Scan results

    Pinterest

    Android

    Pinterest is a visual discovery platform for inspiration and shopping. Create boards, save pins, and explore billions of ideas from fashion and recipes to DIY projects and home décor. Contains ads and interactive content.

    CITT SCORE
    78
    out of 100
    TRUSTish

    Quick Verdict

    Best for: Visual inspiration browsing with standard ad tracking

    Not For: You want to limit ad targeting based on your interests

    What It Means For You

    User activity, interests, and browsing are shared with Facebook, Google Ads, and AppsFlyer to build an ad profile and target users across the web. Firebase and Bugsnag collect usage and crash data. User data touches multiple third-party platforms each time the app is used.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (11)

    Data Security

    1 total
    1 Critical

    Network Security

    4 total
    2 High
    2 Medium

    Code Security

    3 total
    2 High
    1 Medium

    Privacy

    3 total
    1 Critical
    1 High
    1 Medium

    Third-Party Services

    Firebase Analytics, AppsFlyer, Google Ads SDK, AWS SDK, Bugsnag, Facebook SDK, LINE SDK, Google Play Services, Eclipse Paho MQTT, Google Tink

    Security Strengths

    • Google Tink encryption properly implemented (AES-256-GCM with hardware-backed keys)
    • WebView file access restrictions enabled (prevents file:// URL exploits)
    • Play Integrity API for tamper detection (rooted devices, repackaged APKs)
    • Room database uses parameterized queries (SQL injection protection)
    • Proper SSL/TLS validation with no bypass patterns
    • WebView lifecycle cleanup prevents memory leaks and CVE exploits
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    social
    ads
    location
    camera
    sensitive data
    financial

    Package

    com.pinterest

    Version

    14.3.0

    Analysis Date

    Feb 3, 2026

    Classes Analyzed

    47,468

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 1 finding (1 critical)

    Network Security - 4 findings (2 high, 2 medium)

    Code Safety - 0 findings

    Privacy - 3 findings (1 critical, 1 high, 1 medium)

    Privacy Concerns

    What Data is Collected

    Pinterest collects user browsing activity, saved pins, search history, and interaction patterns. This data builds a detailed profile of user interests and preferences that persists across sessions and informs how users are targeted by advertisers.

    Third-Party Data Sharing

    User data is shared with the following third-party platforms:

    • Facebook SDK - Shares behavioral and interest data for cross-platform ad targeting
    • Google Ads SDK - Shares user activity to serve and measure targeted advertising
    • AppsFlyer - Tracks in-app actions and attribution for marketing campaigns
    • Firebase Analytics - Collects usage patterns and session data
    • Bugsnag - Receives crash reports and device diagnostics
    • LINE SDK - Enables social sharing with data transfer to LINE's platform
    • Eclipse Paho MQTT - Handles real-time messaging with data routed through an external broker

    Understanding the Scores

    CategoryScore
    Security82/100
    Privacy75/100
    Data Security70/100
    Network Security85/100
    Code Safety88/100
    Data Collection78/100
    Data Sharing80/100
    User Control75/100

    Positive Security Features

    • Integrates Google Tink, a well-audited cryptographic library, for protecting sensitive data operations
    • Uses Bugsnag for real-time crash monitoring, supporting app stability and issue detection
    • Employs AWS SDK with established cloud infrastructure security practices

    Areas for Improvement

    • Stronger on-device data protection is needed: at least one area where sensitive information is stored on the device does not meet adequate security standards
    • More consistent network security: some data sent from the app uses weaker transmission settings and may travel with less protection than expected on public Wi-Fi
    • Clearer ad tracking controls: user interest and behavioral data flows to multiple advertising platforms, with limited in-app options to restrict or opt out of that sharing

    About This Analysis

    This scorecard reflects the security and privacy posture of the app at the time of analysis. Scores are based on examination of the app's code, configuration, and third-party integrations. Higher scores indicate stronger practices; lower scores indicate areas where user data or the device may be at greater risk.

    App Details

    FieldValue
    App NamePinterest
    Package IDcom.pinterest
    Version14.3.0
    PlatformAndroid
    Scan Date2026-02-03

    Right of Reply

    Developer not yet contacted