices.

Positive Security Features

  • App Tracking Transparency is properly implemented, with advertising identifier access gated on your explicit consent before use
  • A comprehensive privacy manifest is included, declaring all 32 data types collected by the app with valid purpose codes
  • Payment bridges use strict origin validation to protect your payment data from being intercepted by other pages
  • Modern encryption methods and Secure Enclave key operations are active throughout the app
  • All primary server communications use encrypted connections with strict transport security enforced

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. Tracking Consent Accuracy
    The in-app tracking consent dialog describes its purpose as personalizing ads shown to you, but the app's own privacy declaration covers much broader cross-app identity linking using your name, address, phone number, and device identifier. Updating the consent description to reflect the full scope would give users an accurate picture before they decide.

  2. Contact Access Transparency
    The permission dialog for contacts describes their use for friend suggestions and service improvements. The app's privacy declaration also lists advertising as a declared purpose for contact data. Users should be clearly informed of all uses at the point of requesting permission.

Security Enhancements

  1. End-to-End Encryption Default
    Direct messages are stored locally without confirmed additional encryption by default. End-to-end encryption is available as an opt-in feature. Making it the default for all conversations would better protect message content.

  2. File Protection Coverage
    The app includes the capability to store certain files with reduced iOS data protection. Applying full protection to all locally cached content would reduce exposure in physical device access scenarios.

Technical Context

App Type: Social media with advertising, payments, and third-party browsing
Classes Analyzed: Not applicable (iOS binary analysis)
Third-Party Services: 12 identified
Context Tags: social, ads, contacts, location, camera, sensitive_data, payments


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on iOS applications to help users make informed decisions about app security and privacy.

App Details

Developer: Instagram (Meta Platforms)
Version: 434.0.0 (build 994860828 / FBAppVersion 434.0.0.28.78)
Analysis Date: 2026-06-18
Package: com.burbn.instagram

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on iOS version 434.0.0 analyzed on 2026-06-18
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#3 (current) 77/100
#2 84/100
#1 85/100