Mastodon Security & Privacy Scorecard
Android
Posts and interactions stay on the server the user chooses, not a corporate platform. Push notifications are delivered via Firebase, meaning Google handles that data path. Account data and content are not sold to advertisers.
Best for
Open-source social media users who value data control
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- OAuth Access Tokens Stored in Plaintext
- User CA Certificates Trusted (MITM Vulnerability)
- Android Backups Enabled Without Exclusions
Top privacy issues
- Push Notification Metadata Exposure to Google
- HTTP Cache Stores API Responses Unencrypted
- Cache Data Retention Without Expiration Policy
Full analysis
Mastodon
Version: 2.11.9 (Build 158)
Platform: Android
Scan Date: February 7, 2026
What This Means for You
Posts and interactions stay on the server the user chooses, not a corporate platform. Push notifications are delivered via Firebase, meaning Google handles that data path. Account data and content are not sold to advertisers.
Recommendation: Use With Caution
Best For: Open-source social media users who value data control
Key Findings
Data Security - 5 findings (1 critical, 2 high, 1 medium, 1 info)
Network Security - 1 finding (1 critical)
Code Safety - 0 findings
Privacy - 1 finding (1 medium)
Privacy Concerns
What Data is Collected
Mastodon collects the information users directly provide: account details, posts, profile content, and media uploads. The app does not build advertising profiles or collect behavioral data about user activity.
Third-Party Data Sharing
Push notifications are routed through Firebase Cloud Messaging and Google C2DM. Google receives notification delivery information when alerts are sent to a user's device. No advertising networks or analytics platforms were observed receiving user activity data.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 85/100 |
| Data Security | 40/100 |
| Network Security | 50/100 |
| Code Safety | 88/100 |
| Data Collection | 100/100 |
| Data Sharing | 92/100 |
| User Control | 100/100 |
Positive Security Features
- Mastodon is open-source, meaning its code is publicly available for independent review
- No advertising or behavioral tracking services are integrated into the app
- Users choose the server where their account and data are stored, keeping control out of any single company's hands
- The app collects only what users actively provide, with no passive data harvesting observed
Areas for Improvement
- The app has data security issues that could put information stored on a user's device at risk under certain conditions.
- Network communication has a critical issue that may affect the security of data traveling between the app and the user's chosen server.
- Addressing these areas would significantly strengthen overall protection for user accounts and content.
About This Analysis
This scorecard is based on static analysis of the app's code and configuration. Scores reflect findings at the time of the scan and may change as the app is updated.
App Details
- App Name: Mastodon
- Package ID: org.joinmastodon.android
- Version: 2.11.9 (Build 158)
- Scan Date: February 7, 2026
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 65/100 |