# Security & Privacy Scorecard

## VLC for Android

### App Details

- Package: org.videolan.vlc
- Developer: Videolabs
- Platform: android
- Scan date: 2026-09-10T04:39:54.990371Z

## What This App Collects

The code sends credentials to OpenSubtitles; authentication tokens to OpenSubtitles; media files to OpenSubtitles; and network identifiers to libVLC MediaBrowser (VideoLAN, in-process native). Another 1 data point is sent out to other third parties.

Other findings record data the code reads on the device and data arriving from a server.

## Can This Be Trusted

The code sends data out of the device to third-party recipients. Some of those flows are recorded on paths that lack a consent step.

Four high severity findings related to Code Security, Data Security and Privacy are worth reading before this build handles anything a user would want kept to themselves.

## What Needs Attention

Four findings need attention. Three are about how data is stored on the device, one about how the app connects to servers. The detailed report states each of these in full.

## Scores

- Overall: 75/100
- Security: 68/100. Held down by how data is stored on the device and by how the app is put together.
- Privacy: 91/100. Held down by the amount collected and by how little of it is recorded as consented to.
- Data Security: 76/100
- Network Security: 82/100
- Code Safety: 78/100
- Data Collection: 92/100
- Data Sharing: 97/100
- User Control: 91/100
- Permission Usage: 96/100

## What the Score Set Aside

Of the 339 findings that describe something this build contains, 43 describe code inside bundled libraries that the call graph shows this build leaves unused. They keep their recorded severity and are named in full in the detailed report; the score was computed over the other 296.

The largest group is bouncycastle (43).

Set aside by library:

- bouncycastle (43)

## How This Was Checked

Of 186 planned analysis tasks, 1 was asked for and did not come back. This page covers the rest.

CITT examined 761 files, traced 106 data flows and recorded 373 findings.

On whether the user was asked first, across the 106 flows recorded, not only the outbound ones: 68 have an unsettled consent state either way; 31 run on paths recorded without a consent step; 7 run after a recorded consent grant.

## Method and Limitations

Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

## About This Analysis

This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.
