All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
The Vatican's official prayer app, Click to Pray, exposed the personal information of more than 700,000 users through a flaw that let anyone with a web browser retrieve account data without logging in.[1] The exposed information included users' first and last names, email addresses, and country.
Click to Pray is available on iOS, Android, and the web, and according to its operator is used in nearly every country. Security researchers who examined the flaw said the exposed data could be used for targeted phishing and impersonation.
For the many people who use faith, wellness, and other lifestyle apps that collect similar personal details, the incident is a useful reference point for how to protect yourself after a data breach.
Why apps that collect your name and email pose a privacy risk
How to protect yourself after a data breach like this one
Bottom line
How a coding flaw exposed 700,000 Click to Pray users
To create a Click to Pray account, users provide a first and last name, an email address, and optionally their country. The app then assigns each account a sequential user ID.
According to Dark Reading, the app exposed an API endpoint that returned a user's account information to anyone who supplied a valid user ID, with no authorization required. Because the IDs were sequential, a visitor could cycle through them and retrieve records in bulk. The exposed records included first and last names, email addresses in plain text, country, and role flags identifying staff accounts. No passwords or financial data were exposed.
The flaw was discovered in January by a white-hat researcher who goes by BobDaHacker. It is an insecure direct object reference (IDOR), a type of broken access control in which an application returns a record without confirming the requester is allowed to see it. Broken access control has ranked as the top category in the OWASP Top 10 web application risks since 2021. Dark Reading independently tested the flaw and reported it was still live at the time of publication, and that exploiting it required no technical skill, only a web address entered into a browser.
Why apps that collect your name and email pose a privacy risk
The exposed data did not include passwords or financial details. The risk security researchers identified is targeted phishing: with a name, an email address, and knowledge that a person uses a specific app, an attacker can send messages posing as that organization, in this case the Vatican, Click to Pray, or the Pope's Worldwide Prayer Network.
Messages that reference real account details are more likely to succeed than generic spam.
According to an All About Cookies survey of 1,000 U.S. adults, a data breach was the single most common way identity theft victims had their information stolen, ahead of stolen cards or documents.
How to protect yourself after a data breach like this one
If you use Click to Pray, be cautious of unexpected emails that claim to come from the Vatican, Click to Pray, or the Pope's Worldwide Prayer Network. Do not click links or share a password based on an email alone, and verify any message through an official channel before acting. Learning to spot a phishing attempt is the most direct defense, because exposed email addresses are typically used for phishing first.
To limit exposure in future breaches, share less at sign-up. Users often do not need to provide a real full name, and tools such as Apple's Hide My Email supply a relay address that forwards to a real inbox. Dark Reading reported that Click to Pray users who used such measures were not exposed by the flaw.
Before downloading an app, it is worth knowing how to tell if an app is safe, and if you suspect your information has already been misused, All About Cookies outlines how to tell if someone has stolen your identity.
Identity theft protection and monitoring services can alert you when your details appear somewhere new; in the same All About Cookies survey as above, monitoring was how most victims first learned their identity had been stolen.
Bottom line
The Click to Pray flaw exposed the names and emails of more than 700,000 users and, as of July 24, 2026, remained live. Affected users should watch for phishing messages that reference the Vatican or the app, and verify before clicking.
The broader takeaway applies to any app that collects your name and email: it is holding personal data that can be exposed. A practical next step for anyone is to check whether your email has appeared in a known breach and to limit what you share the next time an app asks.