A prayer app tied to the Vatican left the personal data of more than 700,000 users around the world open to anyone who cared to look, according to Tom's Hardware.
The outlet reports that the "Click to Pray" app was found to have zero authentication and no meaningful security on its backend. In plain terms, there was no digital lock on the door: anyone could reach the system that stores user information and siphon it off.
The exposed data included users' names, email addresses, and birthdates, per Tom's Hardware. That combination is exactly the kind of information that can be used for targeted phishing, identity fraud, or building profiles of individuals.
What makes the situation worse is how long it lasted. Tom's Hardware says the flaw had been leaking data for over six months. The report notes the issue was described as resolved, while its own headline states the app "still does" leak data, underscoring lingering questions about whether the fix fully closed the hole.
The app's link to the Vatican gives the story added weight. Faith-based apps often draw users who may not think of a prayer tool as a place where sensitive personal details could be at risk, and the audience here spans the globe.
Why it matters: it's a reminder that any app collecting personal data—even a spiritual one from a trusted institution—can expose hundreds of thousands of people if basic security is missing.