Google and Microsoft have opaque and unpredictable ad moderation
dkzlv.medium.com
dkzlv.medium.com
The entire thing just looks like a badly built scam. Every individual decision can maybe be explained as a branding or design choice, but the end product just doesn't look reliable.
I don't think Google gives a shit about your blog articles about how Google is bad, every tech company has written one of those at this point. They're also not as much anti-privacy, they're anti-anti-anti-privacy. A privacy focused product is fine, a product that prevents Google from stalking you not so much.
It'd definitely be a false positive, but the truth is that if I saw this ad, I'd definitely click the "report" button.
We're freemium. You're not forced to get a subscription right away. You can even use the product without it at all.
> there appears to be no way for you to self-host the service at the moment
We will provide such an option if there will be any demand. For now it would just waste a lot of our time without any real output. Still, you can do this if you want.
(disclaimer: I work for Google, in a division that has nothing to do with ads.)
Also, the name and domain seem like you're compensating for something, or trying to trick people. If a bank has big signs saying, "No, we won't steal your money, promise" that opens up a whole lot of questions. Why do you need to put "safe" all over the place? Is there some reason I should think it isn't safe?
Lol :) Thanks for your honest feedback! The app looks more traditional, btw. (https://imgur.com/a/KabWkNS) Based on the feedback here I will probably change the landing page to something more traditional.
> Also, the name and domain seem like you're compensating for something, or trying to trick people
Wow, that is the opposite thing we were aiming for. There are a lot of other apps that provide the same value while being completely unsafe to use. We're just emphasizing on the core value. Strange to hear that it causes the opposite reaction.
There is nothing wrong with it, apart from my usual criticism to landing pages like this: I still have no clue what is it for, or who I must be to use it, what exact problem I have that it could solve. But that’s in line with virtually everything. Nobody puts a history like “Tired of manually entering your invoices? Want automatic categorizing of expenses? Your bank formats are illegible crap? …” anymore.
I wonder what critics above think of e.g. curve.fi, which is serious enough to eat $1000 per transaction.
Edit: yeah, the app looks more like “modern” “design” “thing” to me, but it’s just me missing clear UI borders and color-cued sidebars and property sheets.
> Nobody puts a history like
Yeah, a bunch of people here told me we have a huge problem with copy. Will rework it. Storytelling is not my feature, but I'll try my best :)
> it’s just me missing clear UI borders and color-cued sidebars and property sheets
Will think of a better way, thanks!
Bottom line: financial products require an incredibly high degree of trust for most people, and this feels very much like the work of a sincere developer working alone and without a lot of product design experience. All the little issues (copy, design, presentation, unknown solo developer) that would be forgivable in a product of any other kind become red flags and deal breakers when my finances are concerned.
I hope this is helpful feedback! Keep on building!
I'm not sure it's a high converting site because I couldn't understand what you were offering but I'll remember the design.
After reading it a third time, I realize I guess it's just an open-source version of Mint?
But the author provides zero evidence that Google bans ads for "privacy-first services". It was probably classified as a crypto scam or similar.
Just write a better ad that's clearer about what it's actually advertising, for goodness' sake. And make the product's website a bit more professional looking too -- it looks like a scam. There's no way I'd trust my finance credentials to anybody who built a site that looks like... a weirdly updated version of a GeoCities page?
> After reading it a third time, I realize I guess it's just an open-source version of Mint?
Well, not a great sigh for us, but at least… you guessed right!
> But the author provides zero evidence that Google bans ads for "privacy-first services". It was probably classified as a crypto scam or similar.
I made this conclusion based on the information provided by my friends working in Google and Microsoft. Again, there's no way I can reliably say the _real_ reason because all Google said was "Unacceptable Business Practice" linking to this page. (https://support.google.com/adspolicy/answer/6020955?hl=en#36...)
That's actually more or less the point of the article: you get banned for life for no apparent reason. Is that how it's supposed to be?
> it looks like a scam
What is it that you don't like about the design? I just tried not to follow the common guidelines for the design and make the design more… developer friendly?
Claiming they are against "privacy-first services" is just creating a victim narrative where one does not exist. As people keep saying here on this very website, these platforms do not owe you a microphone.
