Jumbo: Privacy Assistant for iPhone
jumboprivacy.com
jumboprivacy.com
"Analytics Our iOS application can send analytics to our analytics providers: Segment and Amplitude. We do not track or store any personal information in our analytics. Instead, we ask Apple to generate a unique deviceID which we use as a unique token for analytics purposes. Our analytics are 100% anonymous."
Pierre, CEO, Jumbo.
List a few ways it's "trivially trackable".
Pierre, CEO Jumbo
The more they do it the more they can narrow it down, until they reach the point where they have a set of IDs that only ever come from the same device/version, IP address as well as very similar times of day.
Also, let's talk about IP address.
We have a CloudFlare worker that sits between our app and our analytics proxy (which role is to send data to Segment). And this worker from Cloudflare is a piece of code that removes the user ip address from the request made to our proxy, hosted on Heroku.
Here is the worker code: https://gist.github.com/pierrevalade/85bbe1e5278b81813e08e7e...
That way, only Cloudflare gets the user IP address (and to my the best of my knowledge I don't know how to access it), and our servers never get it.
Why does your privacy policy mention third-party analytics then? Why do you mention “Segment sends the data to Amplitude” in another one of your comments if you claim here that you don’t use any third-party analytics service?
Also, just wondering - why do you need to send anything in the first place? People have been building software just fine for decades before this whole “analytics” plague started going around, and I didn’t notice software quality being improved by it (if anything software has gone significantly downhill).
2/ I said we don't use any (mobile) SDKs from 3-parties analytics, but we do use their backend (Segment, Amplitude). We send the requests from our anonymous proxy directly to their servers.
I was worried that mobile SDKs would leak other data (iOS version, device size, ...) that I don't want to know about. And as a general rule we don't like to use SDK/code from 3parties for security reasons.
3/ We use analytics to track how many users are using the app, and how many users are using the cleaning features. This data does help us to make strategic decisions.
2) Good thinking!
3) Doesn’t the App Store give you stats on how many people downloaded their app?
Also I’m concerned about “strategic decisions” - so it’s a business behind this app then. What’s the business model? Last time we had a business claiming to unsubscribe you from newsletters... turns out they were actually sharing data with marketing companies, so I’m rightfully concerned.
3/ yes, unroll.me made the wrong calls. But for Jumbo we can’t even access your data, everything happens client-side. You could say that at some point the client will upload all your to our cloud, but that’s really not going to happen. Again, here, how to trust us? First, audits. Second, my reputation. Third, independent researchers would reverse engineering our app, and look at the networks call made. Open for more feedback
Our business model is the one of Dropbox. Pay (you or your employer) for more features.
If your model is a good old “pay for good software” model, then why not just ask what features people want? Why do you feel the need to stalk what people do instead of politely asking?
A verifiable 'code available' license would be a bonus
If its the advertiser identifier[1], they can track across apps, however this is an easy fix by enabling "Limit Ad Tracking" in settings, which causes the ID to be all 0s.
0: https://developer.apple.com/documentation/uikit/uidevice/162... 1: https://developer.apple.com/documentation/adsupport/asidenti...
We use: UIDevice.current.identifierForVendor?.uuidString
for the deviceID
Let me know if you think that's not a good idea, but it seemed a unique app device that's completely a black box for us, Segment, or Amplitude.
> 100% anonymous
Choose one. This is pseudonymous, which is just a fancy word for "likely deanonymizable".
This language feels disingenuous, given that fingerprinting could be used to match an identity elsewhere.
Just a simple example - I’m sure a data scientist can do a lot more magic given enough data.
This is bullshit. You don't ask Apple. Apple enforces this requirement on every single app.
Do you still think that's "bullshit"?
I didn't try it for Facebook. It has three general settings (public, friends, and just me). I've already tuned Facebook as best as I want. It wasn't clear what FB would overshare or under-share with Jumbo's settings.
This seems like the sort of app one might use to prevent James Gunn style problems from old content.
For Facebook, the full list of Settings we support is here: https://blog.jumboprivacy.com/smart-privacy-for-facebook.htm...
Jumbo disables ads personalization, face recogonization, and soon location data storage.
Feel free to ask me more questions.
Pierre CEO Jumbo
Pierre, CEO Jumbo.
Pierre, CEO
I've learned in my life of computing since the TI-99/4A is that privacy is not an app or program or device... It's all analog - what the end use does and does not do. I don't see this really pushed today, the personal responsibility of personal data.
You hit the nail on the head, I couldn't possibly agree more. People have to think(ahead - sometimes quite a ways) before they act.
Are there (or will there be) any features/benefits for people who don't have social media accounts?
Is there any benefits of auto insurance for people that don't have cars?
All that said, since the app is free and since they claim they're not slurping personal data, I do wonder how they plan to monetise this.
Jumbo works 100% client-side, that's why we have built it as a native app.
You can read more on our architecture on our blog: https://blog.jumboprivacy.com/secure-jumbo-never-sees-your-d...
It's quite cool. We don't have any servers processing your data.
Pierre, CEO Jumbo.
I also appreciate that they know they're selling to a privacy-conscious audience, so they go over the top in assuring that it's all done client side!
Very nice so far.
These are baby steps for sure, but maybe one day all these people will be ditching google for duckduckgo and protonmail, etc.
Facebook should be scared. It's at least X% of the lock-in they have on people.
I downloaded mine, read some stuff that made me think a bit, and then I finished up with deleting my account.