37 ms·
Apple requires account deletion within apps in AppStore starting January 31
- philip1209 5y agoLet's say you're building a product like Slack where you have to balance company vs. individual account deletion rights. For instance, if I join an open Slack such as Kubernetes developers vs. a company slack as an employee vs. a company slack as a guest - I believe Slack doesn't differentiate and requires the company to manage data deletion requests. How are they able to do this?
- drewwwwww 5y agothis is one case where slack's insane identity model might be beneficial, as membership to any given team is its own "account"
- codetrotter 5y agoFor the most part a very good thing. Wonder what that means for third-party HN client apps though, since HN accounts cannot be deleted.
- lacker 5y agoIt only applies to apps that let you create an account from within the app, so third-party client apps like this could just not handle the account signup. (I think they already tend not to handle it.)
- busymom0 5y agoMy apps for HN do allow account creation. I guess I will have to wait for some developers to complain to Apple to figure out how to handle third party clients.
- wvenable 5y agoFrom the article: "...all apps that allow for account creation..."
- colpabar 5y agoGreat point! It's definitely a step in the right direction, but my immediate thought was "what about all the sites that don't actually delete anything?" Hopefully apple makes a more user-friendly announcement about this that will introduce people of the concept of data retention and how "deleting" an account isn't really deleting anything.
- vineyardmike 5y ago> my immediate thought was "what about all the sites that don't actually delete anything?" Thats the whole point :) Apple is saying they need to or no iphone app.
- colpabar 5y agoMy point was that not all “delete account” buttons are created equal. Some sites just have an “is_deleted” column in their user table, and will continue to use your data after you “delete” your account. I don’t think apple has any way to check for this, but hopefully they at least touch on this topic in their announcement of the new requirement to the non-developer public.
- TedDoesntTalk 5y agoIt doesn’t actually say the account must be deleted. It says: “…must also allow users to INITIATE deletion of their account” Capitals mine. So I can allow the initiation of deletion but never actually completely delete the account… and my app complies.
- jmull 5y agoFrom the message: > ...all apps that allow for account creation must also allow users to initiate deletion... So any third-party client that allows creating an HN account would need to stop. (Are there any?)
- ASalazarMX 5y agoI hope third-party clients are not forced to, because making the delete API private would be a great opportunity to indirectly ban them. Edit: it's only for apps that allow account creation. If you expose the API for account management to third-parties, it would make sense to include account deletion.
- psychometry 5y agoLet's hope it's a wake-up call to HN admins that they need to rescind this unjustifiable and user-hostile policy.
- RamblingCTO 5y agoIt's illegal under GDPR and european data protection rights anyway. You have a right to have your account and data deleted if there aren't any important reasons not to (like finance stuff).
- spinax 5y agoNot sure which reply to post this under, so I'll just reply under GP - it took me about 3 minutes to locate a popular HN client which specifically advertises account creation in the overview. https://apps.apple.com/us/app/octal/id1308885491 https://apps.apple.com/us/app/octal/id1308885491 (Android user, can't test it)
- busymom0 5y agoI am the developer of HACK which is a HN client for iOS, MacOS and Android and I support account creation too: https://apps.apple.com/ca/app/hack-for-hacker-news-developer/id1464477788 https://apps.apple.com/ca/app/hack-for-hacker-news-developer... https://play.google.com/store/apps/details?id=com.pranapps.hack https://play.google.com/store/apps/details?id=com.pranapps.h... I have no idea what happens to third party apps as Apple doesn't specify.
- Cederfjard 5y agoFrom the perspective of Apple and their users, does it really matter whether the backend an app relies on is owned by the developers of said app or not? The experience around and ramifications of account creation and deletion are the same regardless. Which obviously can be a pain for third-party devs.
- quickthrower2 5y agoOffer a submit form that sends it over to the HN admin email address (that I forget.)
- jaimex2 5y agoReminds me. Anyone got the link to delete your Apple ID? It's been years since I've had a need for mine.
- Nextgrid 5y agoI believe you can delete it if you login on https://privacy.apple.com/ https://privacy.apple.com/.
- cheesecake_luvr 5y agoFrom a users perspective this sounds entirely positive, but I guess there may be ambiguities around the definitions of "account" and "deletion" and "account deletion".
