Docs

Android 17 Contact Picker: Tracking Referral Data Loss

Android 17 replaces all-or-nothing contacts access with a picker — referral and invite features lose the full contact list they used to see.

Acquisition

Android 17 introduces a system Contact Picker that replaces the old all-or-nothing READ_CONTACTS permission with a browsable, user-controlled interface: the user selects which specific contacts to share, and the app never sees the rest of the address book. Apps targeting Android 17 (API level 37) that request the standing READ_CONTACTS permission must now file a Play Console declaration justifying why the picker doesn’t meet their needs, with enforcement live from October 28, 2026. For most invite-a-friend, referral, and contact-sync features, the picker is the compliant path, and it is meaningfully more private.

The tracking consequence lands squarely on any growth loop built around full contacts access: referral matching, “who of your contacts is already on the app” prompts, and contact-based deduplication all previously worked against a complete address book and now see only whatever subset a user chooses to share through the picker. A referral funnel that measures “contacts matched” or “invites sent” against the old full-list baseline will show a drop that looks like declining referral engagement but is actually a change in how much of the address book the app can even see — a data availability shift, not a behavioural one, and the two need to be told apart before anyone re-prioritises the referral feature based on the wrong read.

Data Points to Track

  • Contacts access mode per session (system Contact Picker vs. legacy READ_CONTACTS, where still granted on older targets), logged alongside every contact-matching or invite event
  • Contacts shared per picker interaction, since the picker lets users choose a small subset — this replaces “total contacts available” as the meaningful denominator for match-rate calculations
  • Referral match rate recalculated against contacts actually shared, not against an assumed full address book, so match-rate trend lines stay comparable across the migration
  • Picker abandonment rate, tracking how often users open the Contact Picker and close it without selecting anyone, as a proxy for friction the old permission dialog didn’t have
  • Invite completion rate split by access mode, comparing outcomes for users still on legacy full access against users on the picker, while both populations still exist

Setup Steps

  1. Instrument the Contact Picker result callback to log how many contacts were shared per interaction, not just whether the picker completed.
  2. Change the denominator in referral and match-rate calculations from “contacts available” to “contacts shared,” and keep both numbers during the transition so the shift is visible rather than silently absorbed into a lower rate.
  3. File the Play Console READ_CONTACTS declaration early if any feature genuinely can’t move to the picker, and track which features fall into that category versus which were migrated.
  4. Add a picker-abandonment event distinct from a general funnel drop-off, so a user who opens and cancels the picker isn’t conflated with one who never triggered the referral flow at all.
  5. Segment referral funnel reporting by access mode for the duration of the migration window, so quarter-over-quarter comparisons account for the shrinking legacy-access population rather than blending two structurally different data sources.

Actionable Insights

A falling “contacts matched” count that tracks closely with the share of sessions now using the picker instead of legacy access is evidence of a measurement artefact, not a weakening referral program — the fix is recalculating the baseline, not redesigning the feature. If picker abandonment is high, that’s a genuine UX signal: users are opening the picker and backing out, which the old single permission dialog never surfaced, and it points to friction in how or when the app is asking. And if invite completion rate per shared contact holds steady or improves under the picker despite a smaller average contact count, that’s a sign the smaller, user-chosen list is actually higher-intent than the old full-list approach — worth testing whether narrower, picker-driven invite flows convert better even after full contacts access eventually goes away entirely.

Expert help

Need help tracking this in your app?

Our team sets up analytics pipelines for mobile and web teams every day. Talk to us and get your first events flowing in under an hour.

Talk to an expert