Also, just one bit of advice, most developer types will have adblockers, so you're really not going to have a great time trying to target them with adverts.
Right, but this cannot be the end of the story. We cannot allow people's life chances getting crippled by an all powerful oligopoly for nothing more than clumsy choice of words.
>These companies are trying to protect average people from being scammed on their services, and I would honestly prefer they keep doing this
Really? That's what you wish for? Deplatforming for life without any due process to determine whether the person has actually done anything wrong? I cannot believe that anyone really wants this.
Or that moderation is inconsistent?
Or that you get banned for life?
Make up your mind!
One red flag I did notice was some awkward phrases/english.
"Phones support"
"This is why you need an open community that will point at your lies or convinces newcomers this app is safe."
"...if you’re not a new kid in the block"
Could someone please elaborate on the aspects you feel are deeply obvious to the point of not pointing them out? I seem to be missing them as well.
Compared to mint.com, which I guess it's competing with, it looks unprofessional and something I wouldn't want to trust my sensitive data with.
Just imagine if there were a new bank which was decorated like... a head shop, or strip club, or something like that. Would you want to bank there?
Which greets you with a “please close me” popdown, stutters because of a video, which plays below transparent text, jumps around at vertical scroll and couldn’t prevent it on horizontal carousels. That looks unprofessional.
Not to mention nauseous light-light-bleached green colorscheme. (I guess it ought to resemble mint)
This could just be a mobile compatibility issue to be honest, but in my eyes this doesn't look like a website that I would trust with my financial information. Sure, they say all my info is encrypted, but so did Zoom at some point.
If I'm going to throw my financial data at something, I want its website to look professional. This website looks more... whimsical to me. That's a fine choice for a website advertising a text editor or social media client, but money is serious business. That first impression is extra important with such questionable ads and such a questionable domain name.
It's very upsetting that you found us scam-alike. It was never meant to be this way. If anything, we're trying to be the opposite: we open-sourced the whole app, we do not ask for your email during sign up, we wrote a post about our security measures in details (https://safeapps.io/content/security).
We'll work on our marketing to be more… convincing?
The first thing that comes to mind for building a better reputation is probably your branding. Picking "safe" as a software brand gives off a paradoxical feeling of unsafety, in the "[safe] free Windows 12 download [open source][free!!].dll.bat.exe" kind of way. Adding a tag like [safe] or [free] or (recommended) is something spammers and scammers do to try to convince their victims to click. I don't think you can pull something like that off without being a well-known brand first, not with that brand name. Matrix.org, for example, has the [Matrix] brackets as a brand, but the word "matrix" isn't used for anything dubious. Their links also don't use the [brand] marking in their ads.
Because of all this, I think your brand (unintentionally) mimics a lot of scam ads, which is why my first thought would be "this is a scam, report". Your website, "safeapps.io", has a feeling I associate with "securefiles.com" or "freewindowsupdatez.net" for much of the same reasons.
Your TLD, .io, is very popular for modern (web) developers but when I think about my bank details, the British Indian Ocean Territory isn't exactly what comes to mind. Perhaps a minor detail few people will fall over, but it's kind of ironic to have the TLD of a remote island nation for a financial software package :)
Perhaps I'm not your target audience, but I want any service I trust with information about my finances to be professional. Your website seems inspired by popular, modern, energetic branding, the kind I'd expect from a soda brand or a kids' commercial. I'd personally much prefer a boring, run-of-the-mill Bootstrap theme with some added branding over the artsy website you've created. That's just a personal preference, of course; maybe you want to show that you're not one of those stuffy bankers, and maybe I'm just too boring to get that. Modern marketing has shown that this strategy definitely attracts some people.
In the end, I'm just a random voice on the Internet. I'm no marketeer, I've never met any investors, and I don't run paid service of my own. You probably shouldn't base your entire marketing campaign on my ramblings.
I do think you should think about your branding, though, especially the way you present it in ads, and consider picking a brand name that's not as easy to confuse with a link that'll install malware. Besides, you can probably use a more recognisable brand name than "safe money". "[SOTANY]" or many other words from thisworddoesnotexist.com probably work a lot better for a software brand than "[safe]"!
