Amsterdam travel app leaked users’ personal data for months

See more DutchNews articles in your Google search results
See more DutchNews articles in your Google search results
Add as a favourite source on Google Add DutchNews as a favourite source on GooglePolarsteps, an Amsterdam-founded travel app used by more than 23 million people, left users’ photos, locations and home addresses reachable by anyone through an unsecured data feed – including trips put on private mode – and had known about the flaw for months, an investigation by Follow the Money (FTM) has found.
The investigation found that anyone could connect to the free app’s data feed and pull users’ names, 230 million photos and videos, and 1 billion GPS locations from nearly 2 million trips – enough to plot journeys on a map and follow many of them close to real time.
More than a million of those trips had been shared only with followers. Even accounts set fully to private gave away who a user followed, who followed them and which device they logged in from. And once FTM held the link to someone’s trip, removing it as a follower changed nothing.
Home addresses were among the most sensitive details exposed. FTM pinned down dozens from the exact location saved inside users’ photos – a shot of packed suitcases taken at home, for example, and worked out many more from the spots people returned to each night.
That photo-location data appeared nowhere in Polarsteps’ privacy policy, and was missing from the file the company released when FTM asked to see its own records.
A year’s warning
The problem was first flagged last year by a French cybersecurity researcher who said Polarsteps told him it already knew what was happening. He took his findings to FTM, which said the data stayed exposed for at least six months.
Marc Schuilenburg, a professor of digital surveillance at Erasmus University, called the company negligent, and warned that leaked location data can be used to stalk, harass or threaten people.
The leak was not from a hack – no passwords were taken and no accounts entered. Anyone with basic technical skill could connect to Polarsteps’ servers and scrape the data, with none of the request limits, CAPTCHAs or login walls.
Company response
Polarsteps, which has grown from 1 million users in 2019, said no passwords or accounts were compromised and that it is in contact with the AP.
Chief executive Clare Jones, appointed in 2024, said the company should have caught the problem itself and was working out what went wrong. It has since tightened its systems, and noted that much of the exposed data had been made public by users’ own choice.
The company’s own website warns travellers that sharing location details in real time “can make you a target.” FTM said a second part of its investigation, on dozens of military personnel it tracked to bases and missions at home and abroad, would follow on Saturday.
Thank you for donating to DutchNews.nl.
We could not provide the Dutch News service, and keep it free of charge, without the generous support of our readers. Your donations allow us to report on issues you tell us matter, and provide you with a summary of the most important Dutch news each day.
Make a donation