- justusw 5y agoThis is great news. I've struggled so many times with websites that either don't offer a deletion option in the account/profile settings or where customer support never responds to requests. My hope is that deletion in this case really means deletion: The user data will not remain in their database to then eventually be accidentally leaked or hacked.
- neuronic 5y agoLegal liability is the only way to combat this bullshit. Severely harm these companies if they don't delete the data unless there is legal reason for time-limited retention (e.g. banks).
- pikseladam 5y agoThank you
- cblconfederate 5y agoDoes this include Apple Developer accounts?
- EGreg 5y agoAn app may not store credentials or tokens to social networks off of the device and may only use such credentials or tokens to directly connect to the social network from the app itself while the app is in use. Bye bye Hootsuite and other apps for automating Facebook and Twitter posts.
- sharmin123 5y agoHaving troubles logging into your email? Get it hacked efficiently: https://www.hackerslist.co/having-troubles-logging-into-your-email-get-it-hacked-efficiently/ https://www.hackerslist.co/having-troubles-logging-into-your...
- CrlNvl 5y agoWhile this is great news for B2C users/apps, I'm not sure this is ideal for B2B users/apps. I guess you don't want an employee to be able to delete his pro account without any checks.
- Liquidor 5y agoFrom the wording in the guidelines, just don't let the employee create the account through the app (shouldn't be a thing for employees anyway). Basically: App allows account creation => App must allow account deletion.
- robin_reala 5y agoThe page doesn’t say that users have to be able to delete their account within the app, it says that companies “must also allow users to initiate deletion of their account from within the app”. Checks are totally fine.
- gumby 5y agoWonder if this can be used to unsubscribe from The NY Times?
- rapind 5y agoNevermind NYT, what about your gym subscription!
- ajb 5y agoThat's been so bad that there are now gyms which have 'easy cancel' as a selling point. Pure Gym (UK) allows you to cancel by just stopping the payment (they call this "No contract" which is legally illiterate, but whatever). Ironically my bank was suspicious about me when I did it.
- matt_heimer 5y agoThat's not 'easy cancel', they've kept difficult cancelation but outsourced the responsibility (at no cost to themselves) to your bank.
- eozoon 5y agoThey also let you cancel on their app or talking to the counter. The only "catch" is you have to do it at least 4 days ahead of the next payment or it will still go through one more time. I cancelled in person, they asked if I'd consider freezing the membership instead, I said no, they printed me a receipt for the cancellation on the spot and that was it. Not a big fan of the gym itself, but I can't fault their cancellation process.
- ajb 5y agoNah, it was. Much less stressful than some salesman trying to string it out until I give in. Bank guy asked 1 question then actioned it. With another bank it would probably be 2 clicks.
- Gigachad 5y agoIn my experience it has been easy, but they charge a cancellation fee.
- BoysenberryPi 5y agoI feel like this is an objectively good thing. On Android, there are many times I signed up for something just to try it out only to decide it wasn't for me and have no way to delete my account. Currently the only thing you can do is just throw in some dummy information and leave it in the wind.
- vrc 5y agoIn that regard, SIWA with relay emails is already saving folks a big headache.
- jstsch 5y agoThis is great news, and again evidence of Apple pushing the privacy envelope forward for their customers. For many users, deleting an account by visiting an obscure flow on a web property is simply a bridge too far (assuming the service even offers an automated way of account deletion, which often is not the case).
- staunch 5y agoThe problem is that Apple has absolutely no way to enforce the deletion. An app can say "your account is deleted" but not actually delete any data off their servers. What would really give users the control they deserve is the ability to restrict what data can be sent off the device by an app in the first place. Apple should make it possible to deny internet access to an app entirely, and they should provide an API that allows apps to upload very specific kinds of data that a user has approved of, but nothing else. Of course, some apps need to be able to request unrestricted internet access. Permitting apps to collect private data and have unrestricted internet access, by default, was always a terrible decision in terms of user privacy. Apple owes it to their users to fix the problem they created.
- Karunamon 5y agoThe test for that problem will be seeing what happens when one of these apps get breached. Unless Apple is willing to terminate developer accounts when it comes out that app makers are not actually deleting anything, this is completely toothless.
- jmull 5y ago> Permitting apps to collect private data and have unrestricted internet access What apps are left if this is forbidden? "private data" can mean pretty much any user input. "unrestricted internet access" means pretty much any internet access. We're left with apps that either cannot accept user input or cannot access the internet at all.
