Dropbox telemetry can't be disabled
dropboxforum.com
dropboxforum.com
<begin rant>I see Dropbox as one of the biggest failures of the VC model. If only they had been bootstrapped, they would probably have stuck with their initial sync offering: A perfectly executed solution to a problem everybody has. And a small team could have made a good living here -- even with reasonably priced non-free options. Instead I imagine some VC partner convinced them to "grow their market" (or maybe "prepare for cloud"), and now they are descending into irrelevance. <end rant>
Who doesn't want free storage? No one, that's who.
See also: everything from Sourceforge to Docker Hub. Very few can complete the transition into a paid service.
The important distinction is whether you sell a product or a service. Dropbox is clearly a service, but it's easy to envision a product instead.
Had the user paid for storage up front, the product would be incentivized to support multiple backends to be able to compete on cost. But it doesn't, because it is the storage service that is the actual thing being sold.
Why would I upload my data for you to hold for free if history shows you are going to be gone in 6 months?
So to answer your question "Who doesn't want free storage?", everyone who's been burned before, that's who.
Honestly, the best way I found to prevent sync errors is to make sure there's continuity...that there's always some computer, somewhere, that's running and knows what the latest version actually is.
I see that as a huge plus for Syncthing.
That's a valid point though, I hope somebody contributes a Windows GUI at some point.
> Plus, you can use it as a portable disk. No "content protection". Yay!
good times
(For anyone wondering the parent is channeling https://news.ycombinator.com/item?id=8863)
Your immutable daily snapshots would be mounted in your local file system in:
(Mount point)/.zfs/snapshot
… and even Mallory can’t alter them since they are read-only.
I've also never had problems with CPU usage (Dropbox often caused high CPU usage in some cases)
The only downside is that background sync on iOS with Möbius Sync doesn't work reliably, but I think that is mainly because of how Apple cripples background processing. It does sync quickly if you manually start the app.
It's a bit challenging for new users (you need to understand machine keys, folder identifiers, ignore lists), but once it's set up it just works.
I always thought this as one of the bigger value-adds of Dropbox; easy cross user management and sharing.
Sync thing is relatively easy for the average HN user.
Dropbox is relatively easy for the average non-HN user.
Neither are hard, but Syncthing requires some background understanding of computers
Sure, they make it as easy as possible to get started, but "easy to use" for first time users does not mean "easy to use" for people who are willing to spend a few hours to read the docs.
Do you expect all developers to give away their apps for free?
I happily paid for it and use it to this day.
The only people who complain about it are those who think "open source" = "I get everything for free".
But here's the beauty of Open Source: anyone can download the source code and try to get it running on iOS.
Now Möbius found a way to get SyncThing kinda working on iOS, and for a small fee you can install it on your iPhone. The wrapper they built around SyncThing isn't open source, but for Möbius customers that doesn't really matter. They just want something that works. And through the beauty of Open Source, someone was able to build it for them, and they get to make a little money with it!
I'm not sure what this has to do with open source, however. These people aren't even part of the free software community, as they obviously don't care about software freedom.
Copyleft is a great thing, but it's also fine for things to be open source and not copyleft.
I can use syncthing because of Mobius. If Mobius did not exist, I would either have to pay a bounty to get someone to port Syncthing or use something else. That bounty is more than $6.
You can still port syncthing yourself. Mobius is not stopping you! You'll have to pay Apple $99 a year, and you will have to handle the app store process, and all - but you can do it. Neither syncthing nor Mobius will stop you.
I release all my software into the public domain; it's not copyleft at all, but it is free software, and it does respect the freedoms of the user.
Why don't you make a free iOS version of SyncThing? There's a lot of people out there who would appreciate it.
This is also one of the reasons I can't pay for IAP cancer - attaching payment methods links identity to the Apple ID and hardware serial number.
I also have Syncthing installed on my home server which gets backed up. So I have a copy of all my files backed up there, in the event a laptop goes missing or dies.
