Personalization of what, exactly, if not ads? What's the proper distinction, in your view?
Personalization of what, exactly, if not ads? What's the proper distinction, in your view?
If I receive a travel reservation confirmation email, I receive a calendar reminder on my phone a few days before the trip.
This is personalization. But years ago Google made a commitment not to use Gmail data to customize ads (after initially doing so). So there's a real difference between personalization data and ads data.
Closer to home for me, we are legally barred from using Fitbit data for ads or allowing any system (or person!) in the Ads organization to access it in any way. But nobody said we can't personalize your Fitbit experience based on data derived from, say, your Fitbit exercise history.
Oh! Well, I actually did not know this. You are saying they realized they shouldn't use my Gmail to customize what ads they show me; how can I verify you are right to say so?
>> So there's a real difference between personalization data and ads data.
I still don't see the distinction.
Unfortunately this goes against people's default (and incorrect) mental model of how Google operates, so it's been a very hard message to land.
Disclosure: Current Googler and I was a PM on Gmail at the time.
However I now get email from various people around the world with xlastname(at)gmail.com addresses. Apparently your email is not unique in the world, but only in your region, kind of (?!).
I get important emails (hotel bookings, insurance mails, trip reservations, orders, lawyer documents) from people which use xlastname(at)gmail.com in the USA, Canada, Australia, and Europe. All with similar names to me, obviously the surname is the same, but first name is different, just the same initial.
I've confirmed (by contacting some of them) that they are not missing out on any important documents. For some reason Google's system is duplicating emails meant for other people into my mailbox.
Only mails using x.lastname reaches MY inbox. If I tell someone I know to send a mail to xlastname I wont receive it, making the statement here...
https://support.google.com/mail/answer/10313
...false (for me).
I guess I'm God over all the non dotted versions of my email address. Thanks Google!
(However sometimes I wonder if other people see my emails as well)
No, it's globally unique. I worked on this system for years. When it looks up an email address, it first looks in a globally consistent database [1] for an email record keyed by "canonicalized" address, with dots stripped out, everything in lowercase, and certain letter/number combinations replaced that are too similar like '1'->'l'. So if you sign up with x.lastname(at)gmail.com, no one else in the world can have xlastname(at)gmail.com, x1astname(at)gmail.com, xl.astname(at)gmail.com, etc. Part of this record's value is the original email address with the 'l's and '1's how you chose them. If those don't match the query, the system returns not found, just as it would if there were no record for the canonicalized form.
> I've confirmed (by contacting some of them) that they are not missing out on any important documents. For some reason Google's system is duplicating emails meant for other people into my mailbox.
I'd be _shocked_ if that were true. It'd be a very serious privacy incident and is contrary to my understanding of the system. Far more likely it's what I've seen with my own email addresses. Someone else incorrectly writes your email address instead of theirs into some system. Usually you're the only person who gets the email, but they might send something to two addresses, or they could even set up a forwarding rule from an address they have to an address they incorrectly think they have. They may say they're not missing any important documents, but maybe they have the documents in another system and don't know they're supposed to have gotten an email copy also. Or maybe they don't know what they're missing and don't understand what you're saying. This group of people was not selected for tech savviness. They might have just made a typo once, or they might keep doing this because they don't understand email at all.
> Only mails using x.lastname reaches MY inbox. If I tell someone I know to send a mail to xlastname I wont receive it, making the statement here... https://support.google.com/mail/answer/10313 ...false (for me).
That's odd. You can write to support if this is a problem. Support tickets actually reach engineers when necessary (yes, even for free gmail.com users).
It seems vaguely possible given the age of your account that your email record state and the current code are inconsistent in some way, like the field that stores your email address with the 'l's and '1's in your preferred form actually having the dot when it's not supposed to or some such. If there is such an inconsistency, one of my former teammates will fix the code or the database state (running a cleanup that finds all affected records) so they're consistent.
Or maybe the xlastname ones are just ending up in your spam folder. /shruggie
[1] old but: http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.133...
> how can I verify you are right to say so?
I mean, you could say "how can I verify Google isn't using my Google password to decrypt my Chrome data and pipe it into Google Ads", but you'd have no way of verifying that, besides taking their word for it. https://variety.com/2017/digital/news/google-gmail-ads-email...
But, it's something we've also said legally:
https://support.google.com/googlecloud/answer/6056650#zippy=...
Is Google using my data? What for?
