Glassdoor | Jobs & Careers Security & Privacy Scorecard
Android
Usage and behavioral data is shared with AppsFlyer, Amplitude, RudderStack, and Firebase Analytics for attribution and engagement tracking. Advertising is served via Google AdManager. Session credentials and auth tokens are stored with strong device-level protection, and app data cannot be extracted via USB backup.
Best for
Job seekers comfortable with standard analytics
Findings
- 0 critical
- 1 high
- 4 medium
- 1 low
- 5 info
2 issues identified across security and privacy analysis.
Top security issues
- Plaintext Room Databases Retain Salary Search History and Post Draft Text
- Indeed OAuth Callback Custom URI Scheme Lacks autoVerify
- Indeed Cross-Platform Tracking Token Injected Into All Glassdoor API Requests
Top privacy issues
- Employment Profile PII Transmitted to RudderStack CDP
- Advertising ID Cross-Referenced With Authenticated Employment Profile
- Indeed Cross-Platform Tracking Token Injected Into All Glassdoor API Requests
Full analysis
Glassdoor | Jobs & Careers
What This Means for You
Your login information is protected by hardware-level security on your device, while your salary research history and employment profile details are shared with third-party analytics and advertising platforms as part of the app's standard data practices.
Recommendation: Trustworthy
Trustworthy for job seekers seeking salary benchmarks and employer reviews. Login information is protected by hardware-level security, and employment activity is shared with standard analytics and advertising platforms. This is consistent with the app's disclosed data safety information on the Play Store.
Best For: Job seekers who want salary benchmarks and employer reviews and accept standard analytics tracking across Indeed and Glassdoor
Key Findings
Data Security - 1 finding (1 medium)
Network Security - 0 findings
Code Safety - 1 finding (1 low)
Privacy - 4 findings (3 medium, 1 info)
Privacy Concerns
What Data is Collected
- Personal information: email address, job title, employment history, and industry identifier shared with RudderStack's customer data platform
- Advertising identifier: your device's advertising ID linked to your employment profile and shared with AppsFlyer and potentially downstream advertising platforms
- Usage data: job search activity and app interactions shared with Amplitude and Firebase Analytics
- Salary search history and post drafts: stored on your device
- Location: approximate location used for job search matching
Third-Party Data Sharing
The following third parties may receive your data:
- AppsFlyer - install attribution and advertising measurement
- Amplitude - behavioral analytics
- RudderStack - customer data platform that may route data to configurable downstream destinations including ad networks and data warehouses
- Firebase Analytics - session and usage tracking
- Google AdManager - in-app advertising
- Datadog - app performance monitoring
- Iterable - marketing communications
- Qualaroo - in-app surveys
Understanding the Scores
Security: 92/100
Privacy: 84/100
Security Breakdown
- Data Security: 91/100 - Login information and session data are protected by the device's hardware security module, and device backup export is disabled across all data types.
- Network Security: 100/100 - All data transmission is encrypted and follows strong network security practices across the entire app.
- Code Safety: 99/100 - The app stores configuration keys in protected native code rather than readable application layers, reflecting strong implementation discipline.
Privacy Breakdown
- Data Collection: 85/100 - Employment profile details, salary research activity, and behavioral data are sent to a multi-platform analytics stack with broad downstream routing capability.
- Data Sharing: 86/100 - Employment profile information and advertising identifiers may be forwarded to multiple downstream platforms through RudderStack's data pipeline with limited in-app transparency.
- User Control: 85/100 - The app provides data deletion options, though in-app visibility into which downstream destinations receive your employment data could be improved.
Positive Security Features
- Configuration keys and service access information stored in protected native code, not accessible through standard app inspection
- Login information and session data protected by the Android hardware security module, keeping them isolated from the rest of the app
- Device backup export disabled across all data types and storage locations, preventing extraction through backup-based methods
- User-generated files such as resumes and photos stored in private app directories with no external storage exposure
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
Transparent Downstream Data Routing
Your employment profile is sent to RudderStack, which can forward it to any number of configured destinations including ad networks and data warehouses. Providing an in-app list of active downstream recipients would give users meaningful insight into where their data goes.Advertising Identifier Consent Disclosure
Your device's advertising ID is linked to your employment profile and sent alongside your email address and job title to analytics platforms. An explicit consent step before this cross-context linking occurs would better align with CCPA and GDPR requirements.Cross-Platform Identity Disclosure
A persistent tracking identifier is shared between Glassdoor and Indeed, linking your activity across both platforms. A prominent disclosure at sign-in would improve transparency for users who may not realize the two services share a tracking identity.
Security Enhancements
Strengthened Login Redirect Verification
The Indeed account linking flow uses a custom URL scheme that lacks Digital Asset Links verification. Adding verification would provide stronger protection against third-party apps intercepting the authentication response, even though the current implementation includes protections that limit the practical impact.Local Database Encryption for Sensitive Search History
Salary search history and post drafts are stored in the local database without additional encryption. Adding database-level encryption would protect this data on devices that are forensically examined.
Technical Context
App Type: Job search and career networking platform (handles sensitive employment and salary data)
Classes Analyzed: 4,200
Third-Party Services: 13
Context Tags: employment, jobsearch, sensitivedata, salary, analytics, tracking, social
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
App Details
Developer: Glassdoor LLC.
Version: 13.4.3 (versionCode 121513)
Analysis Date: 2026-06-13
Package: com.glassdoor.app
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on APK version 13.4.3 analyzed on 2026-06-13
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 86/100 |