The only use case I haven't yet covered is an off-site backup of my Syncthing folder, which would be sensible. I just don't know who I can trust with it.
Syncthing is designed as a sync solution but not explicitly for backups. You need some extra setup on top of the defaults for building a reliable backup solution.
If not setup correctly, any "mistakes" from one of the devices will automatically be synced to other devices and cannot be retrieved back.
In the case of a lost/stolen device, make sure you remove the device as soon as possible. If not a bad actor now possessing the device can delete and sync that back to your "back-up" devices too.
I have a Pi with software RAID and two HDDs running Syncthing in my apartment. I rent a cheap Storage VPS from time4vps.com which is untrusted and set as an introducer--meaning, the data is encrypted before it reaches the VPS, and as an introducer it will announce devices to one another. My (former) laptop and an iMac where I do all my work are always in sync. If I need to add a new device, I only have to connect it to the VPS and suddenly all the other devices know of it.
Edit: I should further qualify that I'm not interested in solutions that would lock me into Apple's walled garden or anybody else's.
Edit: they're using the older unity logo for their "disk" column. That doesn't inspire confidence in their legitimacy.
However, the machine is absolutely slow. It usually takes a few seconds before SSH brings me to a shell prompt. Web apps I have running on it (basically just Gitea and Vikunja at the moment) can take upwards of 10 seconds to render pages, and it's just me using it. If you just want a storage host, they're fine. Running your website off it? I would probably not recommend.
Reliability, I have not had any issues so far, but I'm hardly a power user. My own personal anecdote is that my backups get validated monthly and, so far, have not had any issues.
I would probably agree that these machines alone would not suffice to make a good Dropbox alternative if what you're storing there isn't backed up elsewhere. I would recommend supplementing with off-site backups to B2 at the very least.
They won't let you sign up from a VPN. That's annoying but it doesn't affect me. Maybe they're trying to prevent Russian bots from signing up or something. Fine.
But after I gave them a valid credit card and billing address, they still won't take my money. Here's their support response:
"Your IP address does not match with the location you have provided. In order to accept your order your IP address must match the actual location from where you are placing the order."
Ohh kaay. I'm traveling at the moment in a different US state from my billing address. I'm not in Mongolia. And even when I'm at my billing address, my main ISP is Starlink, whose primary ground stations for me are also in a different state than I'm in. So I routinely see banner ads on websites for stores that are 500 miles away.
It's par for the course for non-technical companies to assume that IP geolocation is in any way accurate. But a cloud VPS company should know better.
Fail.
Although requested by many users throughout the years, the maintainers never considered it seriously.
This is also just very outside Syncthing's functionality.
You still have to manually create the URL first. You don't need to worry about accidentally having everything exposed because the feature is enabled.
> This is also just very outside Syncthing's functionality.
The context was specifically "as a Dropbox replacement".
I sometimes use croc to do one time file sending.
I confess I have never used it. I still rely on USB sticks for a variety of tasks, more than simply transferring files. Anyway, for me, this telemetry nonsense would be one reason I would avoid Dropbox.
Maybe there will someday be telemetry in USB sticks. We'll see. Meanwhile...
No, it’s because it was useful and simple in a way that non-techies could and would set up and use. That’s why Dropbox got popular.
Though, I moved away from Dropbox long ago when they introduced device limits. One phone, one laptop and one triple booting desktop -> over the device limit already.
As a techie, I do this so that I can maintain control and trust, and so that when something goes wrong, I can fix it instead of just refreshing the status page of the service and hoping.
I in no way think that anyone else should do like me, but when people are having trouble with a service, I will mention options that involve not needing that service.
Keeping that running and reliable and operating it for years or decades sounds like an absolute nightmare and I'd suggest avoiding that at all costs.
But it's not. I run many such services for myself, and keeping them running and reliable hasn't been a large burden.
As an example.
I exclusively run hosted apps for email and chat at this point (Outlook/Gsuite/teams/slack/etc).
