Niantic: Pokémon Go requesting full Google account access on iOS is an error and a client-side fix is coming soon, game only accesses basic Google profile info
Niantic Labs: 'Google will soon reduce Pokémon Go's permission.' — If you spent your weekend wandering around …
Context & Ripple Effects
Pokémon Go's launch-week fire drill hit a privacy snag: iOS players noticed the game was requesting full access to their Google accounts — mail, Drive, everything — not just a basic profile. Niantic, the Google-born skunkworks behind the game per its origin as an overlooked internal project, called the over-broad request an error and promised a client-side fix, with Google committing to reduce the permission server-side.
The stakes were unusually high because the game was signing up users at a pace no app had seen, meaning millions were granting the scope before anyone scrutinized it.
First-order effects
- iOS players authenticating through Google face a stark choice between granting full account access or skipping the game entirely, until Niantic ships the client-side fix and Google trims the requested scope.
- Niantic and Google both absorb immediate reputational damage on privacy at the exact moment the game is at peak visibility.
Second-order effects
- The episode puts Niantic's shipping discipline under a microscope it never escapes: weeks later it removes the glitchy proximity tracker rather than fixing it, angering fans (the tracking removal), before finally rebuilding it as the Pokéstop-based Nearby system (the Nearby overhaul) — and the very next day's iOS update lands the permissions fix alongside crash fixes.
- Competing location-based games now inherit a user base primed to read every permission dialog closely, raising the bar for any rival asking for broad account scopes.
Third-order effects
- If the pattern holds, launch-viral apps get one shot at permission hygiene: over-broad OAuth scope requests become a front-page liability rather than a footnote, pushing developers toward minimal-scope logins and platform-level permission review by default.
- The incident foreshadows the broader dynamic where a game operator's live-service decisions — permissions, features, even pandemic-era travel mechanics like Niantic's later temporary gameplay adjustments — are negotiated publicly with its player base in real time.
The trend: Viral consumer apps are learning that account-permission scope is now a public trust issue, forcing same-week remediation and tighter default scopes across mobile platforms.