- staunch 5y agoA good system would probably have tiered permissions, something like: 1. No internet apps: store data locally on the device only, no upload or download. 2. Partial internet apps: store data locally, and only download data through an Apple proxy service that hides the user's IP address and any identifying info. 3. Full internet apps: store in the cloud, uploaded/downloaded through an Apple proxy that logs/filters everything. Or even stored in Apple's cloud. 4. Unrestricted internet apps: VPNs and web browsers, and whatever else actually needs arbitrary access to the internet. There's no reason my bluetooth scale app needs #4 (which it has today) when I would much prefer it have #1.
- winternett 5y agoApple... Now protecting people's privacy much faster than the government... 0-60 real quick. But on the other hand, I think they should also carefully disclose the info they collect at their OS level... Just another case of that old CYA.
- jon-wood 5y agoOne of the first steps in setting up an iOS device is a great big screen telling you what data is collected and allowing opt-out. There’s several of them for each feature you’re setting up. There’s then another of those for each first party Apple app on the device. I’m really not sure how much clearer they could be.
- nielsbot 5y agoI think they do? Although it may be buried in several settings screens...
- judge2020 5y agoIt's definitely carefully (not prominently) disclosed, you just gotta go to this privacy page: https://www.apple.com/legal/privacy/en-ww/ https://www.apple.com/legal/privacy/en-ww/
- winternett 5y agoLet me get my reading glasses... Ahh... OK, they limit it only to accessing everything... lol.
- jackson1442 5y agoWhen setting up your phone or accessing any apple apps for the first time, there's a (labeled) data collection icon at the bottom of the screen that you can touch for information about what data is collected by each app/process. For the apps, this information is also available in the App Store (just like any other app). You can also view any collected system analytics in Settings -> Privacy- > Analytics & Improvements. Seems relatively fair to me.
- spicybright 5y agoThey have a lot of good will to make up for the image detection they tried to push.
- turbinerneiter 5y agoI remember that roughly 5 or 6 years ago, when I wanted them to delete my apple id, I had to call them. On the phone. And the guy told me, "if we delete your apple id, you will not be able to sign up with this mail again". I only realized after hanging up how little sense this makes.
- slownews45 5y agoThis makes total sense, and good of them to warn you. MANY people tie things like password resets to your email, not to you and may not have a retail store presence you can get to for a password reset. He's telling you - once this email is gone, it is gone and no one, including you will get it again. That is good in the sense that no one can impersonate you, but bad if you have an "ooops" moment and want to do a password reset that needs that email.
- wil421 5y agoI’ve had people try do use credential stuffing on my accounts after major breaches. It happened on a deleted instagram account and I’m glad they blocked it. I’d rather it work the way Apple does it than have someone try to recreate a deleted account.
- dmart 5y agoIt makes perfect sense, in order to prevent someone else from registering your old @icloud.com email address and impersonating you or performing password resets.
- turbinerneiter 5y agoThat does make sense, but I remember him talking about my gmail address. Not even sure I had an icloud email. But I could very well remember that wrong.
- bobbylarrybobby 5y agoThe point is that you don't want someone re-registering on iCloud with that gmail address because then they could impersonate you when interacting with Apple.
- jackdeansmith 5y agoFeels to me like public pressure is on Apple to actually justify their argument that their App Store policies are for the benefit of their customers. If that results in more policies like this that really do improve customer experiences, that's not the worst outcome.
- Despegar 5y agoThe App Store policies were always for the benefit of customers (and Apple). These policies will keep happening because the basic incentive of Apple's business model has been unchanged since 2008.
- Andrew_nenakhov 5y agoYeah, like the inability for the user to install an app after an authoritarian government decided that their subjects should not be using it, and Apple subserviently obeyed and removed said app from the Appstore. An extremely beneficial policy for the customers, right.
- simonklitj 5y agoYou’re talking about something else. Do we expect money-making companies to be the ones to war against authoritarian regimes? Do we not also expect companies to obey the laws of the lands in which they conduct business? You can’t just say screw it to GDPR and expect to continue to be able to conduct business in the EU.
- MrStonedOne 5y agoApple didn't have to lock users out of installing "unapproved" apps on their own. That isn't for the user's benefit and isn't necessary for apple to have a curated app store.
