Figma defaults to train AI models on personal data
help.figma.com
help.figma.com
I'd love the governement to take a more powerfull stance against it, but they clearly aren't interested.
If small you and me want some privacy, you have to shield it from the internet, govs and bigcos: No more Microsoft, Google, Adobe, .... products.
[1] https://www.androidauthority.com/microsoft-ai-ceo-interview-...
Lots of issues come with privatized ML though:
- It's pretty close to impossible for a consumer to judge if the methods used are actually privacy preserving, or just lip service. It's just too technical.
- It's much harder to implement than non-private learning.
- Governments will likely not be able to regulate at the level of technical detail needed to allow privacy preserving, and not the non-private learning
- You complain about using the consumers CPU/electricity, but that's often very helpful for privacy. The private alternative is taking DP data off the device, in which need to collect a lot more data for same privacy levels.
Figma won’t begin training on content for accounts with the Content training toggle on until August 15, 2024.
Do you not want it to continue to get better?
Perhaps it's simply not feasible at the price point users are willing to pay?
1. Use fewer services. This limits the amount you have to read or worry about changes.
2. Of the services you use, limit the personal information you provide. Disposable emails and making up names and birthdates (when they are mandatory) all help. Only do this for services where you don’t care if your account is closed. Particularly impactful for those services which make it a pain to delete an account.
3. Don’t read the full TOS. They are legal documents organised in logical sections so skip the fluff and go to the ones you care about like the handling of your data. As you read more TOS, you’ll become better at detecting the patterns and won’t need more than a couple of minutes to read what’s important to you.
4. The Privacy Policy is often more important than the TOS, regarding what will truly affect you. Start with that.
5. Always open TOS and Privacy Policy links, even if you’re not going to read them. You might be surprised to find how many of them are broken links. That’s usually the sign of a shadier company that you should skip.
It should be illegal.
That would mean 600 TOS, which means you’re not following points 1 and 2. Furthermore, as soon as you find anything objectionable, you stop reading. After the first couple of them you don’t need 10 minutes.
> It should be illegal.
There have been instances of unenforceable TOS, and some countries are pushing for contracts to have mandatory summaries of each section. Find out about it in your country and see how you can help.
Could be nice way to fight back fire with fire
Because having seen what the state-of-the-art AI use is across the industry, that is what vast majority will be doing. Hell, Atlassian enabled their "AI magic" integration to all accounts recently and they send it all to OpenAI. Yes, I read through their terms. That detail was hidden behind three steps of discovery from their main AI use terms.
I hit the disagree button and “nothing” happened as in I could just play the game normally.
I sometimes wonder what that was about.
TOS should be illegal.
Imagine if you had to agree to ToS while entering at Cosco.
Or if you actually had to read 9hours of a legal doc to shop at wallmart.
Data created by the user - such as a youtube video, HN comment, or whatever you want to call Figma - is probably still a wild west. That's more about intellectual property than privacy. The ToS of pretty much every single platform has included a mandatory licensing clause for ages, giving them the rights to do pretty much everything they want to.
It is very important point and anybody who is working on something more innovative than few mockups for their next SaaS app is fuming from their ears.
Just to illustrate let's consider a scenario where we have a team of scientists working for a long period of time on a data structure which they have visualised in their Figma project.
Now let's say they forgot to turn the toggle off. In an instant all of their intellectual property earned through years of blood, sweat and tears is integrated into Figma's LLM. Just like that and without any attribution!!!
The GDPR is not actively enforced enough for compliance to be as widespread as it should be, especially by non-European companies but even by European companies. (I suspect that’s part of the reason lobbyists haven’t forced in more loopholes through legislative amendment; the EU and member-state politicians and regulators can look stronger on privacy than they are without actually severely impacting the corporate surveillance and advertising regimes.)