Duolingo: Language & Chess Security & Privacy Scorecard
by Duolingo · iOS
In-app taps and screen interactions are captured by a session replay service. Usage data is shared with over a dozen advertising and analytics companies, including networks linked to Facebook and ByteDance, to serve targeted ads and measure how users installed the app.
Best for
Daily language practice with occasional ads
Avoid if
Users who prefer not to have sessions recorded
Findings
- 0 critical
- 2 high
- 9 medium
- 4 low
- 10 info
1 issue identified across security and privacy analysis.
Top security issues
- App Transport Security globally disabled — blanket bypass enables cleartext traffic for all SDKs
- 7 production API endpoints hardcoded with HTTP URLs enabling credential interception
- Ably SDK credentials with unknown permissions embedded in plaintext in binary
Top privacy issues
- Xiaohongshu SDK transmits behavioral data to Chinese-operated servers with no privacy disclosure or manifest
- Raw contact data (non-users) uploaded to Duolingo servers without on-device hashing
- ByteDance/Pangle ad SDKs (CSJAdSDK, PAGAdSDK) have no Apple privacy manifest — data collection undisclosed, COPPA unverifiable
Full analysis
Version: 7.116.0 (Build 7.116.0.9) | Analyzed: April 1, 2026
What This Means for You
In-app taps and screen interactions are captured by a session replay service. Usage data is shared with over a dozen advertising and analytics companies, including networks linked to Facebook and ByteDance, to serve targeted ads and measure how users installed the app.
Recommendation: Acceptable
Best For: Daily language practice with occasional ads
Avoid If: Users who prefer not to have sessions recorded
Key Findings
Data Security - 2 findings (1 medium, 1 info)
Network Security - 4 findings (2 high, 1 low, 1 info)
Code Safety - 0 findings
Privacy - 10 findings (5 medium, 5 info)
Privacy Concerns
What Data is Collected
- Screen recordings of in-app taps, swipes, and interactions via a session replay service
- App usage patterns, lesson progress, and in-app engagement behavior
- Device identifiers and advertising IDs used for ad targeting and audience profiling
- Install source and referral data showing how users discovered and installed the app
Third-Party Data Sharing
Data is shared with the following third-party services:
- FullStory - Session replay and behavioral analytics
- Facebook / Meta - Advertising, audience targeting, and attribution (Core, Login, Share, and AEM integrations)
- Adjust - Install attribution and marketing analytics
- Liftoff (Vungle) - In-app advertising
- ByteDance / Pangle - In-app advertising (two separate integrations: CSJ and PAG)
- Xiaohongshu (RedNote) - Social platform integration
- QQ Music - Music platform integration
- AppsFlyer - Marketing attribution and analytics
- Google AdMob - In-app advertising
- Unity Ads - In-app advertising
- Firebase Analytics - Usage analytics (noted as disabled in this version)
- Firebase Crashlytics - Crash reporting
- Sentry - Error and performance monitoring
- Zendesk - Customer support
- Ably - Real-time messaging infrastructure
- Google Sign-In - Authentication
Understanding the Scores
| Category | Score |
|---|---|
| Security | 77/100 |
| Privacy | 78/100 |
| Data Security | 93/100 |
| Network Security | 73/100 |
| Code Safety | 92/100 |
| Data Collection | 82/100 |
| Data Sharing | 84/100 |
| User Control | 84/100 |
Positive Security Features
- Locally stored data is handled responsibly, reflected in a Data Security score of 93 out of 100.
- Application code follows safe development practices, reflected in a Code Safety score of 92 out of 100.
- Data Collection, Data Sharing, and User Control scores all exceed 80 out of 100, indicating above-average privacy practices compared to the broader app ecosystem.
Areas for Improvement
- Two network-level issues pose a moderate risk to user data during transmission. While unlikely to affect routine app use, they represent configurations that fall short of current best practices.
- The session replay service records granular details of how users interact with the app, going beyond typical analytics and giving a third party detailed insight into in-app behavior.
- The advertising and tracking footprint is broad. Over a dozen third-party companies receive data about user activity, including advertising networks with ties to Facebook and ByteDance.
About This Analysis
This scorecard is based on automated static analysis of the application package. Scores reflect the security and privacy posture of the app at the time of analysis and may change with future updates.
App Details
| Field | Value |
|---|---|
| Package | com.duolingo.DuolingoMobile |
| Version | 7.116.0 (Build 7.116.0.9) |
| Platform | Android |
| Scan Date | April 1, 2026 |
| Severity Breakdown | 2 high, 9 medium, 4 low, 10 info |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 77/100 |