The Global Phonebook
A global phonebook can be created without asking everyone to join. People already keep small directories of one another on their phone’s saved contacts. One can collect enough of these relationships and make the resulting information searchable, and participation takes on a different meaning. A person can avoid installing the app, decline to share their contacts, and still become someone that the app identifies. This is the main privacy problem with a phonebook built through other people’s contributions: my decisions can protect the information I’m holding, but cannot protect the information others are holding about me.
Ever since I got a new eSIM number, unknown callers have been trying to reach me. I’ve always declined the calls and blocked them, but eventually I answered one. The caller said they were from Lazada and asked whether I was Bu Siti. I explained that I was not her and had acquired the new number a few months earlier. The calls stopped finally. Then I tried installing the Truecaller app, and the Getcontact app, in my Xiaomi phone’s Second Space, intending to keep these apps away from my main saved contacts. When I looked up my number, I found many variations of Bu Siti’s label. The number already came with contributions from other people.
The reason people want these types of apps is simple: an unfamiliar number calls, and a name or a spam warning helps them decide whether to answer. Each additional useful identification makes the apps more valuable. From their perspective, a more complete directory seems like an obvious improvement, but completeness also means identifying more people, including people who never have decided to participate. The same expansion that improves the product can reduce the ability to stay outside it, so we need to evaluate both consequences.
The two apps differ in how they obtain their information. Getcontact’s privacy policy says it may collect names and numbers from contacts and periodically synchronize that sharing, though it also says users providing another person’s information must have obtained that person’s consent. Truecaller’s app store listing states that it does not upload phonebooks to make them public or searchable. Its privacy policy nevertheless acknowledges receiving and processing information about non-users from its users. A criticism of these apps should preserve those distinctions. The broader issue applies wherever an app uses one person’s contribution to identify another. What choice did the person being identified have?
We often treat a permission request as the place where that choice is made: the app asks to read contacts, and the user accepts. The device owner has authorized access to data on the device. Yet an address book describes many people, and their agreement cannot be inferred from the owner’s decision. A policy requiring the contributor to obtain everyone’s consent recognizes this difficulty. It does not, by itself, show that anyone else was asked. A system that depends on that consent needs a credible way to establish it.
The mistake is easy to make because saving a contact is so ordinary. Someone gives me a number, and I attach a name so I can recognize it later, and I might add a workplace, a profession, or a reminder of where we met. Those details make sense within my relationship with that person. Making them available through a directory changes their audience and purpose. Information given to help two people communicate becomes information that helps others identify one of them. Even if the app discarded who supplied the entry, the association between the number and its subject would remain.
My experience with Bu Siti also showed how a directory can accumulate agreement without accumulating updated knowledge. People might have saved her number correctly, but when that number became mine, their entries all became misleading. A name that’s remembered by people is still a claim that needs context, including when it was true. The appearance of consensus can conceal that missing context.
Deliberate false contributions introduce a further problem. A group could attempt to attach a misleading name or spam label to a number, or one person could attempt the same through multiple accounts. Whether this succeeds depends on the app’s safeguards. The existence of contributions alone does not establish an easy exploit, but requiring several reports is insufficient if those reports can come from the same source in disguise. An app that gives collective judgments influence over a person’s identity or reputation takes on the responsibility of handling coordinated abuse, disagreement, and correction.
Accuracy, however, would not settle my objection. I may want a seller to reach me without wanting everyone who obtains my number to discover my name. I may share different details in different relationships. That is an ordinary way to manage privacy, and a directory that combines those details changes the conditions under which they were shared. An accurate identification can still disclose more than its subject intended. Better matching cannot decide whether that disclosure should happen.
The usual response is to offer control after inclusion. For example, Truecaller’s unlisting page describes removing a number from searches, but the opt-out requires the person to basically discover the app, understand what it holds, and take action. People who never installed the app have no reason to look. Exclusion also needs to persist when new contributions arrive. Otherwise, the work of maintaining privacy falls indefinitely on the person who tried to leave, while others can continue contributing information about them.
These problems are connected by a simple imbalance. The person contributing information can receive benefit. The person described by it can bear a cost without seeing the transaction. That’s why it’s not enough to measure a directory’s success only by how many callers it identifies or how convenient it is for its users. The people being identified belong in that measurement. A design that treats them as participants would give them meaningful control over inclusion, effective correction, and durable exclusion. It would also distinguish evidence of unwanted calling behavior from permission to publish a personal identity.
I do not have to solve every problem in caller identification before objecting to this arrangement. The usefulness of a global phonebook creates a reason to build it carefully, with limits on what one person can disclose about another. Those limits may reduce its coverage, and accepting that constraint would mean recognizing that people have interests beyond being accurately catalogued. Knowing someone’s number gives us a way to contact them. Making them identifiable to a much wider audience requires a further decision, and they should have a say in it.