3 ms·
I mean, in practice that would probably work. But an interesting caveat is that apps for federated networks don't typically have one singular privacy policy. It
by DeadSuperHero 6y ago
I mean, in practice that would probably work. But an interesting caveat is that apps for federated networks don't typically have one singular privacy policy. It varies server by server. Architecturally, this is a different beast than having a client for a specific service, like Twitter.
I guess they could probably get around it by showing an instance's policies prior to user registration, but not every server actually has them, or needs to (in the case of self-hosted servers)
- jhugo 6y agoSo, when signing up for the app, how do I know what's being done with any personal information that's being collected?
- ForHackernews 6y agoYou don't. But you never do. Just because some company has a thousand pages of legal boilerplate policies doesn't mean you have any meaningful information about what they're doing with your data. The only thing you can do is try to give them a minimum of data to play with.
- swiley 6y agoYou don't sign up "for the app." The app speaks a standard protocol and you sign up on an external service (like qoto.org or mstdn.social.)
- jhugo 6y agoOK, so how do I know what the external service is doing with my personal information? And, separately, how do I know whether the app collects personal information itself (it's effectively in the transmission path between me and the external service) and where it transmits it if it does?
- thepra 6y agoThe app is on itself open source, normally it doesn't track users. I'm also a hoster of my own fediverse instance and data is shared in the network only with the instances with which you interact, and the same thing is for me. And I don't have any privacy policy because I'm the only user in my instance.
- jhugo 6y agoI've seen a great many open-source apps add analytics frameworks to the version they deploy to the App Store. Is there any way to verify that the version on the App Store is built from the same code that's in the repository, without modification?
- neltnerb 6y agoI'm not a mastadon developer or anything, but what floated up for me about this was: Accounts never get fully deleted from a Masto instance TL;DR: Choose your mastodon instance wisely. Never use your legal name as your nickname and associated email addresses. VPN is advised too. (not my work, credit/details https://rage.love/@iantila/105900906491530648 https://rage.love/@iantila/105900906491530648)
- londons_explore 6y agoI think they could meet the store policy by having a message in-app that says "I agree to abide by the terms of whichever server I connect to"
- marcinzm 6y agoThere's the privacy policy of the app and then there's separate privacy policies of the servers. The app sees your data and has access to it independently of the servers so it needs a policy.