WhatsApp Help Center – We’re Updating Our Terms of Service and Privacy Policy
faq.whatsapp.com
faq.whatsapp.com
Now think all the info you can get from another person in a group chat. The phone, the public name/picture, the description, all they say (in that group)... That's the info Facebook will get about you WHEN you chat with a business account, and ONLY from that business chat.
That's apparently the change (or at least what the privacy policy says, what they do in reality is, as with everything, a mystery).
Sounds like if the businesses use Facebook tooling to manage their chats, then the Facebook servers operating the tooling will see the contents of the chat.
Obligatory disclaimer: I work at Facebook but not in WhatsApp and don't have any extra knowledge beyond what is on the linked page.
Of course, if you talk with someone, even if it's a person, you have no control over that other person. If you say something inappropriate in a group then everyone from that group can see it and share it. In the case of business they (probably) share all the chat data with their provider, which in most cases is Facebook (hence my analogy with the 3-persons group chat).
What the change seems to imply is that, even if the business doesn't use Facebook tooling, Facebook will always have access to that business chat. I may be wrong though.
yes, this is similar to any other business chat system. This would then allow Facebook to provide chat logs to businesses, something that would otherwise require a third party addon (and consequently a large eula before the chat starts)
As with any other chat system, it requires users to trust the people hosting it.
Personally I think its safer to talk about account details in whatsapp compared to the dodgy popups that are hacked into people's websites....
Why would a third party addon be required? In an E2EE setting, the business would just have to maintain logs on their end.
This sounds like it offers the possibility of cutting out that middle-man and will potentially provide an easier API and onboarding process.
That's the state of affairs.
No fucks given.
Their FAQ page does have a relatively clear summary:
https://faq.whatsapp.com/general/security-and-privacy/answer...
Neither WhatsApp nor Facebook can see the content you share with family and friends, which includes your personal messages and calls, the attachments you share, or the location you send. We do not keep logs of who everyone is messaging or calling, and WhatsApp does not share your contacts with Facebook."
Does this mean that Whatsapp will not share invasive data with Facebook? I think not.
Does it mean that they are able to run whatever profilers they like over the data and then share the output of that? I think so. They wouldn't be sharing the content per say, just the evaluation of the data. I would also suspect that shared profiling would have been going on from asap from the day they bought whatsapp.
However, note the differing wording they use: 'WhatsApp cannot see your personal messages or hear your calls' vs 'WhatsApp does not keep logs of who everyone is messaging or calling'. So, are they saying that they do keep logs of who some people are messaging/calling? Maybe they don't log Zuckerberg's usage, but keep everyone else's, and that lets them get away with the weasel words?
Also, what about video calls? They don't mention those, presumably they aren't encrypted and transit through FB/WA servers, allowing them to be viewed/recorded if desired.
The way I view them is to try to take an approach that a lawyer would. Could a lawyer try to argue that they process the data and generate an artifact that is passed to facebook, and that is fine because they are not passing the content? I think a lawyer could and would fancy their chances. And anyway, who's going to take them to court?
Do you recollect all the kerfuffle about the NSA collecting meta-data not the actual content? I think what I'm suggesting is akin to that already existent process.
This is definitely suspicious because it is so awkward. You would never say that sentence in that way. It could have easily been "WhatsApp does not keep logs of who you are messaging or calling" and that would have flowed much better.
> Also, what about video calls?
They have stated earlier that video calls are end-to-end encrypted in a similar way to voice and chat.
> Neither WhatsApp nor Facebook can see the content you share with family and friends, which includes your personal messages and calls, the attachments you share, or the location you send.
They cannot see _what_ you send. But obviously they could still see who you send messages to.
> We do not keep logs of who everyone is messaging or calling, and WhatsApp does not share your contacts with Facebook."
Which means that they cannot keep aggregate logs of call data, this is to align with the next bits of GDPR. However it doesn't preclude monitoring individuals, as that is a legal requirement.
the rough translation is: we cannot keep logs of who called whom, unless we are asked to by governments. The irony is, that if whatsapp were charging for usage, they would actually be able to store and use the aggregate call data.
The information from the EFF appears to contradict what WhatsApp says here.
https://www.eff.org/deeplinks/2016/08/how-keep-your-whatsapp...
https://www.eff.org/deeplinks/2016/08/what-facebook-and-what...
You know what? I've changed my mind. I still understand the issues but at some point you have to decide that life's too short for this. Yes, it still sucks, and FB are still evil and I don't trust them, but I calculated that the chances of me personally being harmed by this are low enough that I don't care. All it was doing was causing me extra anxiety.
CMV.
Really, as a European resident, I expected more than "accept the terms or GTFO" - wasn't that the entire point of the GDPR?
Today facebook just wants to monetize it's acquisition on detriment of the users.
99% of the users don't want this feature.
Can I opt-out of the new ToS?