I use Plex for most of my personal media consumption.
When outlook/gsuite/teams/slack/etc stop working, I realize there's nothing I can do, lots of engineers are fixing it and I move on to some other task.
When Plex stops working, it doesn't come back online until I do something.
Maybe it's just restarting it's container, maybe some update broke something and I need to downgrade, maybe the spinning bit of slowly rusting metal in my basement failed and I'm going to spend the next week fighting with mdadm because the raid rebuild goes poorly. It happens. If you're self-hosting, even if you want to claim to be perfect at deploying/running software and even if you think you can constantly upgrade things without any issue or even if you think you can leave things running on old software forever, something will eventually break. Probably software at times, definitely hardware will break.
Do you see fixing and troubleshooting these kinds of issues as a burden, or a large one? That's the question.
At this point in my life I do. If not for the cost, I'd run absolutely everything on the cloud.
The amount of free time I spend with computers is not infinite and I'd prefer to spend it doing fun new things rather than troubleshooting for the 30th time why some random ISP I was trying to send mail to is blocking my home mail server. Been there, done that, burned the t-shirt out of frustration.
If you use a 3rd party service they'll handle that too.
It's not the initial setup that's the problem.
Yes, but that's not technically difficult or time-consuming.
> a plan for disaster recovery to match what an external service can offer.
I'm not sure what you really mean by this. Isn't that what the backups are for?
> Yes, but that's not technically difficult or time-consuming.
Yes, you just pay for some server space on a cloud service... oh wait...
The point is all this trivial to do stuff just adds up, and sometimes it does make sense to use a 3rd party.
Your pain threshold may just be larger than mine.
Which is far from the only solution. I have automated off-site backups without involving the cloud.
> sometimes it does make sense to use a 3rd party.
Of course. I'm not arguing otherwise.
> Your pain threshold may just be larger than mine.
Perhaps, but I suffer very nearly zero pain on this. I probably spend a couple hours a month maintaining my systems on overage.
I consider dumb storage for encrypted data to still be sufficiently under my control.
At the time dropbox launched, there wasn't anything this convenient.
Of course you can use whatever you want.
Phew boy. You really should try dropbox or a competing service.*
Picture this:
1. Double click a file 2. Type some words 3. Save the file
That's it. There is no step 4. Your file is now synced to all your other computers and to any colleagues who also need that file.
Seriously you shouldn't be using USB sticks these days. Also - I'm guessing you haven't started the transition to USB-C yet? USB sticks are going to get really painful when you do.
(* I use a competing service - more than one actually, but I have used dropbox in the past and it worked well. I just didn't like the direction the company was taking it. This story is yet another example of that)
Why not? You say that like there's a problem beyond not caring if there's a more convenient option.
Shit, not more painful than nearly everything else. You're gonna need a USB-A/C hub anyway, unless you only use very new equipment and you've gone out of your way (and, not infrequently, spent more money) to make sure you get C instead of A versions of everything—lots of A devices still being sold.
If not for current-generation console video game controllers, I'd still have almost nothing in my house that natively uses C, aside from Macbooks and one newish iPad.
(However, I am, like you, a tad scandalized at the notion of favoring flash drives over network sync of some sort—I'm a luddite in a lot of ways, but god do I not miss losing flash drives, having them mysteriously fail in 6-24 months of light use [even the good brands! If anything, that part's worse now than it used to be], the "whoops, forgot to copy the file", not being able to have any of the stuff unless you physically have it with you, "let me just print this from my phone—oh, right, I don't have an adapter to plug a USB stick into it", et c. A bunch of extra stress and fiddling, to gain... ???)
Those USB sticks that are A on one end, C on the other are excellent. They are also great fidget toys.
https://www.rubbermonkey.co.nz/SanDisk-128GB-Ultra-Dual-Driv...
Suddenly I have ripped myself out of a lot of stationary storage space, and access to a lot of files in the process. Moreover, this change was also compounded by lifestyle changes, which reduced my computer time at evenings a lot.
