# Security & Privacy Scorecard

## com.burbn.instagram

## What This Means for You

Usage data and device activity may be shared with the app developer and the services it integrates with. The category summary below shows what data the app handles and where it goes, so people can weigh whether it fits their needs.

## Recommendation: Solid

This app has some areas that could be strengthened but rests on a solid foundation for typical use.

**Best For:** Casual social media users comfortable with Meta's extensive analytics and advertising data collection practices

**Avoid If:** Privacy-conscious users who deny ad tracking, as a persistent device ID bypasses ATT refusal and background location is linked to identity for advertising

## Method and Limitations

Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

## Key Findings

**Data Security:** 5 findings (1 medium, 2 low, 2 info)

**Network Security:** 3 findings (1 medium, 1 low, 1 info)

**Code Security:** 5 findings (3 low, 2 info)

**Privacy:** 9 findings (3 medium, 4 low, 2 info)

**Third-Party Risk:** 1 finding (1 info)

**Permission Usage:** 1 finding (1 low)

## Privacy Concerns

### What Leaves the Device

The app's store listing and in-app privacy notices carry its full disclosure of what is sent off the device.

### What Stays on the Device

Any data the app processes only on the device stays under the user's control and is not sent off it.

### Third-Party Data Sharing

**The following third parties may receive user data:**
- GoogleCast 4.8.3
- SpotifyiOS 6.1.0
- FFmpeg/libavcodec (Meta custom build)
- FBSharedFramework (Facebook SDK — FBSDKAppEvents, FBSDKApplicationDelegate)
- Stripe (embedded IAB JavaScript)
- Mastercard SRC (embedded IAB JavaScript)
- Shopify (IAB)
- Meta AR / FBAR
- PyTorch (embedded on-device ML)
- sqlite-vec
- FBAnalytics
- MerlinLog
- XDSPData
- FOA

## Understanding the Scores

**Security:** 82/100
**Privacy:** 74/100

### Security Breakdown

- **Data Security:** 87/100. How the app handles stored data.
- **Network Security:** 82/100. How the app handles data in transit.
- **Code Safety:** 92/100. Overall code hygiene signals.

### Privacy Breakdown

- **Data Collection:** 74/100. Scope of data collected.
- **Data Sharing:** 85/100. Third-party data sharing behavior.
- **User Control:** 74/100. Controls the app offers over personal data.

## Positive Security Features

- API traffic is protected by multi-layer certificate pinning (FBSSLPinningVerifier + SPKI-based proxygen pinner), raising the bar for interception attacks against Instagram's own communications
- Opt-in end-to-end encrypted Direct Messages via the Instamadillo protocol with a dedicated encrypted iCloud backup container — Meta cannot read E2EE DM content even on its servers
- On-device ML inference via embedded PyTorch — AI and recommendation features process data locally with no confirmed server egress

## Areas for Improvement

- The category summary above shows where the app could strengthen its practices.
- Keeping the app on its latest version brings the newest security improvements from the developer.

---

## About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

### App Details

**Developer:** Unknown developer
**Version:** 442.0.0 (Build 1035455812 — compiled 2026-08-07)
**Analysis Date:** 2026-08-11
**Package:** com.burbn.instagram

_Analyzed 2026-08-11 · ruleset citt-ruleset-2026-08-v1 · artifact binary not retained_
