# Security & Privacy Scorecard

## com.duolingo.DuolingoMobile

**Version:** 7.116.0 (Build 7.116.0.9) | **Analyzed:** April 1, 2026

## What This Means for You

In-app taps and screen interactions are captured by a session replay service. Usage data is shared with over a dozen advertising and analytics companies, including networks linked to Facebook and ByteDance, to serve targeted ads and measure how users installed the app.

## Recommendation: Acceptable

**Best For:** Daily language practice with occasional ads
**Avoid If:** Users who prefer not to have sessions recorded

## Key Findings

**Data Security** - 2 findings (1 medium, 1 info)

**Network Security** - 4 findings (2 high, 1 low, 1 info)

**Code Safety** - 0 findings

**Privacy** - 10 findings (5 medium, 5 info)

## Privacy Concerns

### What Data is Collected

- Screen recordings of in-app taps, swipes, and interactions via a session replay service
- App usage patterns, lesson progress, and in-app engagement behavior
- Device identifiers and advertising IDs used for ad targeting and audience profiling
- Install source and referral data showing how users discovered and installed the app

### Third-Party Data Sharing

Data is shared with the following third-party services:

- **FullStory** - Session replay and behavioral analytics
- **Facebook / Meta** - Advertising, audience targeting, and attribution (Core, Login, Share, and AEM integrations)
- **Adjust** - Install attribution and marketing analytics
- **Liftoff (Vungle)** - In-app advertising
- **ByteDance / Pangle** - In-app advertising (two separate integrations: CSJ and PAG)
- **Xiaohongshu (RedNote)** - Social platform integration
- **QQ Music** - Music platform integration
- **AppsFlyer** - Marketing attribution and analytics
- **Google AdMob** - In-app advertising
- **Unity Ads** - In-app advertising
- **Firebase Analytics** - Usage analytics (noted as disabled in this version)
- **Firebase Crashlytics** - Crash reporting
- **Sentry** - Error and performance monitoring
- **Zendesk** - Customer support
- **Ably** - Real-time messaging infrastructure
- **Google Sign-In** - Authentication

## Understanding the Scores

| Category | Score |
|---|---|
| Security | 77/100 |
| Privacy | 78/100 |
| Data Security | 93/100 |
| Network Security | 73/100 |
| Code Safety | 92/100 |
| Data Collection | 82/100 |
| Data Sharing | 84/100 |
| User Control | 84/100 |

## Positive Security Features

- Locally stored data is handled responsibly, reflected in a Data Security score of 93 out of 100.
- Application code follows safe development practices, reflected in a Code Safety score of 92 out of 100.
- Data Collection, Data Sharing, and User Control scores all exceed 80 out of 100, indicating above-average privacy practices compared to the broader app ecosystem.

## Areas for Improvement

- Two network-level issues pose a moderate risk to user data during transmission. While unlikely to affect routine app use, they represent configurations that fall short of current best practices.
- The session replay service records granular details of how users interact with the app, going beyond typical analytics and giving a third party detailed insight into in-app behavior.
- The advertising and tracking footprint is broad. Over a dozen third-party companies receive data about user activity, including advertising networks with ties to Facebook and ByteDance.

---

## About This Analysis

This scorecard is based on automated static analysis of the application package. Scores reflect the security and privacy posture of the app at the time of analysis and may change with future updates.

### App Details

| Field | Value |
|---|---|
| Package | com.duolingo.DuolingoMobile |
| Version | 7.116.0 (Build 7.116.0.9) |
| Platform | Android |
| Scan Date | April 1, 2026 |
| Severity Breakdown | 2 high, 9 medium, 4 low, 10 info |