I see that your comment got the most upvotes here, so it IS what I needed to hear.
At least I won't need to change a lot in the product itself as it actually has a rather boring and standard design: https://imgur.com/a/KabWkNS
I think we'll go with your idea of changing the brand and the landing. Might help.
On the other hand, I bank online and KNOW my data ends up on the banks server in a readable format and still do it because trust itself is built by what the audience perceives and there are HUGE network factors in play when building trust. There is no trust momentum for you guys considering the sort of information you expect customers to trust you with.
Also, you seem to think that you're selling to customers who routinely develop proofs about what bob can keep safe from alice or whatever, but are those really the folks who will make your product a win? I would almost think those folks would more likely be your competition rather than your customers. Heck, I really can't tell who you are marketing to honestly.
If you were an online battle tank game and asking 60 a year its a completely different story.
No offense to the poster, but everything about this service, the ad, the copy, etc. make me think "major scam". If you are offering a legitimate service, it looks like you're trying as hard as possible to be confused as a scam.
So, from Google's perspective, when they see this, they respond with some generic "this looks like a scam" response, but obviously if they gave enough detail on every little thing to fix it would make scammers' lives much easier.
So while I've seen other cases where accounts have been frozen, etc. with little recourse, and I have a ton of sympathy, in this case I'm ok with Google making it hard to sign up if something looks this much like a scam.
edit: It would nice if the downvoters could explain their thoughts.
Any business that is sophisticated enough to build a genuine product is also usually sophisticated enough to realize that "the message is the medium", that a professional non-scammy appearance is required for most customers to even consider trusting it, and so invest in professional graphic design. This goes doubly or triply so for anything finance-related or that takes your finance credentials -- that requires huge trust.
So on those two principles, when something looks like a scam, it much more likely is -- because for certain categories of scams, scammers want it to look that way, and non-scammers don't. "Scammy apperance" is a genuinely meaningful signal in practice.
But if you don't believe that, then there's this bridge I'm selling... ;)
[1] https://www.businessinsider.com/why-nigerian-scam-emails-are...
This is so middle-age stereotypical that I’m not even sure if it’s worth opposing. The first thing you see in every financial app is how much unprofessional it really is with regards to UI, and it only gets worse with time. It doesn’t take a ph.d. to understand that this “trust theater” is just that, and it’s beyond me how people trust someone with their money based on some CSS (which is presumably fubar in the source view).
Regardless, I still find your position kind of crazy. Basically you're saying (honestly totally subjectively without any real rational basis) that this _looks_ like a scam (opinion), therefore it's more likely to be a scam and therefore it should be banned. So if the user responds and demonstrates that it _isn't_ a scam, then you why the hell not allow it to work again?
Personally I think Google should be legally required to provide this reasoning and to reinstate it if they are initially incorrect in their conclusion that it's a scam. I'm kind of amazed that that would even be required since it's basic human decency that if Google is incorrect, they fix their mistake. But well money is more attractive than morals and decency.
It's not the job of an ad service to go "well, you look really scammy, but digging deeper it turns out you might be OK, so go ahead". Scammy ads make advertising worse for everyone, even if they just look scammy. That's leaving aside that "looks scammy" is a reasonable signal for "is scammy".
I'm in the "all ads are bad" camp, but I can also observe that scammy ads contribute to more widespread perceptions of ads being bad, even among people who might otherwise intentionally click on some ads.
And frankly I don't even think the ad looks all that scammy. At least nothing even remotely specially compared to all other ads I see by Google.
Regardless, we don't even know that this is the reason why Google banned it because they refused to say why they did. They should be required to do so.
Punishment has to fit the crime. If we allow corporations that are more powerful than nation states and can crush a person's chances in life then conflict resolution needs to be bit more sophisticated than a cost optimisation algorithm.
If this is true (which is very much in question), that's the issue. If it's true that nobody else can enter that market, then that's the problem we should address. A monopoly or oligopoly does not suddenly become OK because we put some rules in place for how it should operate, and those rules may in fact entrench the established companies because they can afford the overhead.
I think in some areas it is extremely difficult to prevent market concentration. How many viable operating systems can there be for instance?
