Disney+ Security & Privacy Scorecard
Android
Viewing habits and app activity are shared with analytics and engagement services including Braze, Sentry, Datadog, and Conviva. Notification preferences and billing interactions pass through Firebase and Google. OneTrust provides some control over consent, but data collection is active by default.
Best for
Streaming fans comfortable with standard analytics
Findings
- 1 critical
- 2 high
- 5 medium
- 3 low
- 4 info
1 issue identified across security and privacy analysis.
Top security issues
- Debug Mode Can Disable SSL/TLS Certificate Validation
- Unencrypted Authentication Token Storage
- Compose PreviewActivity Exported in Production Build
Top privacy issues
- Room Databases Unencrypted
- Braze SDK Stores Data in Plaintext SharedPreferences
- Unencrypted Cookie Persistence
Full analysis
Disney+
Version: 26.1.2+rc2-2026.02.23
Scan Date: 2026-03-03
What This Means for You
Viewing habits and app activity are shared with analytics and engagement services including Braze, Sentry, Datadog, and Conviva. Notification preferences and billing interactions pass through Firebase and Google. OneTrust provides some control over consent, but data collection is active by default.
Recommendation: Acceptable
Best For: Streaming fans comfortable with standard analytics
Key Findings
Data Security - 3 findings (1 high, 1 medium, 1 info)
Network Security - 2 findings (1 critical, 1 low)
Code Safety - 0 findings
Privacy - 3 findings (2 medium, 1 info)
Privacy Concerns
What Data is Collected
Disney+ collects viewing activity, search history, device identifiers, and interaction patterns within the app. Account details, billing information, and notification preferences are gathered during normal use.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Braze - engagement and messaging platform
- Sentry - error monitoring
- Datadog RUM - real-user performance analytics
- Conviva - streaming quality and behavioral analytics
- Firebase Messaging - notification delivery
- Google Play Services - platform services
- Google Billing Library - payment processing
- OneTrust CMP - consent management
- Google Cast SDK - casting support
- Disney Streaming Services SDK - internal platform services
Understanding the Scores
| Category | Score |
|---|---|
| Security | 82/100 |
| Privacy | 88/100 |
| Data Security | 80/100 |
| Network Security | 85/100 |
| Code Safety | 90/100 |
| Data Collection | 100/100 |
| Data Sharing | 95/100 |
| User Control | 95/100 |
Positive Security Features
- Strong code safety practices reflected in a 90/100 Code Safety score
- High user control score, indicating meaningful consent and preference options through OneTrust
- Data sharing is limited to named, identifiable third-party services with defined purposes
- Data collection scope aligns with app functionality, scoring a perfect 100/100
Areas for Improvement
- A network-level issue was identified that could leave data sent over public Wi-Fi with less protection than expected.
- Some data-handling configurations could be tightened to reduce diagnostic information retained on the device.
- Data collection is active by default, requiring manual adjustment through OneTrust settings to reduce sharing.
About This Analysis
This scorecard is based on automated static analysis of the Disney+ Android app binary. Scores represent the security and privacy posture at the time of the scan.
App Details
- App: Disney+
- Package: com.disney.disneyplus
- Version: 26.1.2+rc2-2026.02.23
- Platform: Android
- Scan Date: 2026-03-03
- Analysis by: canITrustThat.com
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 85/100 |