{"id":43213,"date":"2026-09-04T13:59:07","date_gmt":"2026-09-04T13:59:07","guid":{"rendered":"https:\/\/www.europesays.com\/netherlands\/43213\/"},"modified":"2026-09-04T13:59:07","modified_gmt":"2026-09-04T13:59:07","slug":"amsterdam-travel-app-leaked-users-personal-data-for-months","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/netherlands\/43213\/","title":{"rendered":"Amsterdam travel app leaked users\u2019 personal data for months"},"content":{"rendered":"<p>Polarsteps, an Amsterdam-founded travel app used by more than 23 million people, left users\u2019 photos, locations and home addresses reachable by anyone through an unsecured data feed \u2013 including trips put on private mode \u2013 and had known about the flaw for months, an investigation by Follow the Money (FTM) has found.<\/p>\n<p>The investigation found that anyone could connect to the free app\u2019s data feed and pull users\u2019 names, 230 million photos and videos, and 1 billion GPS locations from nearly 2 million trips \u2013 enough to plot journeys on a map and follow many of them close to real time.<\/p>\n<p>More than a million of those trips had been shared only with followers. Even accounts set fully to private gave away who a user followed, who followed them and which device they logged in from. And once FTM held the link to someone\u2019s trip, removing it as a follower changed nothing.<\/p>\n<p>Home addresses were among the most sensitive details exposed. FTM pinned down dozens from the exact location saved inside users\u2019 photos \u2013 a shot of packed suitcases taken at home, for example, and worked out many more from the spots people returned to each night.<\/p>\n<p>That photo-location data appeared nowhere in Polarsteps\u2019 privacy policy, and was missing from the file the company released when FTM asked to see its own records.<\/p>\n<p>A year\u2019s warning<br \/>The problem was first flagged last year by a French cybersecurity researcher who said Polarsteps told him it already knew what was happening. He took his findings to FTM, which said the data stayed exposed for at least six months.<\/p>\n<p>Marc Schuilenburg, a professor of digital surveillance at Erasmus University, called the company negligent, and warned that leaked location data can be used to stalk, harass or threaten people.<\/p>\n<p>The leak was not from a hack \u2013 no passwords were taken and no accounts entered. Anyone with basic technical skill could connect to Polarsteps\u2019 servers and scrape the data, with none of the request limits, CAPTCHAs or login walls.<\/p>\n<p>Company response<br \/>Polarsteps, which has grown from 1 million users in 2019, said no passwords or accounts were compromised and that it is in contact with the AP.<\/p>\n<p>Chief executive Clare Jones, appointed in 2024, said the company should have caught the problem itself and was working out what went wrong. It has since tightened its systems, and noted that much of the exposed data had been made public by users\u2019 own choice.<\/p>\n<p>The company\u2019s own website warns travellers that sharing location details in real time \u201ccan make you a target.\u201d FTM said a second part of its investigation, on dozens of military personnel it tracked to bases and missions at home and abroad, would follow on Saturday.<\/p>\n","protected":false},"excerpt":{"rendered":"Polarsteps, an Amsterdam-founded travel app used by more than 23 million people, left users\u2019 photos, locations and home&hellip;\n","protected":false},"author":2,"featured_media":43214,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[23],"class_list":["post-43213","post","type-post","status-publish","format-standard","has-post-thumbnail","category-amsterdam","tag-amsterdam"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/posts\/43213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/comments?post=43213"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/posts\/43213\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/media\/43214"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/media?parent=43213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/categories?post=43213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/netherlands\/wp-json\/wp\/v2\/tags?post=43213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}