---
title: "FaceApp: What our security report shows"
description: Pictures are the only sensitive data processed by FaceApp. Indeed, the app sends selected pics towards its servers, but the app doesn’t leak the gallery.
image: https://blog.pradeo.com/hubfs/faceapp_security_report.png
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Mobile Application Security](https://blog.pradeo.com/topic/mobile-application-security) [Expertise](https://blog.pradeo.com/topic/expertise)

# FaceApp: What our security report shows

![Picture of The Pradeo Lab](https://blog.pradeo.com/hubfs/Pradeo%20Logo%20D%C3%A9grad%C3%A9%20seul.png)

 By [The Pradeo Lab](https://blog.pradeo.com/author/the-pradeo-lab) on July, 25 2019

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![faceapp\_security\_report](https://blog.pradeo.com/hubfs/faceapp_security_report.png)

**FaceApp** is currently highly questioned in the press. A lot of articles and some American politicians relate that the Russian mobile application collects and exfiltrates its users’ personal data, without specifying which. Real threat or fake news? The FaceApp security analysis performed by the [Pradeo Security engine](https://www.pradeo.com/en-US/pradeo-security) clarifies things. Here is a part of it.

---

## App ID

**Name**: FaceApp

**Package**: io.faceapp

**Version**: 3.4.9.1

## Personal data processed by FaceApp

**Pictures taken via the camera in the app** -\> Sent to FaceApp servers

**Pictures selected in the gallery** -\> Sent to FaceApp servers

**Gallery** -\> Used locally, not sent to the network

 

## Device data processed by FaceApp

**Device identifier** -\> Sent to Google-owned analytics servers

**OS Version** -\> Sent to Google-owned analytics servers

**Device manufacturer** -\> Sent to Google-owned analytics servers

**Device name and model** -\> Sent to Google-owned analytics servers

 

## Vulnerabilities

The application doesn’t embed any code vulnerability.

To conclude, pictures are the only sensitive data processed by FaceApp. Indeed, the application sends selected pics towards its servers, but unlike some claims posted on social media, the app **doesn’t leak the gallery**, and therefore, doesn’t exceed its permissions.

When it comes to unraveling the real threats from false alerts, accuracy is key. Pradeo provides companies with solutions to access applications’ security report, and clearly see in a few seconds whether they represent a real threat, or not.

To learn more about Pradeo Security global application database and mobile application testing solution, [contact us](https://www.pradeo.com/en-US/contact-us).

 

**Discover Pradeo Security solution suite:**

- **[App Self-Protection](https://www.pradeo.com/en-US/in-app-protection) **
- **[App Security Testing](https://www.pradeo.com/en-US/application-security-testing)**<https://www.pradeo.com/en-US/mobile-threat-protection>
- **[Mobile Threat Protection](https://www.pradeo.com/en-US/mobile-threat-protection)**

 

###### About The Author

[More from this author](https://blog.pradeo.com/author/the-pradeo-lab)

![](https://blog.pradeo.com/hs-fs/hubfs/Pradeo%20Logo%20D%C3%A9grad%C3%A9%20seul.png?height=100&name=Pradeo%20Logo%20D%C3%A9grad%C3%A9%20seul.png)

###### The Pradeo Lab

#### Recommended articles

[![Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/hubfs/Template%20article%20(32)-1.png)](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

###### [Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- June 18, 2026

[![Cyber Resilience Act: The first obligations take effect in September 2026](https://blog.pradeo.com/hubfs/Template%20article%20(26)-1.png)](https://blog.pradeo.com/cyber-resilience-act-the-first-obligations-take-effect-in-september-2026)

###### [Cyber Resilience Act: The first obligations take effect in September 2026](https://blog.pradeo.com/cyber-resilience-act-the-first-obligations-take-effect-in-september-2026)

 \- May 7, 2026

[![What is Application Shielding?](https://blog.pradeo.com/hubfs/Template%20article%20(6)-1.png)](https://blog.pradeo.com/what-is-application-shielding)

###### [What is Application Shielding?](https://blog.pradeo.com/what-is-application-shielding)

 \- March 5, 2026

#### Recommended articles

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 25 July, 2019

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 25 July, 2019

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 25 July, 2019

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 25 July, 2019

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 25 July, 2019

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The Pradeo Lab"
  },
  "dateModified" : "January 27, 2021, 1:54:01 PM",
  "datePublished" : "2019-07-25 07:00:43",
  "description" : "Pictures are the only sensitive data processed by FaceApp. Indeed, the app sends selected pics towards its servers, but the app doesn’t leak the gallery.",
  "headline" : "FaceApp: What our security report shows",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://cdn2.hubspot.net/hubfs/2378615/faceapp_security_report.png"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```