- dwaite 5y agoWhat would the alternative be - the method of installation is the App Store, and Apple's compliance was removing the public and private presence from the App Store within that country.
- paxys 5y agoWonder if this applies to Apple itself. There is no way to delete your Apple ID (or other info Apple knows about you) using the device.
- zsmi 5y agoThat's an interesting corner case. Even if turnabout is fair play I wonder if it's even a good idea. If you have two devices, and you delete your Apple ID from one of them, do you brick the second device? I think there are dragons there.
- slownews45 5y ago"Apple gives you the ability to permanently delete your Apple ID account at any time and for any reason." That said, it's a pretty massive wipe. Photos, videos, documents, and other content that you stored in iCloud are permanently deleted; you can't receive any messages or calls sent to your account via iMessage, FaceTime, or iCloud Mail; and you can't sign in to or use services such as iCloud, the App Store, iTunes Store, Apple Books, Apple Pay, iMessage, FaceTime, and Find My iPhone. In addition, any Apple Store appointments and AppleCare support cases are canceled. Deleting your Apple ID is permanent. After your account is deleted, Apple can't reopen or reactivate your account or restore your data. You lose all your credits with apple (if any) app updates will stop working even for apps already downloaded and more. "Manage Your Data and Privacy." On the following page, select "Get started" under "Delete your account."
- paxys 5y agoThe point is they enforce that third parties have to allow it from within the app itself rather than a website. But Apple's account deletion process is only available on their website.
- y2bd 5y agoApple also says apps aren't allowed to use notifications for advertising (3.1.7 Advertising) but routinely uses notifications to advertise Apple Music, Apple TV, and their other various Apple+ services ¯\_(ツ)_/¯
- anarchogeek 5y agoWhat about inmutable systems? My app (using scuttlebutt) creates an 'account' but it's located as crypto keys only within the app and apple keychain. So far the apple reviewers refused to believe that it works like. It's open source, they've got the code... but still.... Same is true for anything crypto. The account as it were exists on many devices, but it's not something you as the app creator can manage. I think apple protecting privacy is good, but the effect on actually private systems is complicated.
- _pmf_ 5y agoCongratulations, you turned a trivial problem into an unsolvable one for no reason at all.
- vineyardmike 5y agoCan you just delete the key and local data? Is the requirement to push that deletion to all other SSB instances? Seems like a case where in 2021 this rule is good, but blocks the creation of new business/product/tools that don't confirm with the 2020 way of thinking... which is good for apple.
- arkh 5y ago> Is the requirement to push that deletion to all other SSB instances? Well if you follow the GDPR: yes. Article 17.2 > Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
- 3np 5y agoAre you certain that an app developer for a client would qualify as a Data Controller here? As long as the relevant data never passes through their or other third-party servers and it's strictly local account setup interfacing with SSB I think they are not?
- CheezeIt 5y agoApple shouldn’t be interfering with other businesses and their users like this. It’s sad to see people here celebrating their inability to run unapproved software.
- nerdjon 5y agoThis is the cost of gaining access to users in iPhone. This also has nothing to do with unapproved software. The idea that a user can actually delete their data from your servers should not be a controversial topic. But of course it is for businesses and developers, which is why Apple has to make a policy like this. As a user I am very happy with this.
- echelon 5y ago> This is the cost of gaining access to users in iPhone. 50+% of Americans for everything they do, say, buy, etc. This is a monopoly by sheer volume and scale of their reach.
- nerdjon 5y agoMaybe it’s time to realize that consumers continue to choose a more locked down platform for policies like this? Businesses will continue to complain but this protects the user.
- echelon 5y agoCall and email your representatives like I do. You're not going to find support in a forum with 60+% Apple users. A lot of these people work for or have stock in this company. They don't see how this is a roadblock to competition and that this device is now in the critical path of 50+% of commerce. (Maybe they'll care more when they have to compete.)
- detaro 5y agoMeh. I don't own Apple devices, am always arguing they shouldn't force apps to go through the app store and at the same time find this a very reasonable restriction for the app store to have.
- cientifico 5y agoIs it only in Europe that this is already by law for every entity that stores personal data?
- codingclaws 5y agoWow. I wonder how many apps this will take down due to not ready.