Google processes your data to fulfill our contractual obligation to deliver our services. Google’s customers own their data, not Google. The data that companies, schools, and students put into our systems is theirs. Google does not sell your data to third parties. Google offers our customers a detailed Data Processing Amendment that describes our commitment to protecting your data.EY, an independent auditor, has verified that our privacy practices and contractual commitments for Google Workspace and Google Workspace for Education comply with ISO/IEC 27018:2014. For example:
We do not use your data for advertising
The data that you entrust with us remains yours
We provide you with tools to delete and export your data
We are transparent about where your data is stored
You can get even more detailed in the DPA:
Customer instructs Google to process Customer Personal Data only in accordance with applicable law: (a) to provide the Services and TSS; (b) as further specified via Customer’s and End Users’ use of the Services (including the Admin Console and other functionality of the Services) and TSS; (c) as documented in the form of the applicable Agreement, including this Data Processing Amendment; and (d) as further documented in any other written instructions given by Customer and acknowledged by Google as constituting instructions for purposes of this Data Processing Amendment.
First line in your legal statement:
>> We do everything in our power to protect businesses, schools, and government organizations from attempts to compromise their data.
Where is the "me" in this equation?
https://policies.google.com/privacy#infocollect
"We don’t show you personalized ads based on your content from Drive, Gmail, or Photos."
and
https://support.google.com/mail/answer/6603
> When you open Gmail, you'll see ads that were selected to show you the most useful and relevant ads. The process of selecting and showing personalized ads in Gmail is fully automated. These ads are shown to you based on your online activity while you're signed into Google. We will not scan or read your Gmail messages to show you ads.
The FBI, NSA, CIA, and DoD have access to it, without a warrant (thanks to FISA 702), along with the entirety of the email corpus that produced it.
You can't do threat modeling if you don't accurately model the various threats. Everyone at Google could be completely trustworthy but there's still huge insider risk thanks to US spying.
If we are going to do "threat modeling", we should also talk about the risk of nation state actors penetrating Google, or compromising your browser and getting access to your gmail that way. Or an accidental bug that changes everyone's password to be 12345. Yes, or the federal government could subpoena it.
Lots of things could be true and possible, but none of them are relevant in a discussion that's about the _internally permitted use of data within google_.
I routinely dealt with situations where connecting workspace data with other teams, even with explicit opt-in from users, at best required building incredibly detailed data scrubbing and log redaction to ensure no user data persisted outside of the workspace systems, in case it might accidentally end up used for some non-workspace purpose. At worst it was simply not possible, or not worth the other teams time to build things to a standard that would satisfy legal and privacy.
For sure, it’s possible there is some secret system or accidental data exposure, as I said, can’t prove a negative. But I will freely confess that I was someone who was generally skeptical of Google’s approach to data handling and always believed Gmail data and everything else was mined for every purpose until I joined Workspace. Once I was inside and saw how carefully it was treated and how many rules there were around anything you do with user data even within the Workspace teams, I was honestly nonplussed. It made product development harder.
15 is not a prime number.
There is no elephant in your room right now.
Prove it.
Of course, as people living in the world we don’t necessarily need full proof to try and protect ourselves from the actions of an entity we don’t have full knowledge of. But saying “I don’t want to give google X data because of what they theoretically could do with it” is different rhetorically from saying “I believe that google is doing X with the data, and if you don’t prove otherwise it’s probably true.”
Whether a contract is formed when you register and agree to their terms would depend on locally applicable law. I don't recall stories that courts would have deemed registrations on the internet invalid in general. Certain terms in the aggreement definitely.
- Your "content" (data in Gmail, Docs, Photos, etc) won't be used for advertising. (Only for personalization, like the Gmail smart compose, asking Assistant about the status of your order, etc.) - Your "activity" (your searches, etc -- what you can see at https://myactivity.google.com/item roughly) can be used for advertising, though you can turn it off (see https://adssettings.google.com) or delete it. (IIUC, you have more granular privacy controls as a logged-in user as you can delete individual items….)
But luckily google provides us with a completely gdpr compliant opt-out for Google Analytics.
"Oh! Well, I actually did not know this. You are saying they realized they shouldn't use my Gmail to customize what ads they show me; how can I verify you are right to say so?"
and then my response:
"Googler here, who worked on Workspace (which gmail is a part of). Anyone who works in workspace could confirm that, it's something that is taken very seriously."
I'm not sure how I could have been more clear...
Out of the top of my head: NoScript, Trace [0], uBlock origin, Decentraleyes, Privacy badger.
As well as using a pi-hole.
[0] https://addons.mozilla.org/en-US/firefox/addon/absolutedoubl...
https://myaccount.google.com/permissions?continue=https://my...
And disable Google Account Sign In prompts
If you're watching YT and think you are not seeing ads, then you're being foiled.
>> So my data is being used, just for my benefit.
Apart from the word "just", I agree.
Actually running an ad blocker/paying for Premium means you aren't seeing ads, pushed by Google. Any creator might be showing you sponsorships/product placements of course, and Google has no say in that.
Yes
>> guiding you
Yes
>> based on your profile
Yes
>> based on all the data they have collected on you
Yes
>> in order to entice you to consume goods
Yes
My guess is very very few.