Serious Discussion Malwarebytes Amplitude Tracker

A user on Reddit brought this topic


I am not sure if the one who replied is working at MB or not, but the reply does not promote confidence tbh.
I cannot verify the Reddit post or determine whether that respondent works for Malwarebytes from the link alone. A Reddit username, profile description, or claimed affiliation is not reliable proof of employment.

A single informal reply also should not be treated as an official Malwarebytes position. For confidence, rely on:

  • A verified Malwarebytes employee account or staff flair
  • Statements published on Malwarebytes’ official website or support channels
  • Documentation that clearly identifies the policy or technical behavior
  • Confirmation from Malwarebytes support

If the reply concerns a detection, privacy issue, product behavior, or security incident, it is best to compare it with the relevant official documentation and avoid drawing a firm conclusion from that comment alone. If you share the exact text of the reply, its wording can be assessed separately from the person’s claimed identity.
 
I cannot verify the Reddit post or determine whether that respondent works for Malwarebytes from the link alone. A Reddit username, profile description, or claimed affiliation is not reliable proof of employment.

A single informal reply also should not be treated as an official Malwarebytes position. For confidence, rely on:

  • A verified Malwarebytes employee account or staff flair
  • Statements published on Malwarebytes’ official website or support channels
  • Documentation that clearly identifies the policy or technical behavior
  • Confirmation from Malwarebytes support

If the reply concerns a detection, privacy issue, product behavior, or security incident, it is best to compare it with the relevant official documentation and avoid drawing a firm conclusion from that comment alone. If you share the exact text of the reply, its wording can be assessed separately from the person’s claimed identity.
According to Exodus Privacy, MB has 5 trackers and Amplitude is one of them.

It seems the guy who replied to the Reddit post is indeed a employee at MB.

Screenshot_20260813_135319_com_duckduckgo_mobile_android_BrowserActivity.jpg
 
According to Exodus Privacy, MB has 5 trackers and Amplitude is one of them.

It seems the guy who replied to the Reddit post is indeed a employee at MB.

View attachment 299392
If the account is verifiably associated with Malwarebytes, the reply carries more weight than an anonymous Reddit comment. However, it still should not automatically be treated as an official company statement unless it was made through an official channel or clearly presented as such.

Exodus Privacy identifying five trackers, including Amplitude, is also relevant, but the term “tracker” needs context. Exodus generally identifies embedded tracking or analytics components in an Android application; that does not by itself establish malicious behavior, unlawful data collection, or that every tracker is active in every situation. The result can also depend on the specific app version examined.

Amplitude is commonly used for product analytics and telemetry. Its presence may still raise legitimate privacy questions, particularly concerning what events are collected, whether they contain personal or device identifiers, retention, consent, and whether telemetry can be disabled. Those details require confirmation from Malwarebytes’ privacy policy, app permissions, network behavior, or an official response.

The most accurate conclusion is that the Exodus result warrants scrutiny, but it is not by itself evidence that Malwarebytes is unsafe. A verified employee’s explanation may clarify the purpose of the SDK, but independent verification and the current official privacy documentation remain important.