Some markets simply have a structural bias towards very few global players. Trying to prevent that is a quixotic effort.
We need some rules to govern the relationship between dominant platforms and those whose livelihoods depend on those platforms.
My view on this is somewhat skewed since I rarely see ads at all, I tend to view every ad I do see as suspect, and consider anything to do with money/finances to be especially suspicious.
Miscellaneous opinions:
1. The ad started with "[safe] money". I imagine most people would instantly disregard it as a scam and not bother reading further.
2. The ad references crypto. While crypto can be awesome, it's also great for scammers and the like. So if your ad is already at-risk for looking scam-y, stressing an association with a safe-haven for scammers might not do any favors.
3. The ad has a sentence start with "Tracking", then a line-break. People who want privacy generally don't want to be tracked, so that might be a poor happenstance.
4. It's not immediately clear how the app is end-to-end encrypted. That claim usually makes more sense if it's like a messaging-service, where end-to-end crypto implies security against the server. But if clients are just contacting the server, then "end-to-end" would seem misleading.
5. The ad said "100% open source". Unlike most of the stuff in it, that part does inspire more confidence. So much so that, personally, I might lead with it before even saying what the product is, or else immediately afterward.
1. it's hard to judge about that right away. It would be cool to see the ads data beforehand. If I saw the ad performs poorly I would change it obviously. "[safe] money" is our brand, so it would be strange not to start with it.
2. the ad does not reference crypto. We had a mention of it on the landing page, that is all. We allow people to pay with crypto along with banking cards — so it's kind of your decision to go one way or another.
4. its more or less the same. You can be e2ee if you, say, have an encrypted version of Google Drive. e2ee in this case means that even though there's a server (which we also have) it cannot read the data in any way. We're mostly the same.
5. ok, we'll think about it, thanks!
Thanks for your detailed feedback.
https://support.google.com/adspolicy/answer/7645254?hl=en#zi...
We mentioned crypto because we allowed people to pay for our services using BTC or ETH, that is it! You're also allowed to pay using usual banking card.
Still, I submitted an appeal after we tore down this whole feature but no luck, still got banned after that.
Just to note it -- you may be suffering from a [curse of knowledge](https://en.wikipedia.org/wiki/Curse_of_knowledge)
> The curse of knowledge is a cognitive bias that occurs when an individual, communicating with other individuals, unknowingly assumes that the others have the background to understand.
here, as you know what your product's supposed to be and what the ad is supposed to convey, so you may be assuming that it's more obvious to viewers.
For example, when your ad starts with "[safe] money", you may know that it's your product's name. However, to a regular viewer who doesn't already know your product's name, it may give off an impression of a stereotypical scam.
As a thought -- it might help to get someone else to write a draft of an ad for you. Someone who doesn't already know what your product is, so you have to explain it to them. Then they can try to make an ad that corresponds with their initial conception of it.
This is the truth and it's very depressing. I would personally support either legislation forcing Google to be more transparent of these bans or legislation ripping the company apart so that they don't own the ad exchange, as well as sell ads themselves, as well as everything else they have integrated. One can only dream...
I also think "we reserve the right to refuse service to anyone" applies no matter who you are. I don't support the idea of legislation that forces giving detailed policy responses, or any responses at all.
Google (and others) have formed a business around having policies so automated that half the people involved might not even know what the policy is, just "computer says no" or "computer flagged it and someone somewhere in the review process said no". I don't think that practice should be banned; on the contrary, it should be possible to try the approach of using automation to be able to scale.
And that's a potential opportunity for other competitors; one demonstrated path to success in competing with a company like Google is providing better support and real human interaction.
If it turns out that a company is succeeding in spite of awful service, it might be because their product is just that good to overcome that deficiency, or it might also be because their monopoly prevents people from competing with them even with a better product. That's worth examining. But I don't think that's an argument that people should be forced to explain why they don't want to do business with someone; I think that's an argument that we should make sure that it's possible to compete fairly and offer better service to people who want better service.
> On the other hand, this post talks about having a similar response from Microsoft, and those companies didn't collude
As I wrote, I got the ban from Microsoft minutes after Google even before I created an ad or told them what site I planned to advertise. So my guess is that they do exchange data about potential fraudsters.
