> Anything and everything the app and its 30 social, ad, and analytics SDKs are able to capture and exfiltrate from the phone.
I’m asking about iOS. If you have an Android device - using an operating system written by an ad tech company, the Hilton app is the last thing you should worry about.
Instead of being hand wavy, what exactly do you think an analytics SDK can “exfiltrate* from your phone outside of the app sandbox without your explicit permission?
> Maybe they won't upload the list of my installed apps (which can leak information like religion or medical issues),
Not possible with iOS. There was a loophole that Twitter used where they would try to send a message to another app. But Apple closed that a few versions ago.
> Almost certainly I'll have to agree to lengthy ToS that will then be used as justification to inundate me with spam
You mean the same TOS you have to sign when booking from their website? But I use the built in “Hide My Email” feature on iOS and give each app/website that I don’t care about a separate email that gets forwarded to my main email address.
> “ The Android permission model is particularly messed up because it changes every few SDK target versions, so it's hard to build a mental model what exactly you're allowing
“I care about my privacy yet I use an operating system with a poor permission model written by an adTech company”