Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Any app that you log into "links" anything in your profile to your phone, so of course it links this information.

I'm all for calling out bad privacy practice, like when a Weather app says it links your contact info. But an airline app inherently does this.

Did you know that Ryanair knows your name when you fly! They even know what city you're flying from.



They didn't necessarily have to know my main email address though! Or a list of the installed apps.


Installing as an app doesn’t share your main email address and they can only identify apps from a fixed list, so it’s not really useful to do that.


Oh sorry, missed that one.

> your main email address

Right, it doesn't get my main email at the moment, true, turns out an app needs `android.permission.GET_ACCOUNTS` to do that. I do, however, expect them to do that later -- looking at their declared permissions, it's hard to assume a good will:

- `BLUETOOTH_SCAN`, `ACCESS_FINE_LOCATION`, `ACCESS_ADSERVICES_AD_ID` -- all together. Yes, I see they use `android.ext.adservices`

`READ_EXTERNAL_STORAGE`? `WRITE_EXTERNAL_STORAGE`? What for? Do they even offer saving a PDF into a Downloads folder? I think they can do it without asking for the separate permission.

> and they can only identify apps from a fixed list

While it's true they would require `QUERY_ALL_PACKAGES` to openly get a _complete_ list, see this: https://www.medianama.com/2025/04/223-android-apps-data-brea...

And then check their admitted privacy practices/policy from their Google Play listing (com.ryanair.cheapflights)

Notice, the first section is `DATA SHARED`, not just collected. It's shared with the undisclosed third parties (we know from the privacy policy[1], though, that at the very least it includes all the social networks

>> App Activity: installed apps >> Purposes: Analytics, Personalisation

>> Also: Email address, financial information, physical address, user payment info, phone info.

`DATA COLLECTED`:

>> Photos, User ids (plural, it's not just email used to login), Installed apps once again, Files and docs (?!)

Generally;

I have a very little trust for a vendor that is known for the deceptive practices and which lies from the outset about the reasons to force all passengers into using their app.

If they lie in such a fundamental question, it should be assumed they're using deceptions and trickery.

Like with disgraced Meta caught red-handed on deception and trickery: https://arstechnica.com/security/2025/06/meta-and-yandex-are...

[1] https://www.ryanair.com/ie/en/lp/privacy-policy


I suppose if you’re on android the protections are a lot lower… At least based on your description


I agree. The fact AOSP doesn't offer blocking network by default is ridiculous.

Of course, Google is the ad company, this is the reason.

Thankfully I could contain and strangle it in its dedicated profile with the better AOSP variant. Works for the time being.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: