Summary: DropBox now scans the contents of your private documents to train A.I., shares your data with tech giants like OpenAI and Google, records all browser activity of Dash application users, and has humans manually reviewing data.
In my opinion, it is no longer suitable for private or confidential data of any kind.
Key quotes:
We may build models that identify keywords and topics from a given document. These models may be trained on your documents and metadata
We may review which of a given set of search results you click on [...] This can be done manually by Dropbox employee, or as part of a machine learning model
If you use Dash Answers, we may manually review questions you ask and the responses you receive.
When you use Dropbox Dash, Dropbox will import your browser history, starting with the previous 90 days, [...] The data collected includes the URLs of websites you have visited, as well as the contents of those websites (including page titles, images, and page content). [...] we may share your data with trusted third parties
In order to provide, improve, protect, and promote our Services, Dropbox shares your personal information with trusted third parties [...] Trusted third parties include:
- Amazon Web Services, Inc.
- CloudConvert (Lunaweb, Inc.)
- Concord Technologies Corporation
- ElasticSearch
- FileStack
- FullContact
- Google LLC
- IDnow GmbH
- Intercom, Inc.
- Mailgun Technologies, Inc.
- MaxMind
- Metrics Enterprises, Inc. (Kissmetrics)
- NG Communications bvba
- OpenAI, Inc.
- Oracle America Inc.
- Salesforce.com, LLC
- Stripe
- Teleperformance A.E.
- Twilio, Inc.
- Voxbone, S.A.
- Zendesk, Inc.
- Zoom Video Communications, Inc.
Dropbox has collected and disclosed the categories described [below] to trusted third parties in the preceding 12 months:
your real name, alias, unique personal identifier, or online identifier, and it could also include other personal information like your postal address, Internet Protocol address, email address, account name, profile picture or other similar identifiers
what you decide to store in your Dropbox account
identifying information about contacts that you’ve chosen to give us access to. It can also include identifiers such as a real name, alias, or email address
information relating to your use of the Services
device-specific information, such as an online identifier or Internet Protocol address, or geolocation data
14 Comments
davidgro@lemmy.world · 17 pts · 2d
Really it never was. No centralized service is.
I've even had Mega block my own access to files I uploaded (and didn't share) when it deems them to be copyright infringement, and files there are supposedly encrypted.
stoy@lemmy.zip · 10 pts · 2d
Yeah, I have allways been suspicious of major companies that pretend to not be able to access the data you store on the servers.
This is also why I don't understand why so many companies are abandoning on-prem infrastructure in favour of Microsoft 365.
Sure, it may be cheaper and leaner for companies to just use 365, but you give up control and any real crisis options.
OneDrive does have it's advantages, but it is just so damn annoying to troubleshoot.
I absolutely prefer the old normal network drive approach.
Whostosay@sh.itjust.works · 1 pts · 1d
Onedrive is a steaming pile of shit.
Zarobi@aussie.zone · 2 pts · 2d
Surely a centralised service like Proton Drive which is zero access encrypted would be a good alternative, right? There's a difference between "encrypted (but we also have a spare key)" and "encrypted (not even we can access it)"
Zikeji@programming.dev · 5 pts · 2d
To be fair, a centralized service with your own layer of encryption on top is an option. Like Borg supports that. Not a real option for miscellaneous small file sharing or organization though, but there may be an OSS solution to that.
davidgro@lemmy.world · 3 pts · 2d
True, the old passworded zip or rar was along those lines, Something modern might do the job. Just make sure the filenames are random also.
davidgro@lemmy.world · 2 pts · 2d
I don't know enough about that one to say, but if it's properly E2E than yes. But even then there's still the possibility that metadata might not be encrypted and the user could get banned for filenames, etc.
unicornrust@piefed.blahaj.zone · 5 pts · 2d
thank you for this summary. i was going to delete dropbox anyway but this was the kick in the ass i needed
Zarobi@aussie.zone · 3 pts · 2d
Same here… what prompted this research was an event that caused me some anxiety. I searched the keywords "sunshine" to find the song "walking on sunshine". I noticed it came up with health document PDF results and even photos containing sunbeams. I'm like wait… how did it find those files?! I was horrified and went to check their privacy policy, only to become even more horrified lol
I've been dragging my feet migrating out of Dropbox but now I need to get out ASAP. Really lit a fire under me. 10 year paying customer btw
eleijeep@piefed.social · 5 pts · 2d
It would be a shame if people started using Dropbox to store their lemonparty photographs.
jobbies@lemmy.zip · 2 pts · 4h
You guys are still using Dropbox?
artyom@piefed.social · 1 pts · 2d
Yeah I mean I would simply assume as much about literally any modern corporate product. Because 99% of them are and have been doing this for a long time. And no one cares.
Zarobi@aussie.zone · 8 pts · 2d
I care 💖
artyom@piefed.social · 1 pts · 2d
I was being hyperbolic, clearly.