Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cooperation to get anonymized user data as app developer #2657

Open
1 task done
christianlupus opened this issue Nov 7, 2022 · 2 comments
Open
1 task done

Cooperation to get anonymized user data as app developer #2657

christianlupus opened this issue Nov 7, 2022 · 2 comments

Comments

@christianlupus
Copy link

christianlupus commented Nov 7, 2022

⚠️ This issue respects the following points: ⚠️

Hello,

I am an app developer (of the cookbook app) and I recently opened this discussion on the forum. The idea was to provide a central domain for all app developers as a starting point. One could create sub-domains for each app to be used for documentation and other, more app-specific tasks.

One such issue was my request to have the option to collect some statistics on the installed versions. This triggered a significant push-back by some users that fear that their data is leaked out. They fear that the valuable name of Nextcloud as independent and not collecting any personal data might be at stake.

I personally think this is not too critical as I would like to collect only anonymized data and any app can do so once installed. It is just a matter of willingness.

Long story short: I would like to get the opinion on this by some other devs that might have their own agenda and pain points. Maybe this could be useful for you as well.

I will post this in a few repos in order to trigger a bit of honest discussion about the pros and cons.
Christian

@dartcafe
Copy link
Collaborator

dartcafe commented Nov 28, 2022

Hey @christianlupus

Although I am interested in telemetrics data, it is difficult to make sure keeping the responsability for the privacy. At least when it comes to GDPR.

Who watches about applying privacy rules?
Where is the data stored?
Who is responsible for data protection and security?
Who guarantees transparancy about the collected data?
How can a user/admin be sure, there is no illegal storage of private data?

I see two options to realize that:

  • Use the Nextcloud org to be able to collect data in a centralized way or
  • foundig a new organization for Nc developers and collect the data an provide it in a privacy compatible way to the members.

And at last, where does the needed money come from? I.e. for infrastructure, security, organisation, ...

@christianlupus
Copy link
Author

Hello, @dartcafe.

I wrote already a few times, that the original request was aiming at proving a community domain for the app devs. So, each app could have its own subdomain where the devs could "do as they like". There were various ideas flying around like a link to the app store, some documentation, additional material, etc.

I confirm that it was best to be hosted by the NC GmbH or a community club/association/... There is also some financial aspect in this as well, I have to admit. The domain is only a dozen bucks in the year, so this is no big issue. I, personally speaking, would not provide web storage or similar to the devs. Just the domain to have everything in one location and with an option to give it some official touch.


One problem that might come up with such a solution is for sure the issue of privacy and telemetric data. This is just one aspect of how the domain could be used in general.

One has to realize that without the domain this is possible exactly the same way. The main difference is that no common domain is in use. The rest ..., well, you get it. So, the domain in itself is no significant difference in terms of GDPR or privacy. Only the devs decide on what might be done with private data.

Having a central data collection might be one approach. This was suggested in the forum post as well. Currently, this is a low priority for NC GmbH. Eventually, there is a community effort coming up but, well, I do not see it right now.


To sum up a bit: I am open-minded wrt to telemetric data collection. I see its benefits as well as its drawbacks. I have been able to manage the cookbook app so far and it will eventually continue to work that way. So, no hard feelings there.

Regarding the domain, I would like to know how to proceed from here. I registered a domain yet to prevent it from being registered by other persons/organizations. I would be willing to spend the 12 bucks a year as a contribution to the community but only if the domain was usable in general. So far everyone was fearing the GDPR issues involved. Otherwise, I will have to cancel the domain registration and let every developer do their own business.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants