Paisa Press

Asia's loan-app beat

News

Can a loan app access my contacts in India? The Play rule

Play's Personal Loans policy bars READ_CONTACTS and seven other permissions, and only apps on the RBI DLA list may submit in India. Read 20 Sept 2026.

By Staff, Paisa Press 6 min read

Can a loan app access my contacts in India? Not under Google Play’s rules: the Play Personal Loans policy, read on 20 September 2026, lists READ_CONTACTS among eight permissions that personal-loan apps, lead generators, loan calculators and Earned Wage Access apps are prohibited from using. An app installed from a link sits outside that page’s rule.

This is an evergreen question, not a news event, and the four ranking pages read for this piece say Google bars contacts without naming a permission. The rule text is short, so here it is.

Can a loan app access my contacts in India under the Play policy?

The Google Play Personal Loans policy states, under General Requirements: “Personal loan apps, apps with the primary purpose of facilitating access to personal loans (for example, lead generators or facilitators) or lines of credit, accessory loan or credit apps (loan calculators, loan guides, etc.), and Earned Wage Access (EWA) apps are prohibited from accessing sensitive data, such as photos and contacts.” The list that follows, as read by this desk on 20 September 2026, has eight entries, not four.

Permission named by the policyOrder in the policy’s listPolicy’s own wordsPlain reading of the name (this desk did not fetch Android’s permission reference)
READ_EXTERNAL_STORAGE1“sensitive data, such as photos and contacts”Files on shared storage
READ_MEDIA_IMAGES2Photos, in the glossImage files
READ_CONTACTS3Contacts, in the glossThe contacts list
ACCESS_FINE_LOCATION4Not glossed separatelyPrecise location
READ_PHONE_NUMBERS5Not glossed separatelyThe device’s phone numbers
READ_MEDIA_VIDEO6Not glossed separatelyVideo files
QUERY_ALL_PACKAGES7Not glossed separatelyThe list of installed apps
WRITE_EXTERNAL_STORAGE8Not glossed separatelyWriting to shared storage

The prohibition is not limited to the lender: a lead generator, a “loan guide” or a calculator that feeds a lender is caught by the same sentence. And the page describes requirements for apps submitted to Google Play. In the text read it says nothing about an APK installed from a link or a third-party store, and this desk fetched nothing on Play Protect, so nothing is claimed about a sideloaded app.

What else the policy requires of a loan app on Play

The same page requires a personal-loan app to set its Play Console category to Finance, to disclose the minimum and maximum repayment period, and to carry a privacy policy covering personal and sensitive user data. It does not allow apps promoting loans due in full in 60 days or less, and tells developers to “Be properly licensed and registered to provide loans in all regions where your app is available.” We argued in August that app-store policy keeps doing work regulators intended to do.

Which rule applies to the app in front of you: Play or the RBI?

The India section of the Play policy is one gate: “Only apps that submit a license and are on the ‘Digital lending apps (DLAs) deployed by Regulated Entities’ list of the Reserve Bank of India (RBI) may submit personal loan apps to Google Play for review.” A platform that only facilitates lending by registered NBFCs or banks must say so in its declaration, and “the names of all registered NBFCs and banks must be prominently disclosed in your app’s description.”

So on Play, two rules stack: the app must be on the RBI’s list to submit, and once submitted it may not use the eight permissions. Off Play, the Play half falls away, and of the RBI half this desk could read only part. The RBI’s Press Release 2025-2026/288 of 8 May 2025, read on 20 September 2026 from the copy the NBFC industry body FIDC hosts, announces the Reserve Bank of India (Digital Lending) Directions, 2025: regulated entities were to upload their apps through the CIMS portal by 15 June 2025, with the list live “on or before July 1, 2025.” The list exists “for the limited purpose of aiding the customers in verifying the claim of a DLA’s association with a RE” and is built on lender submissions “on as is basis, without any further validation check by the Reserve Bank.”

The Directions’ own clause on what a DLA may take from a phone was not read: the Master Directions page on rbi.org.in answered 418 to this desk on 20 September 2026, so the RBI’s data rule is not printed here as the RBI’s words. The press release establishes that a DLA listing is a lender’s claim of association, not the RBI vouching for the app; our assessment of the DLA directory against the NBFC register shows how to use it.

How to tell which side of the line an app is on

Check where it came from. Installed from Google Play, the app is bound by the policy and a contacts request is a request for something it names as prohibited. Arrived as an APK from a link, the policy page read does not reach it and the only public check is the RBI list, which the RBI itself calls unvalidated. Our August piece on permission creep is the general survey.

Why do loan apps ask for contact access?

The Play policy page this desk read does not say why; it only says the access is prohibited for lending apps on Play, and this desk read no lender’s own explanation at 200. Whatever reason it gives, an app that asks for READ_CONTACTS is asking for something the Play policy names as barred.

Indian law could not be sourced at 200 by this desk: the RBI Digital Lending Directions, 2025 page on rbi.org.in answered 418 on 20 September 2026 and its data clause was not read. What was read is Google’s rule: on Play, a personal-loan app may not use READ_CONTACTS, and in India only apps on the RBI DLA list may submit at all.

Can loan apps call your contacts if you don’t pay?

The Play policy read speaks to data access, not collection calls; an app that follows it should not hold your contacts to call. Whether a collector may contact third parties is a conduct question; the recovery-agent call-time rules this desk read fix hours, not who may be called. Treat a call to your contacts as a complaint to the NBFC behind the app.

Which permissions should a loan app never ask for?

On Google Play, the eight the Personal Loans policy names: READ_EXTERNAL_STORAGE, READ_MEDIA_IMAGES, READ_CONTACTS, ACCESS_FINE_LOCATION, READ_PHONE_NUMBERS, READ_MEDIA_VIDEO, QUERY_ALL_PACKAGES and WRITE_EXTERNAL_STORAGE. The policy’s own gloss is ‘sensitive data, such as photos and contacts’. A request for any of them means the app is off-policy or did not come through Play.

A collector holding your contacts got them from an app that either broke the Play rule or never faced it, and the hours a recovery agent may call you are a separate question. Nothing here is financial advice. Borrow only from lenders licensed in your own jurisdiction, and verify a licence with the regulator directly rather than trusting an app listing.