4 ms·
I want this, but very concerned about the security and privacy - you're talking about getting my most personal of personals (email, calendar, messages, phone ca
by jmagnuss 2y ago
I want this, but very concerned about the security and privacy - you're talking about getting my most personal of personals (email, calendar, messages, phone calls). This could be a nightmare of privacy or security breaches. That's why I'm likely waiting for Apple's version within their corporate security and privacy commitments (and they already have my data).
I don't see anything on the website about SOC2, or privacy commitments beyond a boilerplate policy?
- darweenist 2y agoThanks for leaving the comment! We totally understand your concerns, and you're not alone! We ourselves are very privacy sensitive, and never liked the idea of hardware devices always listening to us. And, as you said, our integrations are dealing with the most personal of personal information. We recently got our CASA Tier-2 compliance done (Cloud Application Security Assessment). We've also gone through Google's OAuth compliance process for every new integration we add that's related to Google. These assessments scan our app and make sure that our software meets pretty stringent standards when it comes to data security and encryption, and that we're not using the data for anything other than the specific features we promise (i.e. not sharing or selling to advertisers, etc.). You can read more about CASA here (https://appdefensealliance.dev/casa https://appdefensealliance.dev/casa). We haven't gone through SOC2 yet, but planning on soon once we have a few more integrations.
- lulzury 2y agoThis really doesn't say much though. What specific measures are in place to ensure user privacy and data protection? Does personal information get sent to OpenAI or Claude as part of the functionality? Can users request deletion of their data, and if so, what is the process? Are there specific protocols in place to ensure security? (i.e. Do you use encryption at rest?).
- talldayo 2y ago> What specific measures are in place to ensure user privacy and data protection? Unless you intend to personally audit their code, I'd argue it couldn't possibly matter. Even businesses like Apple publish all kinds of documentation that belies the reality of their infrastructure. The iMessage Security Overview doesn't mention the NSA's retention period for encrypted communique; the push notification documentation doesn't tell you about the government middleman processing each alert. You either trust people blindly, or you validate them personally. Getting a pinkie-promise about privacy from the CEO is worth absolutely nothing in real-world security terms.
- floam 2y agoBut there is provable, verifiable transparency with what Apple is doing with private cloud compute. https://security.apple.com/blog/private-cloud-compute/ https://security.apple.com/blog/private-cloud-compute/
- talldayo 2y ago> We want to ensure that security and privacy researchers can inspect Private Cloud Compute software, verify its functionality, and help identify issues — just like they can with Apple devices. So... in Apple's own words, they are allowed to cherry-pick who's allowed to read their code and audit their privacy, in the same way they strategically deny researchers the ability to audit certain iOS features. You're still taking them on their word, here.
- floam 2y agoMicrosoft and OpenAI aren’t even providing users with services with any actual confidential compute architecture. You actually need to trust them, but they don’t even claim to do what apple does, so you would need to hallucinate they are making promises they aren’t and believe THAT, and also hope they aren’t hacked or served with a warrant. It’s a different matter with what Apple is doing.
- 2y ago
- deleted 2y ago[deleted]
- toddmorey 2y agoI feel like messaging around trust is completely missing. Think of hiring a human assistant with this level of access to your life—someone who knows everything about you and can act and speak on your behalf. You'd want strong answers to (1) can they perform this role and (2) can I trust them to know everything about me and speak and act on my behalf. That's a high bar! As you develop your messaging, I wanted to share the questions I had as I think a lot of users will ask the same: 1. What powers Martin? Is it a custom LLM or powered by OpenAI, Anthropic? 2. Is any of my data ever used in training? 3. Will I always be notified before new texts / calls / actions are taken on my behalf? Does the AI present as me or are my contacts aware that it's an AI assistant that may provide incorrect information? 4. Can I easily and quickly remove all my data and context?