Live data from Hacker News

Grindr Shares Personal Information With Third-Parties

github.com

21–30 of 317 posts

Re: Grindr Shares Personal Information With Third-Parties

#21
Even within its confines, Grindr's data are rich for blackmail. (Consider: images and messages sent and received within 100 feet of Capitol Hill.) It was recently acquired by an offshore billionaire [1].

[1] https://www.bloomberg.com/news/articles/2016-01-12/china-tec...

Re: Grindr Shares Personal Information With Third-Parties

#22
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

They have the option of not sending HIV status to any third party.

What is the privacy distinction between a third party with a contractual agreement and an employee with a contractual agreement?

Remember that Russian intelligence got a spy hired by Microsoft: https://www.theguardian.com/technology/2010/jul/14/russian-s... Will your interview questions find a foreign spy, or someone who isn't even a spy but is interested in looking at private data for personal amusement?

Re: Grindr Shares Personal Information With Third-Parties

#23
post #4

Earlier quoted context omitted.

> Also, does HIPAA say anything about technology companies outside of the medical field's data that may voluntarily collect HIV status? No, HIPAA binds only covered entities, which are (basically) care providers, insurers, and certain other parties in certain business relationships with care providers and insurers. If you give out your health information to a dating service, it's not protected by HIPAA.

That's not to say there may not be other laws that govern how you protect a user's data though.

Such as? I'm not under the impression that there are any legal prohibitions on this kind of thing in the US.

Re: Grindr Shares Personal Information With Third-Parties

#25
post #22

Earlier quoted context omitted.

They have the option of not sending HIV status to any third party.

What is the privacy distinction between a third party with a contractual agreement and an employee with a contractual agreement? Remember that Russian intelligence got a spy hired by Microsoft: https://www.theguardian.com/technology/2010/jul/14/russian-s... Will your interview questions find a foreign spy, or someone who isn't even a spy but is interested in looking at private data for personal amusement?

What?

How about "lets just not spend medically sensitive information to third party services"

Re: Grindr Shares Personal Information With Third-Parties

#26
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

They have the option of not sending HIV status to any third party.

I don't think the distinction between "third party service" and "hosting company" is all that clear. You're sending data to a third party service when you host an app on AWS. The only data protection you have is contractual.

Re: Grindr Shares Personal Information With Third-Parties

#27
post #2

Does anyone have any information on how Scruff handles that information? Also, does HIPAA say anything about technology companies outside of the medical field's data that may voluntarily collect HIV status?

From Scruff's privacy policy: "For example, we share your device identifier and demographic information with our advertising display and analytics partners."

The whole thing seems pretty bad (privacy-wise) https://www.scruff.com/privacy/

Re: Grindr Shares Personal Information With Third-Parties

#29

Also, many mobile users name their device their whole name, effectively deanonymizing all their app usage for the massive ecosystem of marketing companies out there. Having worked in the mobile marketing industry I was shocked at how many people were doing this and probably had no idea this was the case.

Is that an iPhone thing?

I know it's not possible to set the hostname of your phone on most android phones but it's unique.

Of course with Android making build versions and etc. Available to devs and in the case of chrome to your user agent. You're pretty much identifible.

Re: Grindr Shares Personal Information With Third-Parties

#30
post #23
post #4

Earlier quoted context omitted.

That's not to say there may not be other laws that govern how you protect a user's data though.

Such as? I'm not under the impression that there are any legal prohibitions on this kind of thing in the US.

That's the problem.
Post reply on HN