Then, I realized that I used these files a lot, and I needed them where I am, regardless of the device I have with me. After that, I understood what Dropbox is about. I have all my files, everywhere I need, anytime I need.
Moreover, many of the bookstores and merchants deliver things I buy directly into my Dropbox. That's great. Even updates to these items arrive automatically.
I backup the whole thing weekly via rclone to a disk, and I'm happy.
There was this "Dropbox" folder in your home folder, and anything put in there would show up in the home folder on your other computer or operating system or eventually even your phone. I also knew about Apple File Sharing and it was basically that but much more intuitive and worked on separate networks and on Windows (maybe Dropbox was inspired by AFS and the write-only "Drop Box"). Drop Box just worked, and to less tech-savvy younger me that was the only thing that mattered.
Now we have 300+ other programs which can do the same thing, and I use Git/Github for syncing and woof/AirDrop for individual files, so no Dropbox for me. And probably not for most technical users either.
But the average non tech-savvy user still needs a cross-platform service which "just works". And I'm sure their are alternatives which also "just work", but Dropbox is popular, and they don't care about the telemetry.
Do you use it for images, too? Maybe using a large file extension. Dropbox syncs around 2TB of random files successfully, and it seems like that is not something git it very good at (judging by game developers using Perforce or others to share files).
I am always open for recommendations to replace Dropbox. Even Gdrive (one of the most obvious alternatives) choked on performing the initial sync (of 2TB) last time I tried.
It is my main tool to manage things that aren't code, and I give myself the ability to go back to older files or undelete things in a KISS manner by having multiple rsync destinations that are used in rotation.
I’m surprised dropbox handles those well. Unless things changed the free tier still has a <1TB storage limit. But it goes to show much it “just works”
I say *was because I cannot speak for how it is now, I do not have any data to judge how it is now.
I stopped using it a long time ago – not because I disliked it, I just picked a different solution.
I have had experiences where putting in a USB stick automatically installs malware on the computer.
Do you trust that the USB "power port" is just power and not a host?
Regarding rogue host devices (not just a power port): I agree 100%, these are dangerous. Luckily a typical USB port on a Windows computer can only interact with client devices, not host devices, as far as I'm aware. The inverse of OTG doesn't seem like it would exist.
USB has capability to launch any arbitrary code that the user itself could without inputting any secret.
On anything that isn't the best protected Linux GUI (better protected than the configurations that everybody use), this is enough to install a keylogger on your environment and sniff any secret that it's lacking (but root/administrator rights are overrated anyway).
There has been some work on restricting USB so that it can't initiate anything. But that brings extreme usability problems, so it's very rare for people to do it in practice.
Yes, because it's my USB stick.
> Do you trust that the USB "power port" is just power and not a host?
Not if it's not my hardware. In that case, I use a data blocking dongle. Always practice safe Software EXchange.
I mean Dropbox has the contents of my files should I find it creepy or unnecessary that they know my RAM amount or what the last exception was?
- Is the service running locally?
- Do we trust/expect that the data is not used for marketing (i.e. would the user have complained if the domain was "error-reporting.dropbox.com")?
- Is the data anonymous (think twice, everyone who has IPs or user IDs in request logs)
- Did we agree to relevant ToS or privacy policies?
If we think carefully about this, I'd bet that most people here have used or even implemented some form of logging that has privacy problems.
TIL it is possible from the command line, so perhaps I can make it work with Automator.
It seems like all chat, conference, and collaboration software must devolve into bloated slow buggy trash over time.
The first comment in thread is from 2020, the last - from 2021. Now where I live is 2023.
I don't have any relationship with Dropbox, but we should be precise that this information might be outdated.
How Dropbox Hacks Your Mac (1037 points on Sept 9, 2016, 423 comments): https://news.ycombinator.com/item?id=12463338
Revealing Dropbox’s dirty little security hack: https://applehelpwriter.com/2016/07/28/revealing-dropboxs-di...
