HeadlinesBriefing favicon HeadlinesBriefing.com

Native Apps a Privacy Risk, Advocate for Web

Hacker News •
×

Native apps should be avoided due to extensive data collection and permission requests that go beyond website capabilities. These apps often embed third-party software that transmits user data, including location, to third parties before consent is even given. This data is then bought, sold, and aggregated, with documented instances of its use for tracking immigrants and enabling prosecution over reproductive healthcare.

A recent example is the White House app, released on March 27, 2026, which falsely declared zero data collection while embedding analytics frameworks, including one for location tracking. This app exemplifies the native app model's flaws, with its GPS pipeline polling precise coordinates frequently and syncing to commercial servers. Despite a privacy policy updated on January 20, 2025, it omitted details about GPS tracking and background data collection.

The average app is a wrapper for numerous third-party packages, each with its own data collection pipeline. When an app gains location permission, all embedded packages inherit it. A breach of Gravy Analytics in January 2025 leaked 30 million location records from thousands of apps. The FTC subsequently banned Gravy Analytics, but the data was already circulating. In a separate case, Google paid $391.5 million to settle claims for continuing to collect location data even when tracking was disabled.

Governments, military agencies, and law enforcement purchase this data, sidestepping warrant requirements. This commercially available data has been used to track individuals to abortion clinics and could be used to build registries. The article advocates for using websites instead of native apps, as browsers act as security boundaries, while native apps can bypass them, operating without user awareness.