> applies no matter who you are
In this case we're talking about a monopoly that is the internet's gatekeeper. If they decide they can refuse their service to us, we die, no guesses. Is that the right way?
It should never apply to monopolies. Governments should always go to all extent into making sure a market is competitive, or make sure things like that do not happen. The preference should obviously be the first one.
If you're abusing a monopoly in a way that prevents other people from coming in and doing better than you, that's the issue, not the specific manifestation of how you're abusing it.
"we do not impersonate other brands"
The domain is safeapps.io. Not only does this name seem very similar to other applications, some of which are on the Google Play (https://play.google.com/store/apps/details?id=com.hopehealin...), a service provider (https://safemoney.com/) and even a US military domain (https://safe.apps.mil/). Additionally, on the page the word "safe" doesn't even show up, suggesting the domain name is a squat. I don't believe that it's a squat, but the author is jumping to some big conclusions without looking at some potential causes.
It's because policies are in place to prevent them from doing so, you won't get special treatment or they will be out of a job.
Without seeing the Ad data it's hard to say but Financial products have a lot of policy in place and it's not enough to be ready to provide certification, in some instances you must do this beforehand.
While the policies that prevent even insiders from finding out why some ad or another was banned to avoid special treatment, they also have the side-effect of being opaque to conceal arbitrary, malicious, or insidious motivations. After all, I'd assume if there are good, clear, generally agreed-to reasons why some ad (or even some account) should not have access to Google services, transparency would justify as much. But without transparency, it's inevitable that there will be abuse.
Odds are, there already has been. And Google benefits keeping that behind the curtain.
This is relevant because they interview a moderator and they talk about how insufferable these companies are, and how they have a private set of guidelines that they can't reveal that these scam locksmiths are in an never ending battle to subvert.
Under this lens, and looking at the ad [safe] provided, I have to agree with other peoples take, it's likely [safe] tripped over a bunch of private moderation rules about crypto and ponzi schemes, and nothing to do with privacy.
You got crushed all the same. The fact that it wasn't malicious just makes sure nobody will suffer any consequences for it. Except you, of course.
And even if it was malicious, the veil of "processes" and "policy" will be sufficient to smother any investigation.
Leading with "Encryption" and "Finance" is probably what caused the ban. It got put in the bucket of "shady crypto currency stuff" or "internet money laundering".
Though, yes, it's a shame the system doesn't first issue a warning, and let you reply with a message to a real human with context before a ban happens.
We submitted multiple appeals, but they were all declines — presumably, by real humans. I appreciate your feedback on the copy though. I guess, no harm in trying.
Because yeah, nothing seems to be amiss in the ad. Sorry to see you so poorly treated by the tech giants.
Hell, it's AN INNOVATION I came up with — or at least so I thought I thought most people would be able to see this name instantly BECAUSE of the brackets, lol.
Thanks for your sympathy, I appreciate it.
https://safeapps.io/content/security
That’s what I’d like to see from any security page!
Most of our competitors say they have "strong encryption", but when you read the page it actually means they have SSL. Or that they use SHA256 for hashing the passwords. That is… disappointing.
I also think companies should be able to determine that working with another company is too risky, such as what happened here.
Do we really think people are entitled to use Google or Microsoft services? If so, shouldn't those services just be nationalized?
"If so, shouldn't those services just be nationalized?"
This definitely doesn't (and shouldn't) follow from an entity receiving a common carrier-type designation.Were Section 230 to be revoked, my understanding is that no change would actually occur, other than cases related to it taking longer.
It doesn't give companies common carrier-like designations, and unless they're telecoms, they don't actually have such designations regardless of what Section 230 says, so I'm not sure what the GP was getting at.
All filters are going to have false positives and false negatives. The fact that they missed some things that they likely meant to block doesn’t really say anything about the stuff they block that they meant to let through.
The simpler explanation is that their site got caught by some spam/scam filter.
That was my first thought, but the problem is that the site was moderated by actual human beings and all the appeals were still denied.