Dropbox Lied to Users About Data Security: https://www.wired.com/2011/05/dropbox-ftc/
However, their approach to Android is absolutely ridiculous. There is no files or folders synchronization - at least not at the OS level, like in Windows or Linux. If I need to access my Dropbox files on an Android device, the only way is to do it via the Dropbox app, and it is clunky. The biggest pain point is that I cannot use 3rd party apps to open a folder in my Dropbox storage - I can open a single file, fine, but for example Obsidian is out of reach as it requires opening an entire folder, which is currently not possible.
(I can create an offline copy of the folder on the device and open that one but it defies the purpose of having a sophisticated synchronization software).
So I think at some point I will start investigating alternatives.
Nope, it was an ad for using Dropbox to scan my tax documents or some shit like that.
I contacted support to ask about disabling future fake notifications, and they tried to claim that malware could be responsible.
I suppose in a way, they're not wrong...
There's a market here. Idk how big. Apple seems to think there's a market here too. If they offered larger sizes I might be tempted to go all in on Apple.
It’s a good way to give back, and improve software that is often free. It’s presumably anonymized and safe. I don’t think we should be adversarial.
I’ve been migrating things over to Synology Drive hosted in my closet, and the UX for this is a lot like Dropbox (in a good way).
Combined with Tailscale, I get all of the convenience without the ick, and a hell of a lot more storage for that matter.
People tend to think that "Tech Independence" [1] and "The Cloud" are at odds with each other. But, end-to-end encrypted services that sync via the cloud really are the best of both worlds - convenient and secure.
(Of course that doesn’t solve the telemetry issue.)
Addition:
I also hate apps and gadgets using "clouds" for jobs which can perfectly be done locally.
E.g. I want a vitals tracking device to record my heart and sleep data but I am not buying any because they send that data to their servers, I want them to only send it to my PC where I would do the data science myself (and/or to my smartphone to a purely local app). I would pay a lot (up to e.g. what a beefiest new MacBook costs) for such a device if it were purely local and well-made (wouldn't break soon).
I also want a vacuum robot which would build and use my apartment map without sending it to any cloud but there are no such models no matter how much I am willing to pay (I know a solution[1] for vacuum robots - some can be hacked to run the server part on themselves but I don't really have time for this). And there have recently been a leak of pictures made by vacuum robots which proves my paranoia is legitimate.
Some genius has even invented a WC which analyzes your pee and stores your hormonal changes log in their cloud which is a great gift to conservative maniacs (I don't mean all conservatives are maniacs, some are awesome, there are many flavours of conservatism) which have just banned abortions and can now subpoena the company to find out you if you have secretly undergone an abortion in another state.
Surely insurance companies and banks will also find a way to get your data and make your insurance and loans prohibitively expensive as soon as they find some clues you might have health risks.
I am almost sure the problem of privacy negligence, every serious actor spying on people hoarding data, is going to become more and more serious up to a catastrophic point and hope it will get more and more attention soon.
I used to be called a paranoid loon by fellow students for covering my laptop camera a decade ago, now almost everybody does this and my new laptops (HP EliteBook and ProBook) even came with built-in curtains on the cams.
Like, there's a crash reported by a user. That's already rare in itself, and average report quality from non technical users varies from nearly useless to misleading. What are you gonna do, ask them where it happened and what they were doing, to guess where in your related code something went wrong?
By the way, although I don't want to participate in involuntary and non-transparent automatic error reporting, I find your response logically beautiful. "One step away" - a perfect and reasonable description for this.
I personally abandoned Dropbox when they introduced a limit on the amount of devices you could use for free plans, and the cheapest plan was like 120€/year for 2 TB.
Back when I decided which cloud storage to use, all the big ones were at 1TB and dorpbox was the most expensive with the least features, while microsofts offer included office 365 for nearly half the price.
