Messenger
Messenger is a feature-rich communication app from Meta with end-to-end encryption for 1-on-1 chats, but it collects extensive metadata, location data, and contact information across 9 verified trackers. Meta's history of privacy incidents and aggressive data monetization, combined with mandatory contact/location permissions and biometric access, places this app in the MEDIUM risk category - acceptable for casual messaging but with significant privacy trade-offs.
Data Breach: Facebook
Over 500 million Facebook user records scraped and leaked, exposing names, phone numbers, and personal details of 20% of all subscribers.
Data Breach: Facebook Marketplace
200k Facebook Marketplace records obtained from a Meta contractor posted to a hacking forum.
Regulatory & Legal
FTC $5B settlement (2019) for Cambridge Analytica and systemic privacy violations. GDPR fines totaling €422M+ (2021–2022). Ongoing EU investigations into data processing practices.
How we got to 51.
Google Analytics, AdMob, Facebook SDK, Meta SDK, Mapbox - heavy ad-tech and attribution stack
Messenger data feeds Meta's advertising graph. No opt-out for data collection.
Group chats, call metadata, contacts, and location collected unencrypted on Meta servers
READ_CONTACTS and ACCESS_FINE_LOCATION used for friend suggestions and ad targeting
Cambridge Analytica (2018), FTC $5B settlement (2019), GDPR violations (€405M+)
Schrems II ruling challenges Meta's data transfers to US servers
Optional E2E encryption reduces interception risk for direct messages
Regular security patches reduce vulnerability risk
Hidden inside the code.
What it asks for.
Precise GPS location - not needed for messaging, used for ad targeting
Reads device identifiers and call state for behavioral profiling
Bulk contact harvesting for friend suggestions and social graph mapping
Can initiate calls without per-call user confirmation
Core to voice calls, but combined with location tracking enables surveillance
Keep reading.
What is a tracker in an app, and why should you care
Trackers are code libraries hidden inside apps that collect your data for third parties. Here is how they work, what the...
What trackers are actually hiding in your apps
We scanned 32 of the most-installed Android apps and counted every embedded tracker SDK. The average app hides 5 tracker...
Similar risk profiles.
Scan Messenger yourself.
Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.