Live data from Hacker News

Grindr Shares Personal Information With Third-Parties

github.com

131–140 of 317 posts

Re: Grindr Shares Personal Information With Third-Parties

#131
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

> My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised.

Honest question, are you in the SAAS analytics industry or is anyone else that can comment on this? I am not (though I do do data work) and I would actually be surprised if the SAAS company _didn't_ have access to the data.

That would require some kind of dedicated setup so that Grindr's data was not at rest with other company's data which is a) super expensive, b) no reason to expect that the SAAS company would not have access for maintenance/troubleshooting and c) kind of defeats the purpose of using SAAS.

Re: Grindr Shares Personal Information With Third-Parties

#132
post #2

Does anyone have any information on how Scruff handles that information? Also, does HIPAA say anything about technology companies outside of the medical field's data that may voluntarily collect HIV status?

> Also, does HIPAA say anything about technology companies outside of the medical field's data that may voluntarily collect HIV status? No, HIPAA binds only covered entities, which are (basically) care providers, insurers, and certain other parties in certain business relationships with care providers and insurers. If you give out your health information to a dating service, it's not protected by HIPAA.

> No, HIPAA binds only covered entities, which are (basically) care providers, insurers, and certain other parties in certain business relationships with care providers and insurers. If you give out your health information to a dating service, it's not protected by HIPAA.

This is correct, though it's worth noting that HIV status is actually protected under more strict terms than just HIPAA, and that may in fact apply to Grindr.

There are a lot of laws at the state-level which restrict the ability to collect, record, or pass on information related to an individual's HIV status even when none of the parties involved are covered entities (or business associates of covered entities).

Re: Grindr Shares Personal Information With Third-Parties

#133
These are 3rd party analytics firms and not any random companies. Both these firms have strong data protection processes and are very secure. From Grindr's perspective, they are probably looking for analytics for different segments of their users and send all data to Localytics who help them with this (vs. trying to build these internally).

Here is a thought. Do we think that the data is more secure with Grindr itself or with Localytics? I feel the answer might be the latter given data security means a lot to Localytics (as they provide analytics as a service to thousands of apps) vs. Grindr itself who may not go to the extent of Localytics to safefuard user info.

Re: Grindr Shares Personal Information With Third-Parties

#134

Why wouldn't HIV status be protected by HIPAA?

> Why wouldn't HIV status be protected by HIPAA?

Because Grindr is not a healthcare provider (doctor, nurse, hospital, etc.) or a health insurer. HIPAA doesn't apply to social networks, or otherwise (e.g.) Twitter would be liable if you wrote a post announcing your own HIV status on their service.

Re: Grindr Shares Personal Information With Third-Parties

#135
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

1) At least don't send any personal data over http. It's 2018 for fucks sake. I can't believe there are companies out there with such a hand-wavy approach to this. Is it so hard to do https in this day and age? It's so basic wrt to a security audit, my head hurts. The fact that extra data is sent over https shows that they made an active decision to partition this data into non-important/important.

2) Just don't fucking send it to a third party. Every single time you do that you yield control over the data, introduce another party to the mechanics thus doubling the risk of disclosure and they you cry 'breach of trust'.

> Not everyone can afford to perform their own product analysis.

Then don't do it and don't store sensitive information. You're taking on a risk and if you don't have the money to roll your own analytics then you probably don't belong on the market. This is no longer a playground, this is the real world, especially for this kind of information. People can get killed based on Grindr leaks. It's the big boys game and if you don't have the backing, you shouldn't play in the first place. And this app specifically should not have any problems with funding, give me a break.

Re: Grindr Shares Personal Information With Third-Parties

#136

It's become clear over the last year there is a strong need for a data privacy regulatory agency in US government. I understand that regulation hampers growth, but the tech industry is mature and developed to the point that it's time to reel in "moving fast and breaking things" a bit.

> It's become clear over the last year there is a strong need for a data privacy regulatory agency in US government. I wouldn't trust a governmental regulatory agency to aggressively fulfill it's mission. My impression is that in general they're too much at the mercy of politicians. I suspect a more effective strategy is to enact legislation that makes companies liable under civil law, with private citizens empowered…

>I suspect a more effective strategy is to enact legislation that makes companies liable under civil law, with private citizens empowered to sue.

There's no chance that will happen. It should, but it won't. By taking away the ability of individual citizens to sue, and vesting that power in a government agency, it protects the companies while empowering the regulators. The end result is fair toothless regulation and more donations/lobbying dollars flowing from the private sector to the public sector/politicians.

A number of anti-spam laws ended up this way.

Re: Grindr Shares Personal Information With Third-Parties

#137
post #8

For what it's worth, the most private data here is shared to analytics companies for Grindr's only analytical use. My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. This sort of deal isn't the same as sharing the HIV status to Google or Facebook so that ad…

> My guess is that Grindr's agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I'd be incredibly surprised. Honest question, are you in the SAAS analytics industry or is anyone else that can comment on this? I am not (though I do do data work) and I would actually be surprised if the SAAS company _didn't_ have…

For startups of their sizes, it's unlikely they have strict data controls. So, probably anyone working on the product side of things, support, engineering, services, has access to their analytics data. Basically, most of the company likely has access to that data. Grindr really shouldn't be sending that data to their analytics providers.

Re: Grindr Shares Personal Information With Third-Parties

#138
post #120
post #47

Earlier quoted context omitted.

If one is HIV positive it would probably be a draw of the app to find only others who are also afflicted. Turning it off might result in some illegal decisions.

Grindr wouldn’t be the only way to declare one’s STD status though. It could be omitted from one’s profile, but declared during chat, for example, or prior to hooking up.

Methinks you don't understand the problem space. Putting it in your profile is intended to save the afflicted from wasting tons of time and energy on a. talking with people who will immediately nope out when they learn your status and b. dealing with a lot of emotional BS from people who want to see themselves as nice but who aren't really ready to deal with you and your situation.

That can be a hard enough conversation to have even if they know. Being straight up rejected by some high percentage of people who started to chat you up and are done the minute you mention HIV would be a dreadful experience. It's possible they are on the app precisely for the ability to pre-screen people for their willingness to hook up with someone HIV positive.

Re: Grindr Shares Personal Information With Third-Parties

#139

These are 3rd party analytics firms and not any random companies. Both these firms have strong data protection processes and are very secure. From Grindr's perspective, they are probably looking for analytics for different segments of their users and send all data to Localytics who help them with this (vs. trying to build these internally). Here is a thought. Do we think that the data is more secure with Grindr itsel…

The data is already in Grindr’s systems, this means it is ALSO at Localytics (and others). This is not as safe as if it was only in Grindr’s own systems.

Re: Grindr Shares Personal Information With Third-Parties

#140

Even within its confines, Grindr's data are rich for blackmail. (Consider: images and messages sent and received within 100 feet of Capitol Hill.) It was recently acquired by an offshore billionaire [1]. [1] https://www.bloomberg.com/news/articles/2016-01-12/china-tec...

Reminds me of the relationship between the Mafia and the homosexual community of the early-mid 20th century. The Mafia didn’t particularly like gays, but they ran all of the gay bars because it gave them the opportunity to blackmail their patrons.
Post reply on HN