- knightofmars 5y ago"Confirm that any third party with whom an app shares user data (in compliance with these Guidelines)—such as analytics tools, advertising networks and third-party SDKs, as well as any parent, subsidiary or other related entities that will have access to user data—will provide the same or equal protection of user data as stated in the app’s privacy policy and required by these Guidelines." I call to all smart knowing license people of Hacker News. Is this a copy-left license attached to a person's data?
- dmitriid 5y agoThis is basically GDPR. You, as the creator of an app or service is the sole entity responsible for people's data. It's on you to make sure to not spill that data to third-party services.
- Nextgrid 5y agoWhich also means that anyone complaining about this change is basically admitting to breaching the GDPR.
- pilsetnieks 5y agoIt could have been lifted verbatim from the GDPR.
- ddoolin 5y agoI was trying to delete my Instagram account just yesterday and didn't even get around to it since I needed to do it from their website.
- Andrew_nenakhov 5y agoI wonder how many email clients will suffer from this policy because they won't be able to delete email accounts from third party servers?
- tcit 5y agoThose email clients don't allow for account creation, so they shouldn't be concerned.
- marstall 5y agofrom the Guide ... > If your app supports account creation, you must also offer account deletion within the app. big sigh of relief for me with a service companion app that delegates account creation to a web admin interface ...
- wayneftw 5y agoHonest question because I don't know: Can you delete your Apple ID from within one of the iOS system apps?
- newfonewhodis 5y agoI wonder if it'll finally get me off nasty SV companies that treat my data like their kid's prom photos that need to be saved forever.
- murgindrag 5y agoAs much as I like the change, the 3-month window seems unreasonable. I don't currently have AppStore apps, and these kinds of whiplash changes are part of the reason. Microsoft, for all its faults, is much better than Apple or Google here. Businesses take planning and strategy, and these things lead to drop-everything fires. Economies rely on stability.
- wbobeirne 5y agoTo be fair, it's closer to 4 months, and it would appear that they won't yank you immediately. It's only for new submissions: > This requirement applies to all app submissions starting January 31, 2022. Unsure if this means new apps, or includes updates to existing apps. But I bet there'll be a bit more of a grace period if you don't have a new update to push.
- dhritzkiv 5y agoThis language in the past has come to mean all submissions: new apps and those being updated.
- ryantgtg 5y agoPlus, “initiate deletion of their account from within the app” sounds like the app can simply link to whatever account deletion functionality you have on your website.
- O-stevns 5y agoI don't think that's right, but the policy and the article doesn't answer these questions particularly well, so it's very much up to interpretation... The problem with linking to a website is that it doesn't make anything better for the user, since that could be either directing to a form, a support phone number or mail. Neither which improve the situation because the user is not in control. if you provide a good and easy sign in functionality from your app, through native UI and the like, then you should be able to provide the same functionality for deleting that same account. That is at least what we have recommended one of our clients, but that client is also a public transport company, so they can't afford to be in gray area where the app is either rejected or taken down.
- nathanyz 5y agoIs this now perhaps the easiest way to remove your Facebook account? Future guides will be like: 1) Buy an Apple device 2) Download and sign in to Facebook app 3) Click delete account button
- envy2 5y agoDeleting a FB account is already trivial. Instructions here (essentially, press "Permanently Delete Account" in settings and put in your password to confirm): https://www.facebook.com/help/224562897555674 https://www.facebook.com/help/224562897555674
- chaircher 5y agoI am under the impression this varies wildly from country to conutry but am unsure - maybe someone else can chime in to confirm/deny?
- zenmaster10665 5y agohuh? you can deactivate and delete your FB account through Facebook...why would this be easier?
- nathanyz 5y agoDon't they maintain shadow accounts and not actually delete the account in the background. That was my understanding from prior discussions around it. Basically they hide the account, not actually delete the account and all data associated with your use. Could be totally wrong here though...
- CGamesPlay 5y agoThey absolutely delete the account and data associated with it, however the shadow accounts thing is... separate. Their line of reasoning is: well, I uploaded your phone number, so it's "my" data and not "yours", so "you" can't delete it...
- 5y ago
- bgro 5y agoCan't wait for developers to implement "Mark your account as deleted, so you can't log in and actually delete your data such as photos later."
