Consent Matters
Article Summary
Swiggy's Android team faced a UX dilemma: auto-reading OTPs felt magical to some users, creepy to others. How do you balance convenience with transparency?
The Swiggy engineering team shares how they evolved their OTP verification approach from silent SMS reading to user-consented verification. This shift improved both user trust and conversion rates across login, signup, and payment flows.
Key Takeaways
- SMS Retriever API caused user anxiety: no permission prompt but automatic OTP reading
- SMS User Consent API adds transparency with a simple user approval prompt
- Extended OTP capture to wallet linking and bank transactions across providers
- Achieved 2% improvement in bank transaction success rates post-implementation
Critical Insight
By switching to Google's SMS User Consent API, Swiggy gained user trust through transparency while improving payment success rates by 2%.