Pokémon GO Security & Privacy Scorecard
by Niantic, Inc. · Android
User location, device identifiers, and activity are shared with advertising and analytics companies including Facebook, AppsFlyer, and Quago. Gameplay behavior is tracked across multiple third-party platforms for targeting purposes. Ads are served based on profile data built from this activity.
Best for
Casual players comfortable with broad data sharing
Avoid if
You limit location access to trusted apps only
Findings
- 3 critical
- 4 high
- 11 medium
- 4 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Login Credentials Stored in Plaintext
- Universal File Access Enabled in UniWebView
- Cleartext Traffic Allowed in Manifest
Top privacy issues
- Undisclosed Behavioral Biometrics Data Collection
- Misleading Play Store Data Safety Declaration
- Room Databases Not Encrypted at Application Layer
Full analysis
Pokémon GO
Version: Latest (as of scan)
Scan Date: 2026-02-11
Platform: Android
Overall Security: 45/100
Overall Privacy: 52/100
What This Means for You
User location, device identifiers, and activity are shared with advertising and analytics companies including Facebook, AppsFlyer, and Quago. Gameplay behavior is tracked across multiple third-party platforms for targeting purposes. Ads are served based on profile data built from this activity.
Recommendation: Use With Caution
Best For: Casual players comfortable with broad data sharing
Avoid If: You limit location access to trusted apps only
Key Findings
Data Security - 6 findings (1 critical, 1 high, 4 medium)
Network Security - 4 findings (1 critical, 1 high, 2 medium)
Code Safety - 0 findings
Privacy - 2 findings (1 high, 1 medium)
Privacy Concerns
What Data is Collected
Pokémon GO collects precise location continuously during gameplay, device identifiers, and detailed records of in-app activity including gameplay routes, item purchases, and interaction patterns. This data is used both to operate the game and to build an advertising profile tied to the device.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Facebook SDK - Behavioral data for ad targeting and attribution
- AppsFlyer - Install attribution and cross-app behavioral analytics
- Quago - Location and device-level analytics
- Unity Ads - Ad delivery and targeting
- Firebase - Analytics and crash reporting
- Helpshift - In-app customer support
- Usabilla - User feedback and experience data
- Sentry - Error and performance monitoring
- Google Play Services - Platform and identity services
- Google Maps - Mapping and location services
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 52/100 |
| Data Security | 40/100 |
| Network Security | 48/100 |
| Code Safety | 55/100 |
| Data Collection | 58/100 |
| Data Sharing | 62/100 |
| User Control | 68/100 |
Positive Security Features
- No positive security practices were identified during this analysis.
Areas for Improvement
- The number of advertising and analytics services receiving behavioral and location data is high, extending data sharing well beyond what core gameplay requires.
- Controls that would let users limit data sharing with third-party advertising partners while still using the app are minimal.
- Data transmitted to multiple tracking services increases the number of companies that can build a profile of location patterns and gameplay habits over time.
About This Analysis
This scorecard is based on static analysis of the app's code and observable data-handling behavior. Scores reflect the security and privacy posture of the version analyzed and are intended to help everyday users make informed decisions.
App Details
- App Name: Pokémon GO
- Package ID: com.nianticlabs.pokemongo
- Version: Latest (as of scan)
- Scan Date: 2026-02-11
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 48/100 |