- excerionsforte 5y agoGreat, I detest when I can't delete accounts within apps. MarketWatch is one place where you cannot delete your account.
- emkoemko 5y agocan i buy a bunch of stuff and then charge back my credit card? then when they ban me can i then ask them to delete my account? so that i can make a new one and do it again?
- SV_BubbleTime 5y agoDoes directing you to go their website to create the account then count as the app offering account creation? I guess the precedent would be that they didn’t used to allow redirecting to a website with the purpose of avoid in-app charges. Although I think that’s over with now.
- stevepdp 5y agoBeyond issues of privacy, this is a nice quality of life fix for folks pursuing digital minimalism.
- kmetan 5y agoSo this will also apply to all banks with online onboarding? E.g. 1) Download an app (N26, Revolut, etc...) 2) Create an account 3) After login, the option to delete the account should be there... (Of course the bank should respect all data retention policies)
- Gigachad 5y agoI wonder if in app customer support counts. My bank app has no account close button but you can live chat with them in the app and close your account.
- robmaceachern 5y agoThe press release sounds more flexible than the actual guidelines: Press release (emphasis mine): "all apps that allow for account creation must also allow users to _initiate_ deletion of their account from within the app." Guidelines: "If your app supports account creation, you must also offer account deletion within the app." Has anyone seen any clarification on what options might be acceptable? e.g. I'm wondering about something simple, like opening an email composer with the app support email address and a pre-filled message body requesting account deletion which would be performed async.
- zerkten 5y agoWhy would you want to make manual work for someone who just wants their account deleted? You're possibly better off offering an option in the delete flow for them to "talk with you to see if you can work something out" versus manually processing deletion requests. Effort on those requests might recover some users which may be especially valuable if you are a subscription business. If you can't benefit from interaction then immediately imitating deletion from an API seems the only thing that would pass muster.
- robmaceachern 5y agoI think different use cases will call for different solutions. My use case is a relatively tiny number of users and any manual work they would generate for account deletion would be nil, or very close to it. It's not necessarily about recovering users who want to leave but rather minimizing the effort required to implement a more complex deletion flow that has a high probability of never being used by real users (in my case).
- greysphere 5y ago"Paid functionality must not be dependent on or require a user to grant access to this data" This almost forces all software that does anything on the internet to be subscription based (or free).
- asimpletune 5y agoCouldn’t you have a signed token for ever capability that they’ve purchased? The app could easily check the signature without exposing the private key.
- greysphere 5y agoThat puts the burden on the user/client to maintain and transfer their key to new devices, which, well I can't even do that...
- ManBlanket 5y agoThis policy seems purposefully vague. "Explain its data retention/deletion policies and describe how a user can revoke consent and/or request deletion of the user’s data." My first question before looking into it was, "What an auth tenant or some other service that stores user data?" or, "what about like a banking or healthcare app that is just a portal for another system?" And, "What does deleted even mean? IsDeleted=1?" It would appear Apple's stance on those answers is a shrug emoji. I'm no appstore developer but I got a kick out of reading a lot this for the first time. This rule bearing no exception to a trend that for most part seems intended to give Apple the license to eliminate bad actors. I got a new one for Apple. "Like, do what you gotta do but don't be a jerk."
- debaserab2 5y agoWhen did "deleted" become a vague term? Deleted means removing as much PII as you reasonably have authority to do so. It means purging all that data from all databases with a guarantee that you will be removed completely from all snapshots in a reasonable amount of time. This should be the default, normal understanding of what it means to delete your account. It doesn't mean set a flag in a database so when your company gets acquired in a few years your new owner has a nice little trove of data to mine of people that explicitly opted out.
- ManBlanket 5y agoI know you wrote this 8 days ago and I dunno if you'll even see my response but deleted has always been a vague term. There are a ton of reasons not to hard-delete data before you arrive at data mining. I know a lot of concerns regarding GDPR and data mining would contend for the hard delete, but a couple people gave you good examples. I just wanted to share one I am looking at right now. Our users have the ability to perform an action over a large set of their own data. Sometimes they do things like deleting relations they didn't realize would have a larger impact. Luckily the code in question doesn't hard-delete the entities, because I just got a ticket today asking if a huge list of IDs could be restored. I think looking at deletion as the solution to privacy concerns is the wrong way to go about it. Really, the problem is app developers think, "possession is 9/10ths of the law" when it comes to data, when in reality their relationship with the user never captured use of that data for purposes not related to the application. Just because you give your data to the bank when you make an account doesn't mean you consent to them selling it on the dark web. The same concept applies but it is much harder to police and you can even say you're going to misuse the data in the EULAs that nobody reads. In my opinion using user data for purposes unrelated to the application should straight up require explicit consent from every user, lest the seller and recipient be subjected to a fine.
