If it does network access on your behalf, that would be trickier.
Also, apple should not collect data on behalf of the apps like statistics of any kind (unless you opt-in)
If it does network access on your behalf, that would be trickier.
Also, apple should not collect data on behalf of the apps like statistics of any kind (unless you opt-in)
It is entirely possible to not collect data but use network APIs. For example the app I work on uses Mapbox APIs and CloudKit to store data. Transmit needs access to the network to do it's job, which is akin to what you suggest.
It would be very tricky to audit these things. However it should be pretty straight forward to audit for the presence of libraries which are widely known to collect user data which I suspect is on the horizon.
Is that tracking on your end? It is not.
Is that tracking on _their_ end? Neither I nor you have any way to actually know, even if they claim no data gets stored in a way that allows behavioural mining. So claiming there is no tracking is wilfully ignoring the entirely possible case that there might be, even if you personally have no reason to believe there is. Geodata is incredibly fingerprinty.
It does allow offline use, so I should experiment with that. While offline use requires pre-loading tiles which reveals something about a person, it doesn't reveal more than a broad regional interest.
But in general, I agree. It's a murky situation. Any web request leaks information about the user.
An IDFA also collected via any other service / broker provides such a feedback loop. Location data is reasonably valuable. Mapbox also offers a navigation API; this would be behavioral data from which companies like to try to derive interest and intent.
And has been mentioned a few times in the thread - even if one app author goes out of their way to reimplement the API in a privacy-preserving way, all it takes is one that doesn't to reasonably link all the other requests based on other data points. (IP would be more than sufficient - but since it's a location service, even if all the apps run the requests through a proxy, location-at-time and location/destination pairs are also useful to help link.)
In the end I don't think there's anything privacy-conscious app developers can do other than eschew external services as much as possible, clearly inform users when external services are used, and push for stronger regulation (from phone / OS manufacturers and the government) about data privacy.
This is the crux of it here. In particular, we seriously need regulations making the things Apple is pushing required by law, not something a company with its own vested interests pushes.
Particularly since as many point out whenever this is discussed, there is a bit of opacity with regards to Apple's own apps.
Remember that every single request to them includes your device's IP, potentially user agent, and maybe even a unique identifier generated on first run which will correlate all those changing IPs together.
Over time, IPs & user agents can very easily be connected together by a data broker with very high certainty.