Popular Robocall Blocking Apps Caught Sharing User Data Without Consent
Security researchers discover that several top robocall-blocking applications secretly transmit personal and device data to third-party analytics firms before users even accept the privacy policies.
Robocall-blocking apps promise to eliminate annoying spam phone calls, but a security researcher finds that many of these applications secretly violate user privacy. Dan Hastings from NCC Group analyzes popular apps like TrapCall, Truecaller, and Hiya, discovering that they send sensitive user and device data to third-party analytics companies without obtaining explicit consent from the user.
These privacy violations occur immediately after the apps are opened, often before a user even has the chance to read or accept the terms of service. For example, TrapCall transmits user phone numbers to an analytics firm without any disclosure, while Truecaller and Hiya upload device details prior to user consent. These practices directly contradict Apple's strict app guidelines, which mandate that developers must obtain permission before sharing any data with outside parties.
Hastings notes that the app makers largely ignore his initial warnings about these privacy breaches, and he also criticizes Apple for failing to actively monitor the accuracy of the privacy policies submitted by developers. Because most consumers lack the technical skills to audit network traffic themselves, they rely entirely on these policies to understand how their information is handled, making these hidden data-sharing practices especially deceptive.