4 ms·
Well, you can verify if it is sending all data all the time, or only when you invoke it for a request. I believe most people are uncomfortable with all data be
by deet 4y ago
Well, you can verify if it is sending all data all the time, or only when you invoke it for a request.
I believe most people are uncomfortable with all data being sent all the time, but more okay with sending some data in the exact cases they choose, since they have control.
So I'd argue that the extension being open source helps a lot.
You're right that it doesn't guarantee anything for how the server is behaving in the case that you do invoke it though. For that we'd need either transparency into that source code and server operations, or, more likely, a strong privacy policy and maybe SOC2 or other certifications.
I believe the reason XP1 is subsidizing this right now is to grow their user base to attract investors, and as they develop their LLM platform, and then probably charge for business users down the road, but they don't seem to state that intention as clearly as they could.
- yunwal 4y agoI mean, you can verify the requests your browser is sending off whether the extension is open-source or not (by using developer tools in your browser or proxying the requests). So I don't think being open-source helps all that much really. I still don't think it's appropriate for them to be using responding to emails as an example in their docs, especially without a warning. If someone went around sharing my private conversations with another person without telling me, I'd lose trust in that person. They'll get away with it because some people don't see sharing data with a software company as the same thing, and it's tough to know when it's happening, but nevertheless, it's sketchy.