> Many similar companies run ads on Google all the time
Like I said in the end of the article, it's a thing that is allowed for established companies, because I too run into such ads all the time. I made this conclusion based on the information provided by my friends working in Google and Microsoft. Again, there's no way I can reliably say the _real_ reason because all Google said was "*Unacceptable Business Practice*" linking to this page. (https://support.google.com/adspolicy/answer/6020955?hl=en#36...)
The "[safe]" is confusing since it make's me think there is an not-safe version but this link is to the "safe" version. Like how HN put's [pdf] in URLs that link to PDFs.
It looks like they're gearing up for antitrust action, and this is a good example of how large companies' anticompetitive behavior is stifling innovation and destroying small businesses.
The personal information we collect is stored and/or processed in United States, Netherlands, and Russian Federation, or where we or our partners, affiliates, and third-party providers maintain facilities.
How is that privacy-first or even legal? That clause alone is in direct violation of GDPR and CCPA. So I'm not surprised that this got banned.Also, the website does not name a data protection representative in the EU. In fact, I couldn't find any information about the country that the company is based in (I assume Russia), or if there even is a registered company to begin with, which is another no-go. If you want to operate a privacy-first service you should at least make sure the basic formalities are met, and that includes naming who exactly is processing your data for which purposes.
It is a standard privacy policy generated by getterms.io.
We have no data on you. You can read about our security model here (https://safeapps.io/content/security) and walk through our source code here (https://github.com/safeapps-io). TL;DR: every bit of data you create within the product is encrypted in the browser. The server only sees a blob of encrypted bits, that's all. You can sign up without an email. But if you do, we use Sparkpost for sending emails, which is a EU-based ISP. We do not have any third-party scripts or cookies across all the site at all. No Google Analytics, no Facebook Pixel, no Intercom support chat. We use German hosting and I'm personally from Russia.
So no, we do not violate GDPR (but we do violate Russian laws because we do not have any servers in Russia). And we do take privacy seriously.
About the moderation: it's just like the nightmare with YouTube and Content ID.
False positives are better than false negatives when it's about scams and such. But, my God, tech giants just give people a way to sort this stuff out!
I think Google should be liable for scams on its network. They should either: 1. Figure out a way to better automate scam filtering, 2. Hire a massive number of people to review each ad, or 3. Downsize their business until they can manage it responsibly.
Google is not entitled to their scale. If they cannot responsibly run a business at its current size, they should be forced to downsize until they can.
I don't think it's about privacy though. I think Google have to deal with 100,000,000 ad customers. They have to have guidelines for PR reasons and they need to do all of this for fractions of a penny per impression. So they do it badly.
My photos are stored in Google Photos. My email is Gmail. My files are in Drive. I use Google Fi for mobile. My map use and my phone location are in Google's servers. Google controls for all intents and purposes Android, and the Play Store. I use Google Docs. I use Duck Duck Go, but also Google Search. I could go on. Google analytics is installed on nearly ever web site. Google controls the premiere ad network, and the most popular web browser in the world. But let's not forget their Chrome OS. All of that is being leveraged, not just its liddle search engine.
Break them up. Into many tiny pieces. Dozens even.
This is the core issue under a lot of big tech complaints. The same basic logic applies to fake news on social media, counterfeit products on amazon, even scam calls on land line networks.
I would like to see a lot less of this "moderation". But that means people have to accept there might be more ads for scams or gambling or alcohol. Instead they want more moderation. And that means more expense AND more mistakes and unresponsive mega corps.
I had to reread it a few times to realize that’s not what is meant.
- can't do business because one business says no? ==> too big, break them up.
- too big to give small businesses the time of day, or straight answers? ==> too big, break them up.
If such a company refuses their services to somebody who is compliant with every single of their publicly shared rule, it's an abuse of their power. And an anti-trust issue.
But I didn't offer to break them up. The real solution to this problem, I think, would be to create a transparent process for moderation. That is what the article is about.
Unfortunately, regulators get captured, and regulations often present barriers to entry. The process by which you might get a reprieve or compensation for your loss of business might still cost you your business, in legal fees, or in opportunity costs. Monopolies and oligopolies are the problem, and the solution is to break them up.
I don't think I am alone.
What we are seeing here is just one result of the Internet being dominated by a small handful of companies. Ad networks, social media, app stores, search ranks... it all stems from the same root cause.