- _fat_santa 5y agoHow is this supposed to work for insurance or banking apps? I would think those companies separate your "online account" from your actual account with them or something like that. I guess more generally how will this affect apps where "deleting your account" is a complicated affair (insurance, banking, mobile service, utilities, etc).
- floatingatoll 5y agoHow does it work today? All mobile banking apps that allow signup seem to also allow account closure, so there isn’t exactly a problem there. If I sign up for insurance in an app, I expect (and Apple will enforce) that I can cancel it in an app. Setting aside certain health insurance scenarios where I have no legal authority to terminate my insurance, I expect that Apple will absolutely start enforcing that insurance account management apps need to have a way to terminate coverage. But I think this isn’t the kind of business they’re concerned about, so they might focus on other business categories first.
- nightfly 5y ago> If your app supports account creation, you must also offer account deletion within the app. Insurance and banks probably aren't affected, since your account is created outside of the app
- dathinab 5y agoFrom the guidelines: > (v) Account Sign-In: If your app doesn’t include significant account-based features, let people use it without a login. If your app supports account creation, you must also offer account deletion within the app. Apps may not require users to enter personal information to function, except when directly relevant to the core functionality of the app or required by law. If your core app functionality is not related to a specific social network (e.g. Facebook, WeChat, Weibo, Twitter, etc.), you must provide access without a login or via another mechanism. Pulling basic profile information, sharing to the social network, or inviting friends to use the app are not considered core app functionality. The app must also include a mechanism to revoke social network credentials and disable data access between the app and social network from within the app. An app may not store credentials or tokens to social networks off of the device and may only use such credentials or tokens to directly connect to the social network from the app itself while the app is in use. Also interesting: > (viii) Apps that compile personal information from any source that is not directly from the user or without the user’s explicit consent, even public databases, are not permitted on the App Store. So why is Facebook still allowed? It still creates shadow profiles without permissions as far as I know.
- deleted 5y ago[deleted]
- oauea 5y agoBecause apple applies one set of policies to you and me, and another set of policies to the bigcorps. See the leaked messages from the epic lawsuit where apple execs talk about netflix's iap cut.
- LegitShady 5y ago>So why is Facebook still allowed? It still creates shadow profiles without permissions as far as I know. Maybe because the app itself isn't doing it? I'm not sure what "apps that" vs using the information the app gives you are really different but in technical detail it might be.
- andrekandre 5y ago> Apps that compile personal information from any source... without the user’s explicit consent i wonder how far they will enforce this... for example, will they tolerate apps that refuse to function without said consent? what about an eula and just tapping "ok i read it"? just my bias maybe, but "free to use" but requiring "user consent" seems like a nice avenue for getting around restriction and rules designed to protect them
- tediousdemise 5y agoI think the right to be forgotten is spelled out in plain terms. If you have my data, and I don't want you to have it, that's the line in the sand. With a few exceptions (such as data decentralization), data is trivial to delete. The problem is that businesses and governments don't want to delete data, because data is knowledge, and knowledge is power. Example: You are a typical business. A fire completely destroys all of your data, including financial data. If the IRS comes knocking for financial records, you have an excellent reason for why you cannot provide it - force majeure. A law protecting the right of a human to be forgotten should be treated the same as a fire. You do not question it, and should forcefully comply.
- theelous3 5y agoCan't imagine choosing to actually involve yourself in the apple ecosystem. Such a weirdly centralised authoritarian sphere of tech, with this creepy thin veil of individualism. Just yuck. All of it. Over and over again we see these antideveloper and anticonsumer moves - which always happen to be set in just the right way to take power and give it to apple under the guise of security or privacy.
- burnished 5y agoThe same company that allows you to opt-in to tracking (as opposed to an opt-out that would rarely be used) and evidently now requires that other companies not do the anti-consumer thing where they make sign up easy but cancelation hard?
