On android, it's possible for apps to access contacts in a few ways:
1. Request permission to access all contacts at runtime - user chooses yes or no.
2. Ask the user to choose a specific contact. This pops up some system UI, and then relays back the information the app requested about the contact the user chose:
public void pickContact(View v) {
Intent contactPickerIntent = new Intent(Intent.ACTION_PICK,
ContactsContract.CommonDataKinds.Phone.CONTENT_URI);
startActivityForResult(contactPickerIntent, RESULT_PICK_CONTACT);
}
@Override
protected void onActivityResult(int requestCode, int resultCode, Intent data) {
if (resultCode == RESULT_OK) {
switch (requestCode) {
case RESULT_PICK_CONTACT:
soSomethingWithContact(data);
return;
}
} else {
Log.e("MainActivity", "Failed to pick contact");
}
}
And for most cases, it's also fine to just use the "share" intent to send a link or similar via whatever app and whatever contact the user chooses, without any extra info leaking to the providing app. You can actually see this in action with the uber app - if you choose to share your ETA with someone, it first asks for permission to access all your contacts. If you deny it (which I do) then it follows up by having you send a link via the regular share intent.