Skip to content
gwpenn edited this page Apr 20, 2015 · 4 revisions

Data Collection Policy

Data collection is one of the hardest parts of a project like uProxy. Being able to collect usage data is incredibly valuable; it allows us to learn about the experience users are having with uProxy and find out where they fall off, and where we should focus development. It can be one of the best ways to find bugs and assess their severity.

At the same time, we do not want to spy on you, because that would be sleazy, and it would defeat the whole purpose of uProxy. To that end, we have adopted the following data collection strategy.

  • When the 'report feedback' functionality is used, and the include logs checkbox is marked, we will collect recent logs, along with a snapshot of client state. The user ID's of your contacts will be masked, but we will treat all logs data as personally identifying and erase those logs once they have been investigated by our development team. At a maximum, these logs will be retained for 3 months.

  • We will also ask users to opt-in to report usage statistics. We will take four precautions with these usage statistics to protect your data:

    1. All report data will be hidden through a process known as cloud fronting, and will be reported at irregular intervals over an SSL-encrypted connection. Together, these techniques will make it difficult for a network adversary to use the requests to identify that you are a uProxy user. The cloud fronting technique is also used for feedback submissions.

    2. Usage statistics will be anonymized using the RAPPOR algorithm. You can think of this algorithm as randomly flipping a coin and deciding whether to report your actual usage data or made up data. It means that we cannot trust any individual report, but can only learn usage information in aggregate, and that your report cannot be used to prove anything about your usage of uProxy.

    3. We will ask you to make an informed decision to opt-in to the program when you first install uProxy. The presented dialog box will present the choice without bias, and will not act as a 'click-through opt-in' or otherwise attempt to manipulate your choice.

    4. We will display text indicating you have opt-ed in to data collection during any interaction you make with uProxy that would affect the statistics your client reports. This is meant to ensure that you have consented to report the data, and not an OEM or other user who installed the software.

Clone this wiki locally