DECODING THE DATA APP CONTROVERSY
NaMo app: What is the issue?
A Twitter profile that goes by the name Elliot Alderson describes the issue with the NaMo app as: When creating a profile in the Android app, device information including OS, network type and carrier, and personal data such as name, photo, gender and email are sent to a third-party domain — in.wzrkt.com — without asking for the user’s permission
The domain is hosted by GoDaddy and the Whois.com info is hidden The domain belongs to a US company called CleverTap.
Who is ‘Elliot Alderson’?
Several reports have identified the man behind the Twitter profile as Robert Baptiste, a 28-year-old French security researcher and telecommunications engineer. He has refused any audio/video interviews but told a publication in a Twitter interaction that he was a freelance Android app developer. What data does the app collect? Asks for 22 permissions including access to location data, microphone and taking photos and videos. Security experts say it shares data with a third party without asking for users’ permission.
What does the BJP say?
Says “the permissions required are all contextual and cause-specific” and that “data is being used for only analytics using third party service, similar to Google Analytics. Analytics on the user data is done for offering users the most contextual content”. What do the app terms declare?
A search on web archives for a cached page of the privacy policy of the app returned the following result: “Your personal information and contact details shall remain confidential and shall not be used for any purpose other than our communication with you. The information shall not be provided to third parties in any manner whatsoever without your consent.” The terms appear to have changed after tweets by ‘Elliot Alderson’. The privacy policy now reads: “Certain information maybe processed by third party services to: — Offer you the most contextual content…” What is the Congress’ take?
Says “there is no truth to this allegation. There has been NO breach of data whatsoever”.