I'm looking into what's happening with this email. We definitely did not decide to re-email people invited a long time ago as a growth tactic. That would be shitty. I think the email is a reminder that's supposed to be sent a few times after someone is invited. I'll update when I know what's happening.
OK, here's what I think happened here. The email above was to a user who applied directly to a company, and that company give them a Triplebyte test (a feature we call screen). This was represented in our system as a separate account. This separate account should absolutely have been deleted when you deleted your account. But it looks like our deletion code was not doing that. Fix is going out now. We're also pulling server logs to see if we can find any other accounts in this state.
This is an important point, and it's something I'm thinking a lot about right now. I don't have an answer, but I want to talk to my team and make an announcement in the next few weeks.
Yeah, I think that's certainly part of it. I'll try to be more careful with sprints going forward. But I made the initial plan for the opt-out release before the deadline. So it was also just a pretty bad loss of perspective on my part.
We want to do something more concrete to guarantee user privacy going forward. A technical solution would be best. But short of that just a really strong, transparent commitment (that makes it easy to hold our feet to the fire if we screw it up again). But I could not get this together before the email today. I'm expecting to announce something in the next few weeks. I agree with people here when they say that actions are what really matter. I screwed up enough that I don't certainly don't think an apology alone makes it better.
I was clueless. The posts I made Friday night were what I thought at the time (which was badly wrong). I was still focused on what I'd been thinking while we were developing the feature (still trying to make it "work"). What it took was a bunch of friends and mentors reaching out Saturday morning (and basically telling me I'd made a big mistake and betrayed the trust of our users). I wish I'd been able to understand this sooner based on the original HN thread. But it took me some time.
PR to pull the visibility toggle from prod is under review. Much of the eng team is out for the long weekend, and we may not merge until tomorrow. However, the public profiles themselves are not in production and we are canceling the feature.
OK, I just spoke to my co-founder. The functionally was changed yesterday, but the copy was not updated on the confirmation email. The copy will be updated in a few minutes.
We do not have a Chief Privacy Officer or Chief Information Security Officer. The issue was raised by our head of product and I dismissed it. I saw it as a minor concern (I'm ashamed to say).
We're working on a post-mortem internally right now. The thing I want to do externally is make a more clear/binding commitment to user privacy. The idea is still a bit inchoate, but I want to do something that makes this not just about trusting us.
We're under a lot of pressure because of the COVID crisis. We did have layoffs, but we're not in immediate danger of going out of business. The pubic profiles were set to go live next week, but this is now not happening. No data has been accessed externally.
Yeah... we made this better yesterday (removed the delay and the request for ID). It was totally a dark pattern. We built the initial deletion process right after GDPR passed. We were thinking about it mostly from a legal perspective then, and had not reviewed it since.
I'd say it was both. I wanted to move against LinkedIn profiles, I thought that opt-out was the way to get critical mass, and I screwed up and did not realize how large a privacy violation this was.
We are thinking about how we can make a stronger (and specific) privacy guarantee so it's not just a matter of our future intentions. I had a long conversation with my co-founder about this yesterday. We did not get anything together in time to include it in this email. But we're planning to.
Yeah... that's a much better idea. I can tell you what was going through my head on Friday (I'm not at all trying to defend this now). Basically, it was that for a credential to carry weight with recruiters, it needs scale. There's a bootstrapping problem. But that's not an excuse for violating people's privacy. Opt-in would have been a far better idea.
My head was still in the place it was when we were developing the feature. I thought it was a communication problem (if I could only communicate how this feature could help a lot of people everyone would understand). Perhaps I'm just slow. But it took some time and repetition for the magnitude of my error to sink in and me to really hear what people were saying.
The Friday announcement was a result of us pushing to get the profile toggle feature out that the email linked to, and shipping late. Not something I'm proud of (either from an eng management perspective, or, more importantly, from a not violating the trust of our users perspective). It was a rushed schedule. In hindsight I see that the timing of the Friday announcement is ALSO a problem.
Your Triplebyte profile will NOT contain any data/details about you or your job search that will undermine you at your current employer. We should have included a screenshot and more details in the email. I'll talk to my team about following up with more details tomorrow. We are talking about a lightweight profile, like your Stack Overflow or HN profile, to provide us the canvas to release badges. That's it.
Well, sorry that you feel this way. I don't agree right now (clearly). But I'll certainly take this seriously and think more about it/listen to feedback. We're talking about relatively basic profiles, to give us the canvas to launch public achievement badges (that we hope allow us to better help people who don't have traditional credentials). My view, building this, is that we're not displaying anything more private than hundreds of other companies. Stack Overflow has public profiles. Hacker Rank has public profile. AngelList has public profiles. Even HN has public profiles. We are launching public profiles for a product that has not had them in the past, and I get that that's a more sensitive thing to do. What we've focused on to keep that from harming anyone is what data we include in the profiles. I wish we'd include more details about that in the email.
We're not making anyone's job search details pubic. All that the profile will show is that an engineer created a Triplebyte profile at some point in the past, and any badges they earned.
We plan to add more engineering-specific sections to the profiles. I think there's a lot of room to just display what matters to engineers/eng hiring managers better. Then we want to use the profiles to push the industry to look beyond traditional credentials (school, work at top companies). Recruiters say that they want to do this, but we need to get them off of LinkedIn where everything is designed around the traditional credentials.
Really sorry that you think this is awful. Certainly do opt-out. I think that taking on LinkedIn and creating a better engineering resume is a good thing to do. I can assure you that the Friday announcement is a result of our team grinding to hit a planned release week, not anything other than that (I would have loved to get this out earlier in the week)