I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…
But Apple did do this to their users. They are just as culpable as Path, if not more so. If you are going to provide a platform for app distribution, it is your, and only your responsibility to ensure that private information is not abused if you create the illusion that user information is safe.
Facts are stubborn things.