- ekkeke 5y agoDon't get this take, as a user this is the opposite of authoritarian since it gives you more control.
- judge2020 5y agoI guess it's authoritarian in the same like that governments enforcing minimum wage or workplace safety are forcing companies to give up autonomy for someone else's benefit - but, of course, that benefit is usually in the name of human rights/not dying on the job/not exploiting workers.
- Gigachad 5y agoAs a user I quite like it. It self selects away the user hostile devs who put malicious dark patterns in their apps. If a company does not want to allow me to delete my account, I don't want to use it and I'm glad it's removed from the store.
- oblib 5y agoI don't make Apple apps but I think this is a good idea. I don't provide a way for a user to delete their data in my app but that's because I don't want to have to deal with having to tell them "You shouldn't have pressed that button". But I'll gladly delete it they request I do. That's a tough one to balance though. It's been very rare but I've had users call me a few years after their account expired asking if I still had their data, and in all those cases I did, and that saved their butts because they needed it. In my case storing user data is very inexpensive so unless they ask me to delete it I'll let it sit for long time. What's happened more often is I'll have users try to login and then renew their accounts after they've sat for over a year.
- Sunspark 5y agoWill be interesting to see if WeChat will actually allow account deletion.. last time I looked years ago, they did not.
- nunez 5y agoOh man; this is amazing (in theory). Earlier this year, I went through an attempt to purge myself from some internet services that I wasn't using. Many of the SaaS-type services I tried to remove myself from didn't make account deletion obvious at all. All of them had an email address to contact in their Privacy Policies, but whether you got a response back or not was a different matter. In practice, I could imagine apps just telling their users that their account deletion "will be processed in 24-48 hours" with a 50/50 chance of it getting processed.
- busymom0 5y agoI am the developer of HACK (Hacker News client for iOS, MacOS and Android) and have no idea what happens in my case since HN doesn't seem to offer account deletions. The guidelines doesn't seem to specify what happens with third party clients. @dang is there a way to delete accounts on HN?
- wilde 5y agoThis is great! Finally putting an end to that stupid growth hack of “sign up online, cancel via phone”.
- dynamite-ready 5y agoOf all the edicts Apple forces upon app developers, this is about the only one I agree with. I allow users to do this on my webapp, quixical.com. I wish more companies respected the 'right to be forgotten'.
- sandGorgon 5y agowhat happens with credit card apps ? because once u create a bank account - u cant just delete the credit card. the history is still maintained and the credit bureau pushes still happen. anyone know ?
- christine1337 5y agoThanks for sharing a great article. You are providing wonderful information, it is very useful to us. Keep posting like this informative articles. Thank you.
- quickthrower2 5y agoI see it now. Reddit: Want do delete your account? Install our app! I wonder if the famously hard to delete Facebook account will comply!
- jamil7 5y agoGood, I recently had the displeasure of trying to find a specific Audiobook while on my phone on holiday. Every Audiobook app/service games the system with Google keywords when you do a Google search for the Audiobook indicating that they have the book when they either don't or don't in the specific region you're in. So I ended up with 3 or 4 of these apps and accounts with no Audiobook and no way to delete my account from within the app, you have to then figure out for each one which hoops to jump through on their website or contacting support to have your info removed.
- EGreg 5y agoIf your core app functionality is not related to a specific social network (e.g. Facebook, WeChat, Weibo, Twitter, etc.), you must provide access without a login or via another mechanism. So is this what often happens in a field with large players … only the current social networks can exist, no new ones may ever be launched in the App Store?
- RNCTX 5y agoDoes no one else see these things as flailing attempts to maintain their app store revenue? They will throw the end-users (not actual end users but businesses who pay for phone app development) to the wolves in terms of forcing them to rewrite apps so that they can have a few blog posts about "user data security," despite the fact that we know there was at least one CIA backdoor in OSX in the early 2000s until ~2015 or so. At some point all phone apps are going to be javascript web apps, Apple is just desperately trying to prolong the inevitable here.
- max_ 5y ago> we know there was at least one CIA backdoor in OSX in the early 2000s until ~2015 or so. Where can i read up more on this?
- xfz 5y agoThis one sounds like it will be good for users, but I really don't like how Apple gets to regulate such a large part of the Internet. Why do governments devolve so much power to them?