Concerns Arise Over Pokémon Go Granting Full Access to Players' Google Accounts [Update: Fix Incoming] - MacRumors
Skip to Content

Concerns Arise Over Pokémon Go Granting Full Access to Players' Google Accounts [Update: Fix Incoming]

Pokémon Go is experiencing a momentous launch week, with an estimated 7.5 million downloads and nearly as many daily active Android users as Twitter in the United States. The rollout has not been entirely smooth, however, as the game has indirectly been at the center of crimes, robberies, and even car accidents.

Pokemon-go-access

Pokémon Go has full access to your Google account (Image: Ars Technica)

Now, an even bigger potential concern has arisen, as systems architect Adam Reeve has discovered that Pokémon Go grants full access to a user's Google account linked during the iOS sign-up process. Players can alternatively link a Pokemon.com account, but the website is currently experiencing issues for many users.

pokemon-go-sign-up
When granted full account access, Pokémon Go developer Niantic is theoretically capable of viewing and modifying nearly all information stored in your Google account, including your Gmail messages, Google Drive documents, Google Maps navigation history, search history, and personal photos stored on Google Photos.

Now, I obviously don't think Niantic are planning some global personal information heist. This is probably just the result of epic carelessness. But I don’t know anything about Niantic’s security policies. I don't know how well they will guard this awesome new power they’ve granted themselves, and frankly I don't trust them at all. I've revoked their access to my account, and deleted the app. I really wish I could play, it looks like great fun, but there's no way it's worth the risk.

It remains unclear what information, if any, Niantic is actually collecting from users, but the permissions are concerning given the company's history.

Niantic was formed by Keyhole founder John Hanke in 2010 as an internal startup at Google, until it was spun out as an independent entity in October 2015. Google then partnered with The Pokémon Company and Nintendo to invest up to $30 million in Niantic, so it has a remaining interest in the company.

Google is known to collect and track data from its users, fueling the privacy and security concerns. Niantic told Ars Technica that it has "no comment to share at the moment" about the issue, prompting some players to uninstall the game until the potential privacy implications are addressed.

Pokemon Go gameplay 2
Pokémon Go is available as a free download on the App Store [Direct Link] in the United States, Australia, and New Zealand, but anyone can install the app now with a U.S. iTunes account. The game is expected to expand to the U.K. and additional countries in the near future. Read more about Pokémon Go here.

Update: Niantic tells The Verge that the company did not intend to request full Google account access and will issue a client-side fix to reduce the number of permissions.

"We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon Go only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information is or has been accessed or collected. Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access. Google has verified that no other information has been received or accessed by Pokémon Go or Niantic. Google will soon reduce Pokémon Go’s permission to only the basic profile data that Pokémon Go needs, and users do not need to take any actions themselves."

Popular Stories

iOS 26

iOS 26.4 Adds Two New Features to CarPlay

Tuesday March 24, 2026 1:55 pm PDT by
iOS 26.4 was released today, and it includes a couple of new features for CarPlay: an Ambient Music widget and support for voice-based chatbot apps. To update your iPhone 11 or newer to iOS 26.4, open the Settings app and tap on General → Software Update. CarPlay will automatically offer the new features so long as the iPhone connected to your vehicle is running iOS 26.4 or later....
Apple Business hero

Apple Unveils 'Apple Business' All-in-One Platform

Tuesday March 24, 2026 8:53 am PDT by
Apple today announced Apple Business, a new all-in-one platform that unifies device management, productivity tools, and customer outreach features. The service is designed to be a consolidated replacement for several of Apple's existing business-focused offerings, including Apple Business Essentials, Apple Business Manager, and Apple Business Connect. It provides organizations with a single...
AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday March 24, 2026 12:31 pm PDT by
Apple today released new firmware for the AirPods Pro 2, AirPods Pro 3, and the AirPods 4. The firmware has a version number of 8B39, up from 8B34 on the AirPods Pro 3, 8B28 on the AirPods Pro 2, and 8B21 on the AirPods 4. There is no word on what's included in the firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance...

Top Rated Comments

keysofanxiety Avatar
127 months ago
If you primarily use a Google account, I don't think Nintendo stealing your data should be the pinnacle of your privacy concerns. ;)
Score: 29 Votes (Like | Disagree)
127 months ago
I'm actually more shocked that Google allows developers access to all user's account goodies.
Score: 14 Votes (Like | Disagree)
127 months ago
Shouldn't Google's default level of access just be basic access? It really should prompt you if anything higher is required. I mostly blame Niantic for poor coding/security practices but Google is at least partly to blame here IMO.
Score: 12 Votes (Like | Disagree)
127 months ago
I figured that most people have more than one google account. One for "real life" and others for stuff like this.
No they don't. People rarely think situations like this, especially the audience this game is targeting.
Score: 11 Votes (Like | Disagree)
doctorwhofan98 Avatar
127 months ago
I figured that most people have more than one google account. One for "real life" and others for stuff like this.
I really think you're overestimating the general public. Pretty much everyone I know would just accept the conditions without reading them, and I don't know anyone with multiple accounts. If the developer had malicious intent, they'd have a lot of power right now.
Score: 11 Votes (Like | Disagree)
eniaczz Avatar
127 months ago
whatever, I don't care about my google account. I only care about Pokémons!!
Score: 11 Votes (Like | Disagree)