Our investigation determined the threat actor downloaded or accessed your uninterrupted raw genotype data, and may have accessed other sensitive information in your account,
Fascinating. I was under the impression that you couldn't get that without having it sent to your email address. I certainly haven't seen any other ways of getting raw genomics out.
Is this that the threat actor sent it to an email that was potentially compromised or do they have download logs of some form of hidden direct download feature?
As a mobile app developer I promise that you want to have push notifications that are capable of doing meaningful work on your phone. Apps are often entirely dead but a push notification from a central server will still get you X/Y/Z functionality.
Companies abuse this to then track you, and harvest endless amounts of information but the alternative is your phone no longer notified you of anything and the majority of background functionality for your apps dies entirely.
What I wish would happen is that mobile OSes have another set of location/network permissions for push notifications.