The Pope's Official Prayer App Has Been Leaking the Private Data of 700,000 Users for Months

A flaw in the Vatican's Click to Pray app exposed more than 700,000 users' names and emails. Here's what was exposed and how to protect yourself after a data breach.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

The Vatican's official prayer app, Click to Pray, exposed the personal information of more than 700,000 users through a flaw that let anyone with a web browser retrieve account data without logging in.[1] The exposed information included users' first and last names, email addresses, and country.

Click to Pray is available on iOS, Android, and the web, and according to its operator is used in nearly every country. Security researchers who examined the flaw said the exposed data could be used for targeted phishing and impersonation. 

For the many people who use faith, wellness, and other lifestyle apps that collect similar personal details, the incident is a useful reference point for how to protect yourself after a data breach.

In this article
How a coding flaw exposed 700,000 Click to Pray users
Why apps that collect your name and email pose a privacy risk
How to protect yourself after a data breach like this one
Bottom line

How a coding flaw exposed 700,000 Click to Pray users

To create a Click to Pray account, users provide a first and last name, an email address, and optionally their country. The app then assigns each account a sequential user ID.

According to Dark Reading, the app exposed an API endpoint that returned a user's account information to anyone who supplied a valid user ID, with no authorization required. Because the IDs were sequential, a visitor could cycle through them and retrieve records in bulk.  The exposed records included first and last names, email addresses in plain text, country, and role flags identifying staff accounts. No passwords or financial data were exposed. 

The flaw was discovered in January by a white-hat researcher who goes by BobDaHacker. It is an insecure direct object reference (IDOR), a type of broken access control in which an application returns a record without confirming the requester is allowed to see it. Broken access control has ranked as the top category in the OWASP Top 10 web application risks since 2021. Dark Reading independently tested the flaw and reported it was still live at the time of publication, and that exploiting it required no technical skill, only a web address entered into a browser.

Why apps that collect your name and email pose a privacy risk

The exposed data did not include passwords or financial details. The risk security researchers identified is targeted phishing: with a name, an email address, and knowledge that a person uses a specific app, an attacker can send messages posing as that organization, in this case the Vatican, Click to Pray, or the Pope's Worldwide Prayer Network.

Messages that reference real account details are more likely to succeed than generic spam.

According to an All About Cookies survey of 1,000 U.S. adults, a data breach was the single most common way identity theft victims had their information stolen, ahead of stolen cards or documents. 

How to protect yourself after a data breach like this one

If you use Click to Pray, be cautious of unexpected emails that claim to come from the Vatican, Click to Pray, or the Pope's Worldwide Prayer Network. Do not click links or share a password based on an email alone, and verify any message through an official channel before acting. Learning to spot a phishing attempt is the most direct defense, because exposed email addresses are typically used for phishing first.

To limit exposure in future breaches, share less at sign-up. Users often do not need to provide a real full name, and tools such as Apple's Hide My Email supply a relay address that forwards to a real inbox. Dark Reading reported that Click to Pray users who used such measures were not exposed by the flaw.

Before downloading an app, it is worth knowing how to tell if an app is safe, and if you suspect your information has already been misused, All About Cookies outlines how to tell if someone has stolen your identity.

Identity theft protection and monitoring services can alert you when your details appear somewhere new; in the same All About Cookies survey as above, monitoring was how most victims first learned their identity had been stolen.

Bottom line

The Click to Pray flaw exposed the names and emails of more than 700,000 users and, as of July 24, 2026, remained live. Affected users should watch for phishing messages that reference the Vatican or the app, and verify before clicking.

The broader takeaway applies to any app that collects your name and email: it is holding personal data that can be exposed. A practical next step for anyone is to check whether your email has appeared in a known breach and to limit what you share the next time an app asks.

4.8
Editorial Rating
Get Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

Author Details
Kate Quinlan is a Senior Editor at All About Cookies, where she has tested dozens of digital security tools and contributed to more than 370 articles spanning web hosting, VPNs, ad blockers, parental controls, and data security. Before joining AAC, she managed a team of more than 150 writers at SuperSummary, where she developed editorial standards at scale. She holds a B.A. in Professional Writing from Kutztown University.

Citations

[1] Vatican's Official Prayer App Leaks 700K+ Global Users' PII