Nigeria16 August 2026· 5 min read

The Code Behind the Shame: How We Built a Digital Loan Trap

We need to talk about what happens when you write an Android app that requests `READ_CONTACTS` for a ₦30,000 microloan. It's not just bad ethics—it's weaponized software architecture.

NigeriaAfricaTechStartups
The Code Behind the Shame: How We Built a Digital Loan Trap

A few years ago, someone reached out to me on LinkedIn offering decent money to help patch together the backend for a quick-turnaround Android lending app. The brief was simple enough on the surface, but five minutes into reviewing the spec document, my stomach dropped.

Right under the KYC requirements was a clear instruction: Sync user's entire address book to MongoDB before disbursement. If default hits day 3, queue automated SMS to top 20 frequent contacts.

I turned it down immediately. But plenty of engineers didn't.

Every time I hear another story like Chinedu’s—getting hounded and having his mother called a fraudster over a ₦36,000 balance—I don't just think about greedy loan sharks. I think about the codebase that made it possible.

Lines of Code

The Geolocation Double Standard

There's an open secret in product design: companies treat African users like second-class citizens in the codebase.

TechCity recently ran a teardown showing how big tech platforms serve clean, plain-language privacy toggles to IP addresses in New York, while serving buried, opted-in-by-default tracking switches to users in Lagos.

As developers, we know this isn't accidental. Nobody accidentally writes an if (user.ipCountry === 'NG') block that hides ad tracking controls behind three extra nested divs. It is deliberate UI malice.

When European regulators slap fines on platforms, engineers spend sprint cycles refactoring consent flows and sanitizing telemetry endpoints for EU traffic. But for our market? The default stance is still "extract as much telemetry as the device allows before the OS blocks it."

We've normalized stripping out user autonomy because we assume nobody with regulatory teeth is inspecting the network tab.

The Anatomy of predatory permissions

Let’s look at what these micro-lending APKs actually do on a budget Android device.

When you install a predatory loan app, the onboarding flow is engineered to overwhelm. A user sitting in a crowded bus park in Owerri or rushing through an emergency in an Akure hospital doesn't have time to audit run-time permissions. They just smash "Allow" to get past the gate.

<uses-permission android:name="android.permission.READ_CONTACTS" />
<uses-permission android:name="android.permission.READ_SMS" />
<uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" />
<uses-permission android:name="android.permission.READ_CALL_LOG" />

Under the guise of "fraud prevention" and "credit scoring," the app dumps the entire contact list, parses bank alert SMS messages to calculate cash flow, and tracks cell tower location.

Data and Finance

If the borrower misses a payment by 48 hours, the system doesn't trigger a risk assessment review. It triggers a background worker. A simple Python script or Node worker queries the dumped contact payload, grabs numbers labeled "Mum", "Pastor", or "Boss", and fires off formatted shaming templates via bulk SMS gateways.

That is not financial inclusion. That is extortion automated through an API.

Sapa is Not an Excuse for Dark Patterns

I get it: surviving as a developer or small studio in Nigeria is tough. Sapa is real, electricity bills at your Gbagada workstation keep climbing, and when a client shows up with a fat budget to build a fintech app, it's tempting to look the other way on product requirements.

We tell ourselves, "I'm just the dev, I don't run the recovery team."

Except code isn't neutral. If you write the endpoint that exposes a mother's phone number because her son missed a payment deadline, you are part of the pipeline that humiliated her.

The FCCPC recovering ₦10 billion and the NDPC chasing hundreds of predatory platforms is a start, but regulation always lags behind deployment. Google clamping down on Play Store permissions helped, but sideloaded APKs and shady SDKs still circulate in every corner of the country.

As people who build software, we have to draw our own lines. If an app requires you to turn a user’s social circle into collateral for pocket money, delete the repo and walk away. Building ethical tech isn't something we can wait for foreign regulators or local task forces to enforce on us—it starts right at the keyboard.

Related from Nigeria

Available for Hire

Let's build your next big product.

Accepting project-based freelance, remote engineering roles, and hybrid positions.

© 2026 Samuel Stanley · Full Stack Engineer