Right now it seems: MS 6$/mo for 1TB + Office (https://www.microsoft.com/en-ww/microsoft-365/onedrive/compa...) Dropbox 10$/mo for 2TB (https://www.dropbox.com/plans) Google 12$/mo for 2TB+some smaller things like calls (https://workspace.google.com/pricing.html?utm_source=drivefo...)
There obviously are smaller companies offering storage too, which seems to be around 4~5$/(mo and TB), eg https://www.pcloud.com/cloud-storage-pricing-plans.html?peri... https://icedrive.net/plans https://www.sync.com/pricing-individual/
Overall I'd say its not a terrible offer after the increase to 2TB, but on the expensive side compared to competitors.
Imagine if someone offered you gasoline for 50 cents a gallon, delivered directly to your car, but for personal use only and the minimum contract is 400 gallons a week.
iDrive is the only alternative I found that more or less works the same. Maybe Google Drive too but I try to avoid them (maybe if there was an option bundled with Youtube Premium...)
When I tried MS OneDrive messed up the file dates, Amazon CloudDrive did the same (and also got shutdown since). And Apple iCloud is just too barebones and not really meant for sharing if someone is not using a Mac.
Yep but it's mostly because I have many things which integrate with it -- loads of IFTTT recipes, apps, and sites that automatically sync things for you. If iCloud had a public API that people could integrate with the same way, I'd probably drop Dropbox at some point.
https://www.brother-usa.com/brother-web-connect
Very convenient that Brother MFC machines can automatically upload OCR’d scans to your Dropbox/onedrive/box/google drive account, but I would like to only use iCloud Drive. Wonder if Apple is dropping the ball on that functionality though.
They definitely are but I can understand why they don't want to be bothered supporting something like that. Plus I think the time to be starting that was about a decade ago...
It's pretty neat, but that's all I use it for these days. Still have my original 2GB account from when Dropbox was new.
Recommendations very welcome!
Microsoft Windows.
It is about time something is done about it.
I don't see why people are getting so irked about this, without knowing any details of what data Dropbox is receiving.
Here's a list in French: https://wiki.chatons.org/doku.php/services/nextcloud
BTW I'm learning from it that /e/ [1] partners with Murena [2] which offers accounts with 1 GB of free storage. Apparently, Murena is French.
1TB bonus if you sign up, but haow good is their product?
The telemetry goes to telemetry.dropbox.com. You get this telemetry because you have installed the Dropbox desktop app, which means Dropbox already has lots of access to your machine. If this telemetry just went back mixed with normal Dropbox communications (like most apps), would people even be aware of it?
There doesn't seem to be any discussion of what the telemetry actually is, just annoyance it exists.
There is no explicit consent.
Too bad Dropbox does not see it that way.
It's a shame. I wish more engineers would see things through Richard Stallman's eyes, and realize that software is supposed to serve its users, not its creators. But, as the saying goes: "It is difficult to get a man to understand something, when his salary depends on his not understanding it."
Nonetheless, the potential is there and GDPR does consider it personal data from the point of view of consent, so dropbox is almost certainly violating the rules here even if they do not sell the data for advertising (as unlike the actual data they store, it is not necessary for providing the service, merely useful to the company for improving their service). Such telemetry almost certainly requires an opt-out, and most likely should be an opt-in as far as GDPR is concerned.
There was an opt-out telemetry proposal in Go [0], which caused a huge backlash. The proposal authors were so focused on the benefits of the telemetry, that they did their best to invent all kinds of very convincing arguments why their telemetry is okay, useful, not intrusive, etc. etc. They completely ignored the ethics of the problem - that they are not entitled to users' data without consent.
It took a very dramatic reaction from the community to convince them that adding opt-out telemetry without users' explicit consent is a bad idea, no matter how "non-intrusive" and "helpful" it is.
To bad they just start scanning everything in ~/Dropbox.
Also consent to store does not imply consent to read, process, make use of.
