Paris 2024 Olympic apps ask for dangerous permissions

Posted on Monday, August 12, 2024 by AUSTIN HARRIS, Global Sales

As Paris city attracted a large number of sports tourists, the apps for the Olympic Games 2024 are tracking them, extracting private data, and peddling it to advertisers and big tech.

According to a report from the Cybernews research team, which selected 12 Android apps relevant to the Olympic Games attendees in Paris and tested their permissions, the apps designed to help users during the Olympics are underreporting their data collection scope on Google Play Store, require excessive dangerous permissions, and share sensitive user data with advertisers.

Paris 2024 Olympic apps ask for dangerous permissions: There is no privacy during the Olympics

Bonjour RATP app, a travel app for navigating Paris, buying transportation tickets, and finding routes, is the most data-hungry app in the selection. The Data Safety section reveals that it collects 18 data points from 38 possible and shares most of them with third parties.

Not only does Bonjour RATP collect precise location data for its functionality, but it also shares the user’s location for the declared purposes of advertising, fraud prevention, security, and compliance. The app has more than 10 million downloads on Android.

TheFork app, Europe’s leading restaurant booking platform, collects 15 data points and zaps almost all of them to third parties. Even email addresses and phone numbers are shared for advertising or marketing purposes, the app developer declares.

Citymapper app, another city transport app with more than 10 million downloads, collects 14 data points, but advertising is not mentioned among the declared purposes for sharing.

The Paris 2024 Olympics and The Paris 2024 Public Transport apps require 9-11 data points each.

The Paris 2024 Olympics app, already downloaded more than 10 million times, collects user data, such as web browsing history, email addresses, devices, and other IDs, and beams it to advertisers. It also asks for multiple dangerous permissions that allow it to tap into the deepest secrets you may hide on your Android phone.

The International Olympic Committee (IOC) openly admits that it collects personal data, builds user profiles, and shares data with advertisers, including Facebook, Google, Apple, or X.

“When required, prompts are presented to users to allow them to consent to specific features to enhance their app experience. When first interacting with the app, users may agree to or reject cookies. At any time, users have control over the permission they granted via the device and app settings,” IOC said to Cybernews.

The Paris 2024 Public Transport app, made by a government agency, will share names, emails, and app activity. Security and compliance, fraud prevention, functionality, advertising, and analytics are all among the declared purposes.

Stakeholder Experience & Access Tool (S.E.A.T.) and PinQuest require some of the most dangerous permissions.

S.E.A.T. is designed to support specific accredited stakeholders at the Games. Although it says it collects no data, it asks users for dangerous permissions to read and write to external storage, read and write contacts, check and update calendars, and access media files on the device.

Even PinQuest, a fun game to discover and test Olympic knowledge, will ask permission to access the camera and files, even if it says it does not collect any user data.

Most data-hungry apps for the Olympic Games Paris 2024


Some apps hide they want dangerous permissions

Three out of 12 analyzed apps declare they will collect precise location data. However, the researchers found that three more apps will ask for permission to know your exact latitude and longitude: Paris 2024 Olympics, Paris 2024 Public Transport, and Paris 2024 Transport Accred.

“Location data is required for providing services like venue navigation, event location information, and personalized recommendations based on user location. It may be that the data will stay on the device. However, if the service gets compromised, the users may be exposed to both digital and physical threats,” said security researcher Mantas Kasiliauskis.

Number of apps requiring dangerous permissions


Half of the apps want to peek through camera, access storage

The most widely used dangerous permission, asked by seven out of 12 tested apps, was storage access, meaning that apps want to read and write files on the device. Allowing this may be dangerous, as it enables apps to check and modify files, including those on external media, such as SD cards.

“Usually, apps require storage access to cache data, such as maps, downloaded transport schedules, user preferences, and others,” Kasiliauskis explains.

Half of the analyzed apps also want access to your camera, meaning they could potentially take photos and record videos without additional permission.

“Cameras have many legitimate uses, such as scanning ticket QR codes or credit cards, verification, taking selfies, reporting issues, and capturing moments. It is important to remain vigilant and ensure that cameras are only used for stated useful purposes, and not something malicious,” Cybernews researchers said.

Three apps want permission to communicate with NFC tags and two apps ask permission to record audio, which might help users interact with an app via commands. However, if exploited, this permission can be used for unauthorized surveillance or unconsented marketing.

None of the app developers declared to Google that they collect video and audio recordings, and three apps declared that they collect photos.

“The app should help you enjoy the Olympics, but it shouldn't need to know your whole life story or what websites you visit to do that. This appears as a textbook example of privacy overreach. It’s concerning, given the stated intentions to build detailed user profiles and share data with tech giants. Unfortunately, invasive data collection is a longstanding industry trend, and lots of apps try to grab more data than they need,” Kasiliauskis said.

Improperly handled permissions and data can leave users vulnerable to unauthorized access, identity theft, data breaches, and other cyber threats.

Research Methodology

The Cybernews research team examined 12 Android apps relevant to the Olympic Games attendees in Paris, which can be downloaded on the Google Play Store, to determine what data they access and might collect.

First, Cybernews researchers analyzed app developers' self-declared “Data Safety” claims on the Google Play Store. These do not show the full picture but already reveal redundant data collection practices.

What data will Olympic apps collect about you


More App Developer News

Tether QVAC SDK Powers AI Across Devices and Platforms



APAC 5G expansion to fuel 347B mobile market by 2030



How AI is causing app litter everywhere



The App Economy Is Thriving



NIKKE 3.5 anniversary update livestream coming soon



New AI tool targets early dementia detection



Jentic launch gives AI agents api access



Experts warn ai-generated health content risks misinterpretation without human oversight



Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines



AccuWeather Launches ChatGPT Integration for Live Weather Updates



Stop Using Business Jargon: 5 Ways Buzzwords Damage Job Performance



IT spending rises as banks balance legacy and innovation



Tech hiring slumps as Software Developer job postings fall



AI is becoming more widespread in collaboration tools



FCC prohibits new foreign router models citing critical infrastructure risks



ChatGPT Carbon Footprint Matches 1.3 Million Cars Report Finds



Lens Launches MCP Server to Connect AI Coding Assistants with Kubernetes



Accelerating corporate ai investment returns



Enviromates tech startup launches global participation platform



Private Repository Secures the AI-driven Development Boom



UK Fintech Platform Enviromates Connects Projects Brands and Consumers



Env Zero and CloudQuery Announce Merger



How Industrial AI Is Transforming Operations in 2026



AI generated work from managers is damaging trust among employees



Foresight Secures $25M to Bridge Infrastructure Execution Gap



Copyright © 2026 by Moonbeam

Address:
1855 S Ingram Mill Rd
STE# 201
Springfield, Mo 65804

Phone: 1-844-277-3386

Fax:417-429-2935

E-Mail: contact@appdevelopermagazine.com