This is just completely disingenuous from Google.
> - Request access to the narrowest permissions necessary to implement your product’s features or services.
> - If more than one permission could be used to implement a feature, you must request those with the least access to data or functionality.
> - Don't attempt to "future proof" your product by requesting a permission that might benefit services or features that have not yet been implemented.
My first thought was "oh it would be NICE if G actually enforced these". But the truth is that they're not. One glance at the Android Play store, and it's abundantly clear that Google is letting shitty apps request whatever unnecessary permissions left and right.
Literally the top flash light app requires "full network access", GPS precise and approx location, "view network connections" and "receive data from internet".
It's complete bullshit, Google isn't policing these permissions at all, but just using it as an arbitrarily enforced rule.
It's pretty clear what the incentives are. Android already has a flashlight, but this one has ads, harvests and sells your data, and uses Google Play Billing Service. Win for Google. On the other hand, there's PushBullet, which gives users more control and this is key, the option to use a platform that is not controlled by Google. It has nothing to do with user privacy.
And the whole nice thing about these permissions is that they are granular, this means it should be trivial to point out which one is wrong or better and why, like an error message. That is not "gaming the system", it's literally what these permissions are for.
This is also clearly not an automated scanning process that PushBullet accidentally got hit by. Because it would have to have been a very slow running process, given the heaping amounts of trash in the Play Store. And then it just happened to pick PushBullet instead of the Flashlight app that has 50 times more downloads??