I distinctly recall a webcomic in the past few years lampooning cloud storage. There was a guy who said "hey, there's this guy down the street who lets me keep stuff on shelves in his garage." "What does he charge you?" "Nothing, he says it's just cool if I keep it there." and then the stuff is sold off or tampered with, the guy is irate, and the moral of the story is essentially "why did you trust a random guy with a garage to keep your stuff?"
It's okay for a free service to change how they operate with a take-it-or-leave-it offer. It is not okay for a free service to invade your privacy without permission.
Additionally, all users should be able to trust Dropbox just as much as the paying users.
There's no legal requirement for someone to be polite to a cashier at a supermarket, yet complaining when somebody is an asshole is still a valid complaint.
So yes there are two things: GDPR which is irrelevant here, and storage of non-PII which should be done transparently because it’s polite to be transparent, but not a regulatory requirement.
All the complaints are about them collecting PII. Even if they say they don't, the concern is that they could be lying, or change easily, and nobody would know.
The few exceptions that exist are only applicable in cases where there is no potentially identifiable data collected at all, which is obviously not the case here.
Here is a very accessible (although non-official) GDPR resource that I've come across: https://gdpr-info.eu/
Obligatory "I am not a lawyer" disclaimer :)
Not if the data isn't PII, no. Not in any way shape or form.
> The few exceptions that exist are only applicable in cases where there is no potentially identifiable data collected at all
The whole point of collecting "anonymous usage data" (which is what telemetry usually does) is that it shouldn't be possible to attribute to a physical person, and thus not be PII. As an extreme example, you could take the most typical form of telemetry: a feature usage count. When a feature is used, the telemetry collects a (+1) for that feature. The only long term stored data is the total count N for each feature across the entire user base. Of course there is no PII stored.
> which is obviously not the case here.
Why do you say that it's "obviously" not the case, when there is no indication about what data it is, other than the Dropbox representative saying precisely that there is no PII collected so the GDPR isn't relevant? There may be PII (in which case they are both at fault for not disclosing, and complete asshats for lying in the support forum). But it would be a pretty uninteresting discussion once one assumes that...
Obligatory "I'm not a lawyer either but I've implemented telemetry in software and had those implementations thuroughly analyzed by lawyers a couple of times"
The major differentiating factor here is that that Dropbox does in fact process PII - convenient storage and distribution of their customers digital life is their raison d'être, after all, it's precisely what those people expect of Dropbox and pay them their monthly fee for.
In this case, where telemetry is gathered by the same desktop application that is also a primary component of their legitimate and consented-to data processing activities no less, they would at minimum be required to specify what information goes where, how it is anonymised, and for what purpose they require it.
I'm not assuming ill intent or unsanctioned data mining activities or anything of the sort, but whatever it is that they are collecting and doing is not as clear as it should be.
It will send the IP regardless of whether telemetry is enabled. But they do claim that no PII is stored for telemetry. Whenever the topic of Telemetry comes up I try to keep to the discussion about properly anonymous telemetry, simply because that’s where there is any discussion at all. If anyone transmit or stores anything they aren’t entitled to it’s obviously always wrong so that’s not an interesting discussion.
Dropbox of course already stores PII (your files) but that doesn’t mean they can do so for other info or other purposes.
Whenever the topic of telemetry comes up, I try and point out that just because someone says it's just telemetry, it doesn't mean a damn thing. If anyone thinks it's not interesting because they think things are obviously always wrong, I ask them: what does telemetry mean to you? What does it mean to the company?
Are you sure those two definitions are in 100% agreement?
Similarly, they might have an opt out but not honor it (in the case of Dropbox it wouldn’t be noticeable)
So all those things aside, the interesting discussion is the discussion that assumes they are honest when they say they don’t store any PII in telemetry. That means, for example that the IP isn’t stored.
“Telemetry” as a term means nothing about what’s stored which is why I try to be specific and talk about “anonymous usage statistics and crash reports” or similar. Telemetry without PII tends to be exactly that.
Main features I want is version history and easy recovery.