Contact.presentPicker()
opens the OS contact picker, but the picker's own result is thrown away and only the contact id is kept.
getDetails()
then re-queries the contact store, which requires
READ_CONTACTS
on Android and full Contacts authorisation on iOS.
Both OS pickers already return the selected contact's data without any permission. Because expo-contacts re-fetches instead of using that data, every app that only needs "pick one contact" is forced to hold a permission it doesn't need.
Google Play's Contacts Permission policy restricts
READ_CONTACTS
for apps targeting Android 17 (API 37). Enforcement begins
27 January 2027
. Apps whose only use is selecting a contact are told to remove the permission and use the Android Contact Picker. expo-contacts currently offers no way to do that.
On iOS the same design means users see the "Allow access to all contacts" prompt for what is a single-contact pick, and iOS 18 limited access can leave the picked contact unreadable (
Failed to find a contact with id
).