Changes to our policies
blog.dropbox.com
blog.dropbox.com
Diffs would be very nice, as would some way of tracking those changes over time.
Opportunity for useful service?
Agreed. This is a hard thing to get right, especially with these kind of 'inhuman' legal/procedural issues.
Then make it optional and disable these services for people opt-in for managing their own private keys.
I am not saying that you can't trust Dropbox. Quite on the contrary. But if you give your key to some unknown entity, you have to trust them. You can choose to trust their claims about what they do with it, but there is ultimately no guarantee.
I was thinking they'd have examples like the above in their Privacy Policy... but I was wrong. If they want to be crystal clear, I think they need to be more specific rather than Analytics, Geo-Location Info, and Personal Info are stored.
"For example" to me seems like just the tip of the iceberg, and the three bullet points seem fairly basic.
What do you think?
The tradeoff is hard to make, but at least for me, it was a right balance.