Exodus-Privacy / exodus

Platform to audit trackers used by Android application
https://reports.exodus-privacy.eu.org/
GNU Affero General Public License v3.0
624 stars 62 forks source link

Add recommendations for developers ? #229

Open pnu-s opened 4 years ago

pnu-s commented 4 years ago

Now that we have a page gathering some recommendations for end users, I'm wondering whether we should add on the same page some recommendations for application developers (such as limiting the number of permissions and trackers to the minimum required, use self-hosted and open source solution when possible, use exodus-standalone before uploading a new version, etc.)

Any comment is welcome :)

Gu1nness commented 4 years ago

Good idea. If so, we might need to update a little bit the documentation and outputs of exodus-standalone, I'd say.

jawz101 commented 4 years ago

I wonder if having badges to distinguish any trackers that mention GDPR, COPPA or other governments' compliances might be a good indicator. And if adding xyz tracker immediately changes your app's content rating from E for Everyone to Teens and up that would immediately cut down your userbase, that would encourage selection of more reputable 3rd parties.

pnu-s commented 4 years ago

Hi @jawz101 ! That's a sensitive topic, because we don't want to give any value judgement about which trackers you are using (as rating tracker is a very tedious and risky job).

This being said if anyone wants to use our dataset to do that job, it's freely available (and some are already doing something similar).

jawz101 commented 4 years ago

I wouldn't think it's a judgement. All I'm suggesting is if their Privacy Policy or ToS mentions xyz regulations then they at least acknowledge that they think about these things. I'm just thinking there is a difference between a company that lists a business address, has some sort of legal documentation saying something about their business and its purposes versus some of the intentionally subversive company.