Researcher: robocall-blocking apps like Truecaller and Hiya send user or device data to third-party data analytics companies without users' explicit permission
Robocall-blocking apps promise to rid your life of spoofed and spam phone calls. But are they as trustworthy as they claim to be?
Context & Ripple Effects
This finding lands on an app category whose entire value proposition is trust: users install Truecaller and Hiya to stop unwanted calls, and the researcher's claim that they transmit user and device data to third-party analytics firms without explicit permission cuts against that promise. It is not the first privacy strike against Truecaller — earlier reporting showed its database can expose journalists' phone numbers even if they never use the app.
The consent gap also fits a documented pattern: a later investigation found Truecaller exploits India's weak data privacy laws to build its user information database across 205M+ monthly active users there. With spam volumes climbing — Truecaller itself counted 31.3B spam calls globally in ten months of 2020 — demand for blocking is real, which makes how these apps monetize that demand the open question.
First-order effects
- Truecaller and Hiya face immediate credibility damage with the exact users they court — people seeking protection from spam — since the tools marketed as privacy shields are alleged to leak user and device data to analytics firms.
- App-store gatekeepers that enabled this category, notably Apple when it opened the CallKit Extension to third-party developers in iOS 10, come under pressure to scrutinize what those extensions transmit.
Second-order effects
- Native alternatives gain a trust argument: as telcos, Apple, and Google roll out their own caller ID and spam blocking — the same shift coinciding with Truecaller's slowing growth in India — a consent scandal hands those incumbents a differentiator no feature list can match.
- Advertisers and analytics partners attached to these apps face reputational contagion, since receiving user data without explicit consent implicates buyers, not just senders.
Third-order effects
- If the pattern holds, third-party utility apps built on harvesting behavioral data will be structurally squeezed between stricter consent enforcement and OS-native substitutes, pushing the category toward paid-subscription models like Truecaller's premium tier rather than data-funded free service.
- Jurisdictional arbitrage — building databases under the weakest privacy regimes, as reported in India — becomes untenable as researchers and press make cross-border data flows visible, inviting regulation that treats contact-book and device telemetry as consent-gated by default.
The trend: Call blocking is migrating from third-party apps that monetize user data toward carrier- and OS-native features, with consent scandals accelerating the handoff.