Session is a private messaging app with end-to-end encryption and strong metadata protection. Built on a decentralized network of user-operated servers, it prevents data leaks and sales.
This app did not meet one of the trust checks in this assessment.
The five trust checks
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
1 totalCode Security
4 totalPrivacy
1 totalThird-Party Risk
2 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
network.loki.messenger
Version
1.32.1 (versionCode 4445) — Play Store shows 1.33.4
Analysis Date
Jun 30, 2026
Classes Analyzed
4,500
Feedback helps us improve our analysis
Session provides exceptional privacy through end-to-end encryption, a metadata-resistant onion routing network, and zero tracking or advertising SDKs. The app is built so that even the servers relaying your messages cannot read them or identify who you are communicating with. Highly recommended for privacy-conscious users seeking secure messaging without sacrificing usability.
Data Security - 2 findings (1 low, 1 info)
Network Security - 1 finding (1 medium)
Code Safety - 4 findings (1 medium, 1 low, 2 info)
Privacy - 3 findings (3 info)
The following third parties may receive your data:
Security: 90/100
Privacy: 97/100
The app's privacy practices could be strengthened by:
Database Protection Key Binding
The key used to protect the message database could be further hardened by binding it to device unlock, so that accessing the protection key requires a PIN, password, or biometric on a physically compromised device.
Session Pro Backend Configuration
The Session Pro subscription service is configured to use a developer-environment server address in the production app. Switching to a dedicated production endpoint would reduce reliance on a development environment for paid feature verification.
App Type: Encrypted private messaging application
Classes Analyzed: 4,500
Third-Party Services: 16
Context Tags: privacy, social, sensitive_data, encrypted_messaging
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
Developer: Session Foundation (Session Technology Stiftung)
Version: 1.32.1 (versionCode 4445)
Analysis Date: 2026-06-30
Package: network.loki.messenger
Developer not yet contacted