4 ms·
We develop a banking app for families (parents and kids). 2 weeks ago we had to remove the possibility to pick phone contacts to invite other family members bec
by savy91 4y ago
We develop a banking app for families (parents and kids). 2 weeks ago we had to remove the possibility to pick phone contacts to invite other family members because Google claimed we were uploading contacts to our servers (which we did not).
We appealed and it did not work.
We then complied with their request and added to the privacy policy they we have access to the contacts and we might process them, and yet Google still rejected our app.
In the end we just decided to completely remove every code from the app that would allow us to read the contacts on the phone.
This has now made our app UX worse for the 60% of users who used this feature.
Also, mind that we of course offered the option to never grant this permission so nobody was ever forced to give access to their address book.
- davidhyde 4y ago
- veeti 4y agoThe parent comment literally says that their users always had the choice, but don't let me interrupt your knee jerk reaction. > A win win for everyone is if Google allowed the user to turn this feature on manually in settings post app install but they don’t do that. That is exactly how the Android permission model already works. But now Google/Play Store is enforcing additional restrictions on developers that use these permissions.
- davidhyde 4y agoOh, I wasn’t aware of this. Call it an uninformed reaction, oops. Thanks for pointing out my mistake! Maybe this post will be helpful for iPhone users who think that android users have no control until it’s already too late (I thought that, by default, contacts could already be uploaded before permissions could be revoked by the user)
- striking 4y agoUsers can decline the permission. Additionally it sounds like this was an optional part of the flow ("possibility")
- refulgentis 4y agoHow did you send invites?
- savy91 4y agoThis is the flow: - parent creates a child account and has to provide the child phone number - we create a child account and sms via Twilio with a token to the child to complete sign up - the child uses the token (via a deep link) received via sms and claim their account There is no "mass invitation" feature.
- rawling 4y agoDid you ask permission to access all the user's contacts, or open a contact picker to let them pick a single contact?
- lathiat 4y agoThis is a mistake I see on iOS a lot. You can use a 'system picker' for some things without a permission - photos is the most common one - many apps request full photo library access which I never want to grant when they could just use the system photo picker instead. In a similar way you could (in iOS) for this same feature just popup the share sheet to send a message. Though I am not familiar with the Android analog.
- williamscales 4y agoYou could definitely use the share modal on Android. Clicking to invite would pop it up, let you choose which app to use, and then which contact.
- fomine3 4y agoBut it's not good UI for sharing app. It should have Contact Picker API like photo.
- franga2000 4y agoTrue, but the share modal is terribly broken. It changes every version, the order of icons is different every time you open it, sometimes icons and app names are mixed up...
- mynameisvlad 4y agoI believe in recent OS versions, whenever an app requests full library access, the OS asks you if you want to grant it, deny it, or grant a subset of photos which it fakes as the "full library" to the app.
- woojoo666 4y ago
- p1necone 4y agoI don't think google did anything wrong here (at least in the first half), afaik android app privacy permissions don't differentiate between "app has access to contacts locally" and "app has access to contacts remotely". Probably because this would require thorough code review every time you shipped an update to ascertain as opposed to just identifying whether you accessed a specific API or not.
- CountHackulus 4y agoOf course that would be impossible to differentiate, but adding it to the privacy policy is what Google requests. Adding it and still having it refused can absolutely be blamed on Google.
- franga2000 4y agoWhat I don't get is why does sending contacts need to be added to the privacy policy? The point of the policy is to state what you will and won't do in a legally binding way. If my privacy policy says "the app may access contacts locally, but that information never leaves the device", that means users can sue me if I break that promise and I could even be criminally prosecuted. What more assurance does Google need?
- savy91 4y agoI do not agree. We were explicitly asking for permission to access the contact list, the user was granting it and the user also had the option not to grant it and still use the app by manually entering the phone number. What happened is that Google blocked our updates claiming we were doing something we were not doing, and even if we did access the entire phone book, the users agreed to it explicitly. Another issue is that we would have been fine sharing a single contact with the PICK_CONTACT intent, however there's a bug open in Android since 2018 that causes developers to have to ask for the full READ_CONTACTS permission even just to pick a single contact[1]. So in our case Google did not respect the user choice, claimed we were using user data in a way we were not (without any proof whatsoever), still rejected the update even when we added what they asked us to add to our Privacy Policy and in the end they also don't even fix bugs in the Android codebase to allow developers to use more privacy-friendly APIs in their OS. [1] https://issuetracker.google.com/issues/118400813?pli=1 https://issuetracker.google.com/issues/118400813?pli=1
- deleted 4y ago[deleted]