Duolingo: Language & Chess Security & Privacy Scorecard

by Duolingo · iOS

77
Overall trust score
Acceptable
77
Security
78
Privacy

In-app taps and screen interactions are captured by a session replay service. Usage data is shared with over a dozen advertising and analytics companies, including networks linked to Facebook and ByteDance, to serve targeted ads and measure how users installed the app.

Best for

Daily language practice with occasional ads

Avoid if

Users who prefer not to have sessions recorded

Findings

  • 0 critical
  • 2 high
  • 9 medium
  • 4 low
  • 10 info

1 issue identified across security and privacy analysis.

Top security issues

  • App Transport Security globally disabled — blanket bypass enables cleartext traffic for all SDKs
  • 7 production API endpoints hardcoded with HTTP URLs enabling credential interception
  • Ably SDK credentials with unknown permissions embedded in plaintext in binary

Top privacy issues

  • Xiaohongshu SDK transmits behavioral data to Chinese-operated servers with no privacy disclosure or manifest
  • Raw contact data (non-users) uploaded to Duolingo servers without on-device hashing
  • ByteDance/Pangle ad SDKs (CSJAdSDK, PAGAdSDK) have no Apple privacy manifest — data collection undisclosed, COPPA unverifiable

Full analysis

Version: 7.116.0 (Build 7.116.0.9) | Analyzed: April 1, 2026

What This Means for You

In-app taps and screen interactions are captured by a session replay service. Usage data is shared with over a dozen advertising and analytics companies, including networks linked to Facebook and ByteDance, to serve targeted ads and measure how users installed the app.

Recommendation: Acceptable

Best For: Daily language practice with occasional ads
Avoid If: Users who prefer not to have sessions recorded

Key Findings

Data Security - 2 findings (1 medium, 1 info)

Network Security - 4 findings (2 high, 1 low, 1 info)

Code Safety - 0 findings

Privacy - 10 findings (5 medium, 5 info)

Privacy Concerns

What Data is Collected

  • Screen recordings of in-app taps, swipes, and interactions via a session replay service
  • App usage patterns, lesson progress, and in-app engagement behavior
  • Device identifiers and advertising IDs used for ad targeting and audience profiling
  • Install source and referral data showing how users discovered and installed the app

Third-Party Data Sharing

Data is shared with the following third-party services:

  • FullStory - Session replay and behavioral analytics
  • Facebook / Meta - Advertising, audience targeting, and attribution (Core, Login, Share, and AEM integrations)
  • Adjust - Install attribution and marketing analytics
  • Liftoff (Vungle) - In-app advertising
  • ByteDance / Pangle - In-app advertising (two separate integrations: CSJ and PAG)
  • Xiaohongshu (RedNote) - Social platform integration
  • QQ Music - Music platform integration
  • AppsFlyer - Marketing attribution and analytics
  • Google AdMob - In-app advertising
  • Unity Ads - In-app advertising
  • Firebase Analytics - Usage analytics (noted as disabled in this version)
  • Firebase Crashlytics - Crash reporting
  • Sentry - Error and performance monitoring
  • Zendesk - Customer support
  • Ably - Real-time messaging infrastructure
  • Google Sign-In - Authentication

Understanding the Scores

Category Score
Security 77/100
Privacy 78/100
Data Security 93/100
Network Security 73/100
Code Safety 92/100
Data Collection 82/100
Data Sharing 84/100
User Control 84/100

Positive Security Features

  • Locally stored data is handled responsibly, reflected in a Data Security score of 93 out of 100.
  • Application code follows safe development practices, reflected in a Code Safety score of 92 out of 100.
  • Data Collection, Data Sharing, and User Control scores all exceed 80 out of 100, indicating above-average privacy practices compared to the broader app ecosystem.

Areas for Improvement

  • Two network-level issues pose a moderate risk to user data during transmission. While unlikely to affect routine app use, they represent configurations that fall short of current best practices.
  • The session replay service records granular details of how users interact with the app, going beyond typical analytics and giving a third party detailed insight into in-app behavior.
  • The advertising and tracking footprint is broad. Over a dozen third-party companies receive data about user activity, including advertising networks with ties to Facebook and ByteDance.

About This Analysis

This scorecard is based on automated static analysis of the application package. Scores reflect the security and privacy posture of the app at the time of analysis and may change with future updates.

App Details

Field Value
Package com.duolingo.DuolingoMobile
Version 7.116.0 (Build 7.116.0.9)
Platform Android
Scan Date April 1, 2026
Severity Breakdown 2 high, 9 medium, 4 low, 10 info

Versions & scan history

ScanDateOverall score
#1 (current) 77/100