Show HN: FullStory – Private-by-Default Mobile Analytics
bionic.fullstory.com
bionic.fullstory.com
If the app maker is in control, and the user can do nothing but use the app or not, then while the new defaults are better than nothing, I will continue to have all known FS domain names blocked on my devices / not use said apps at all.
Can the user permanently set and forget a "I don't care if the devs want analytics, they aren't getting them from me" flag in the app? If yes, good. If yes by default, better.
Can the user see what the analytics wants to unmask? If yes, good. Can they permanently make surgical tweaks to the unmasks to not unmask certain fields? If yes, better and impressive.
Edit: the wireframing and reconstructing from xaml views is quite the technical innovation, better than screenshots indeed.
I'd love to have us give better controls to end-users -- we're still investigating ways for users to better control things like that on their own devices. The web makes this a bit easier with adchoices (ie: setting cross-domain cookies opting out) and the ability to more easily block domain patterns with browser plugins.
We have an internal team that is dedicated purely to privacy innovation and I'll bring this up with them.
> Edit: the wireframing and reconstructing from xaml views is quite the technical innovation, better than screenshots indeed.
Thanks! This took us a _long_ time to get right, as you can imagine.
This blog post scratches the surface on the approach we're taking and how we've balanced privacy and fidelity.
The product page has some additional info as well:
https://www.fullstory.com/mobile-apps/
Happy to answer any questions about how we are doing this, how we're putting privacy first, or technical questions. Some other folks from the team will be around as well.
I appreciate that you think about privacy but you really can’t call this “private by default” as the amount of information you collect from every user is extensive. Privacy by default requires that you have the user opt in to the tracking (i.e. privacy is the default setting) and minimize information collection, which you really don’t.
If you really care about privacy you should consider going through a formal privacy by design & default process and certification.
I helped build a product for site owners that automatically quarantines tracking events (including FullStory) for replay with consent at a later time[1]. This product enables sites to include scripts with potentially risky privacy implications like FullStory without ever having to worry about unconsensual PII data emissions. Blog post coming soon!
The documentation doesn't specify this (yet), but no data leaves the device if recording is shut down.
something that is interesting to note is how similar to UI is to their competitor LogRocket. I don't know who copied who (or maybe they both copied someone else?), but the similarities in look and feel were very uncanny
FullStory feels like its UI has certainly received more thought and care over time, whereas LogRocket is full of lots of new bells and whistles, but they're still sorting out how to put the experience together elegantly. LogRocket has this problem because they're building features so quickly (though I'm sure a couple good UI/UX hires could help with the UI keeping pace with features).
Agreed on price, by the way! We were happy with the FullStory product and don't utilize LogRocket's additional dev tools, but switched to LogRocket due to cost.