[Android/iOS] Potential privacy bug?

Issue: I have a lot of random people in my phone contacts who I don’t really know, and I just have saved as something like “Dave the plumber” or “kitchen quote guy” etc.

I’ve just noticed that if they have a Monzo account, I can tap on them in the Payments section, and see their full name. This feels like a big privacy breach to me.

Details to reproduce: Tap any contact in Payments, see their full name.
OS: iOS 12.4.1
Device: iPhone X
App Version: TF 2.62 b555

It is mentioned when you enable payments with friends/contacts. It could be made more obvious I guess. Same thing happens with WhatsApp etc.

1 Like

Where is that screen? It’s not in the flow when you turn on contacts on iOS

Settings > Payments with friends > Top right question mark

1 Like

Wow, that’s buried real good. I’d personally want to see this front-and-centre when you’re enabling contact access.

Don’t forget that it works the other way, too. Some random person you had a phone conversation with 10 years ago could have your full name if they have a Monzo account and have saved your details.

1 Like

Very true! I’d love to be able to have contacts disabled, and for that giant box begging for contact access to go away. Why so thirsty, Monzo?

2 Likes

We should be able to select which contacts we want to add. Full stop.

2 Likes

I’m surprised as to why selecting which contacts wasn’t just built in from the start.

2 Likes

Just add my own experience to this.

My friend changed their number a few years ago. I still have their old and current phone number saved under their contact.

In Monzo, under phone contacts on Monzo, it showed my friends name, that old mobile number, but the picture was of someone else.

So I tapped on it, the name changed from my friends name, to some other person’s name (we’ll call them Alan Doe). This also moved them from the phone contacts on Monzo section to all contacts, I don’t seem to be able to remove this newfound association with a stranger.

But this seems like a pretty flaw in this feature. Presumably and hopefully this Monzo user can’t see me?

1 Like

Your new Monzo friend shouldn’t be able to see you as they do not have your number in their phone

1 Like

Just to double check, if I disable phone number in my profile privacy, will I no longer show up in other’s Monzo apps as a phone contact?

Or does that just stop Monzo reading my contacts?

The answer to this question, which I’m having a hard time finding definitively will be the difference between my Monzo account staying open and me clicking the close my account button.

The privacy (and potentially significant security oversight) problem this creates is a step too far beyond my comfort levels. If I can’t have myself completely opted out, I can’t have a Monzo account.

Just to add to this - there doesn’t appear to be a help article on “Profile privacy” or on “Monzo contacts”. There really should be.

2 Likes