4 ms·
Looking forward to the inevitable "Kagi sells user data" investigative report. The simple truth is that unless they make themselves explicitly liable to users i
by simpaticoder 3y ago
Looking forward to the inevitable "Kagi sells user data" investigative report. The simple truth is that unless they make themselves explicitly liable to users if they are ever caught doing this, that the irresistable urge to monetize user data will tempt even the most well-meaning firm into sin. The ONLY solution is to make 'sinning' an existential threat to the firm. IANAL but I believe this can be done if ownership agrees to voluntarily enter into something like a fiduciary arrangement with their users. This means writing a EULA that does not minimize the firm's risk, but instead increases it in specific, meaningful ways. Increasing client risk is something attorneys are absolutely allergic to, and will argue up and down about why the client shouldn't do it. I would say that, if the customers know and care about such a step, it could be a valuable PR and marketing move that demonstrates REAL integrity.
As it is, we only believe that "users paying for services" will protect against data exfiltration because of very naive reasoning, or, perhaps more accurately, praying.
- chomp5977 3y agoYea I also worry about this. At this moment Kagi feels like the best I can do for search. Unfortunately these days I won't be surprised to hear of fuckery from them. It's happened too many times.
- fallat 3y agoIt's happened too many times in general by other companies, or Kagi? All things said, I think Kagi really as the incentives aligned. I'm not a fan of Kagi but I believe the "business is sound" :) Sure, I also believe there's no need for such a business (an extension or whatever would suffice), but that doesn't really matter here nor there.
- BugsJustFindMe 3y ago> Looking forward to the inevitable "Kagi sells user data" investigative report. Who would they sell the data to? Google? Ohhhh noooooo... More seriously, as long as it's paired with a "But their search results are still better than Google's trashfire", I'm not sure it would matter. Their tagline is "Fast, accurate, and ad-free", not "Fast, accurate, ad-free, and private."
- vunderba 3y agoMaybe try reading more than one sentence. "We care about data protection: We will be good stewards of any personal information you share with us. We do not log or associate searches with an account. More at our privacy policy." literally on the main page. Smh.
- deleted 3y ago[deleted]
- BugsJustFindMe 3y agoThat's great but really misses the point. People sign up for Kagi because they want better search results. Any privacy issues are largely peripheral.
- JohnFen 3y agoThat's me. I do love that Kagi is probably much more private than other engines, but the real draw for me was that it's a search engine that actually works well. Bottom line, that's what I'm paying for. If Kagi became a bad actor with my data, that would just make them like the majority of other search engines, so big picture, I'd not be any worse off. And I'd still have access to a search engine that lets me find what I'm looking for without a lot of struggle.
- chefandy 3y ago> The ONLY solution is to make 'sinning' an existential threat to the firm. Since the userbase consists largely of people who pay them to not act like google, at least for now, it likely would be an existential threat to the firm. They couldn't get much worse in that regard than big free services, so I'll cross that bridge when I come to it. In the interim, I'm putting my money where my mouth is and paying out of pocket for a really good service. The results are consistently more useful than Google's and the tooling is much much better. So if they are invasively tracking me and selling my data, you can definitely say "i told you so" but maybe we should call off the firing squad until the verdict has been reached. We currently don't have a trial, charges, a crime, evidence, or even empirically-informed suspicion.
- Frost1x 3y agoWell the other risk you have trusting all your personal data to some organization is the longevity of said organization. Your data may be protected as long as their business model aligns with that but it's never guaranteed to stay that way. One of the best historic examples is MySpace. MySpace started out fine and slowly as it declined and eventually dwindled to nothing, it started selling off massive amounts of previous user data. With no future or user base to speak of, there was a lot more potential benefit selling the data than the cost of protecting/holding it.
- chefandy 3y agoAt their worst, they're not any worse than my alternatives. DDG is a modicum better than Google for privacy, but using it makes me want to punch the internet in the face.
- wolverine876 3y agoWhat is their privacy policy?
- juunpp 3y agoIt doesn't matter.
- TisButMe 3y agoI work at Kagi. This is a very reasonable fear to have. We do actually not store the data, but of course you'd need to take me at my word for this. That said, if we did lie or change that, we'd be in immediate breach of our privacy policy (https://kagi.com/privacy https://kagi.com/privacy), and as a result be a very easy target for a lawsuit. Given that we're intentionally not VC backed, between the horrible press this would be and the actual costs of fighting such a lawsuit, I expect not much would be left of Kagi afterwards. We are liable to users, in a pretty existential way.
- simpaticoder 3y agoHaving read your privacy agreement, I don't see where the threat is existential if you are in breach. I think that the knowledge of engineers of the judicial system, both criminal and civil, is very naive. You can sue anyone over anything at any time - you don't need valid grounds. It also doesn't mean that if you win it matters. Your privacy policy has lots of feel-good language that actually doesn't mean anything - along the lines of the classic "We value your privacy" statement that firms often make. When you analyze it, you find it means nothing. There are no actionable clauses. For example, if you are in breach of "Anonymous logs are aggregated with GCP's logging tools, retained for 30 days." what are the enumerated damages? A counter-party would have to prove show BOTH that you are in breach AND then real damages , which is difficult in this case, and entirely misses the point. E.g. if you sell 1M user data records for $.001 each, and a user has on average 10 records on them, the real damages are $.01, but your firm made $100k on the transaction. I don't see a limit to class action (or forced arbitration) so that's good; but good luck building out that class - especially since you'll resist sharing user data with the class action plaintiff, using the same privacy policy as a shield! (This is the other trick of privacy agreements, apart from not actually saying anything: the stuff that is measurable is unenforceable). It's time that the public stop seeing moonbeams and rainbows in these matters. Do you think that a lender will be satisfied with a debtor statement "I value paying back my debts, and will never be late!"? If not, then why are we mollified by similar statements by software firms made to us? What is measurable has no teeth; what has teeth is not measurable. It's a very dirty trick.
- 3y ago