The Vatican's official prayer app quietly exposed the personal data of more than 700,000 users for months, and it took the Catholic Church roughly six months to even acknowledge the problem.
The app in question is Click to Pray, the Pope's officially endorsed mobile prayer platform. It leaked user names and email addresses on a scale that would make most app developers break into a cold sweat, and it did so silently, without any immediate public disclosure to the people affected.

Get 1-month GTA+ subscription with pre-order.
Pre-Order GTA 6 Now
What actually got exposed
The leaked data includes names and email addresses belonging to over 700,000 registered users spread across the globe. That might sound like a relatively modest breach compared to the nine-figure leaks that hit major gaming platforms or social networks, but here's the thing: the people who downloaded a prayer app to connect with their faith almost certainly weren't expecting their personal information to be sitting in an exposed state for months on end.
The nature of the exposure means affected users could face phishing attempts, spam campaigns, or targeted social engineering attacks. An email address tied to a known religious app tells bad actors something specific about the person behind it, which makes the data more actionable than a generic credential dump.
Six months of silence from the Vatican
The response timeline is what makes this story genuinely alarming. A six-month gap between a data exposure being identified and the Vatican formally addressing it is a long time in the world of data security. Most jurisdictions with serious data protection laws, including the EU's GDPR framework, require breach notifications within 72 hours of discovery. Six months is not 72 hours.
The delay raises real questions about the Vatican's internal security infrastructure and incident response processes. Large organizations with dedicated security teams can still fumble breach disclosures, but a six-month lag suggests either a very late discovery, a very slow internal process, or both.
Why this matters beyond the headlines
Data breaches hitting religious, health, or mental wellness apps carry a different weight than a gaming account getting compromised. The key here is context. When someone signs up for Click to Pray, they're sharing personal information in a setting they associate with trust and spirituality, not a competitive online platform where data risks feel more expected.
For gamers and tech-adjacent readers, the broader lesson is familiar: no app category is inherently safe. Whether you're logging into a mobile RPG, tracking workouts, or using a prayer platform, the underlying data security practices of the developer determine your actual risk. App store badges and institutional endorsements don't guarantee anything about backend security.
You'll want to apply the same hygiene here that you would after any breach notification: check whether your email appears in known breach databases, watch for unusual login attempts on linked accounts, and be skeptical of any unsolicited emails referencing your Click to Pray account.
For more tips on navigating the gaming and tech world safely, the gaming guides section covers everything from account security basics to platform-specific strategies. And if you're looking for something more lighthearted after a heavy news cycle, the YAPYAP spell casting guide and the OPUS: Prism Peak achievement guide are worth a look.
The Vatican has not publicly confirmed what steps are being taken to prevent a repeat incident, so this story likely has more chapters ahead.








