Hacker News new | ask | show | jobs
by dannyw 1814 days ago
This app sounds really cool. I am very interested in using it.

However, I have read your Privacy Policy, and I see that you collect PII like the following:

* Events on all your calendars (Understandable)

* Information about your Google Drive files (?!?)

* Title, description, default time zone, and other properties of Google calendars you have access to (So other people's data).

You say that you may use your collected data for marketing:

* to provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information;

This, to me suggests that you may legally sell my Google Drive files to the highest bidder.

You also provide a broad justification for improving your services, which means you could legally look at my plaintext events and messages as part of "user research" for how people use my service:

* to gather analysis or valuable information so that we can improve our Service;

This is unacceptable in a corporate environment.

I suggest you may want to re-word your Privacy Policy, and make it clear explicitly what you do and don't do with each piece of information.

1 comments

Sorry Danny, it's a big mistake on our side, the privacy policy should be crystal clear.

- On calendar's data: we only use the title, description, etc. of the calendars you have chosen to sync in Hera. - On google drive files, I will clarify this right now, but basically we have an export feature to google docs, which is entirely opt-in. If you want to use the feature, the first time of course you need to give us access to a small subset of your GDrive

- We do not and never intend to sell any of these data to anyone. I reword the privacy policy so that's crystal clear:)