Foundation/Privacy not included
The Privacy Not Included Guide [archive]
"Privacy Not Included" is a buyer’s guide created by the Mozilla Foundation to help people check how safely internet-connected products (like smart TVs, smartwatches, toys, cars, and apps) handle personal data. Products that fail basic safety tests get a warning label that says "Privacy Not Included."
Why We Made This Guide
Welcome to Mozilla’s *Privacy Not Included buyer’s guide. Our goal is to help you shop smart—and safe—for products that connect to the internet.
In 2017, when we first started *Privacy Not Included, we didn’t know if people would be interested in a guide about the privacy and security of connected toys, gadgets, and smart home products. Turns out, they were. And it wasn’t just people who were interested. We discovered some companies were too. We’re happy to see both consumers and companies increasingly value connected products that are safe, secure, and private.
Unfortunately, It is often difficult for consumers to get clear, concrete information from companies about the security and privacy of their connected products. Is your personal data shared or sold in ways you may not have expected? What is the company’s known track record for protecting the personal information they collect on you? How does the company regularly test for and fix security vulnerabilities?
With this guide, we hope to help you navigate this landscape by understanding what questions you should ask and what answers you should expect before buying a connected tech product.
The way we approach our research here at *Privacy Not Included is from the viewpoint of you, the consumer. We just have a bit more time and expertise to read privacy policies and delve into company’s security practices. We don’t purchase the products and test them in a lab. Consumers can’t do that. Instead, we look at all the information we can find that is publicly available to consumers before they purchase a product to try and understand the privacy and security concerns you should be aware of. We seek a future in which hours of research like this aren’t required to buy safe, responsible products. Unfortunately, it seems we have a long way to go. In the meantime, we’ll read those boring privacy policies so you don’t have to.
What can you expect in our guide to help you shop safely for those connected products? Quite a few things.
Our *Privacy Not Included warning label
We’re very excited our *Privacy Not Included buyer’s guide comes with *Privacy Not Included warning labels on products we think consumers should think twice about before buying. It’s no small thing to assign such a label to a product, so we set ourselves some strict standards. Where we have concerns, we aim to be as specific as possible about what could happen so you can buy products that meet your standards.
Our Best Of category
It’s one thing to call out products that are bad. We also want to help consumers know what products are good. Check out our Best Of category to see which products and companies we think are doing privacy and security right.
There is a Creep-O-Meter
We want you to be able to share your opinion too. It’s important for companies and other consumers to see which products people think are safe, and which products people feel are a bit creepy. So we created our Creep-O-Meter—a user rating on each product—to let you share your opinion. Companies are paying attention, so let them know if you think their product is creepy or not!
Our Minimum Security Standards
We realize people want to just know which products are safe and which aren’t. We used our technical expertise here at Mozilla to create a set of Minimum Security Standards we think all products should meet in order to be sold in stores. Those standards include using encryption, automatic security updates, requiring strong passwords, having a system to manage vulnerabilities, and having an accessible privacy policy. Read more about our Minimum Security Standards on our Methodology page.
Tons of Research
You’ll notice a lot of research went into this guide. We even include the hours we spent researching a product on every page. Fortunately, we have great researchers and expertise here at Mozilla to dig into this so you don’t have to. We don’t buy and test products. Instead we look at what we can find that is publicly available. Our researchers comb through privacy policies, reach out to companies with questions about encryption and bug bounty programs, sift through product and app specifications, and read the research and news articles written about the products in the past three years. We do our best to then make your access to all this information accessible and easy to understand. We’ve even put together a How to Use This Guide page to help you understand all the information we share here on *Privacy Not Included.
We hope you use this guide to help you think about, shop for, and buy products from companies that show they value privacy and security. Then share it with your friends and family to help them shop safe too. We as consumers need to demand that privacy and security as a value from the people who build our products. It’s how we’ll start to make the internet, and our lives, a bit safer in this digital world. That is our goal every day here at Mozilla.
We hope you use and enjoy this guide to help you think about, shop for, and buy products from companies that show they value privacy and security. We as consumers need to demand that value from the people who build our products. It’s how we’ll start to make the internet, and our lives, a bit safer in this digital world. That is our goal every day here at Mozilla.
Thank you! The *Privacy Not Included Team
Mozilla fights daily for a healthier internet as a non-profit tech company that puts people before profit. This guide was created by the Mozilla Foundation which relies on donations from people like you to do our work. You can also visit Mozilla.org to learn more about our purpose driven products like Firefox and Common Voice.
How to Use This Guide
Need help understanding how to use this guide? Here you go.
Tip: If you don’t find the product you are looking for, search to see if we reviewed any other products made by that company. Often, criteria will match from one product to another from the same company. We simply don’t have time to review all the connected products out there.
Privacy Not Included Warning Label
Our Privacy Not Included buyer’s guide comes with *Privacy Not Included warning labels on products we think consumers should think twice about before buying. It’s no small thing to assign such a label to a product, so we set ourselves some strict standards. If we can’t confirm a product meets our Minimum Security Standards, it automatically earned the *Privacy Not Included label, as we feel those standards are the minimum a product should meet to be on the market. We also look at how a company uses the data the product collects on you, how you can control the data the company collects, and what the company’s known track record is over the past two years for protecting their users’ data. How a company performs on these criteria determines if we assign them the warning label. You will see little mini-warnings in our review section of the guide to help you understand what our concerns are.
What could happen if something goes wrong
It’s likely nothing bad will happen with most of the products in this guide. However, it’s also good to think through what could happen if something goes wrong. We try to identify what risks and concerns users should have about the product. We often lay out a potential worst-case scenario--in some cases for fun and in some cases based on things that have already happened.
Tips to Protect Yourself
While we don’t think all the responsibility should be on consumers to protect themselves when they buy a connected product, the reality is, the more you can do as a consumer, the better. We lay out a few tips of things you can do to be a little safer, whether it be to set up two-factor authentication, lock down your privacy settings, or remember to opt-out of data sharing. And we try to link to places to help you understand how to do this too.
Time Spent on Research
We approach our research for *Privacy Not Included from the viewpoint of you, the consumer. We don’t purchase the products and test them in a lab. Consumers can’t do that. Instead, we look at all the publicly available information we can find to try and understand the privacy and security concerns you should be aware of. We want to help you understand how long this takes us, in part so you know we’ve taken the time to get things right. But also to help you understand how ridiculous it is that consumers are expected to spend so much time researching connected products before they buy them just to hopefully protect their privacy. It shouldn’t be like this. Companies should do better by building privacy by design into their products.
Mozilla Says
If a product receives our *Privacy Not Included warning label, we give it a Thumbs Down. If we designate a product as Best Of, it receives a Thumbs Up. If a product receives neither, we give it a Thumbs Sideways.
Creep-O-Meter
Our Creep-O-Meter is a reader-generated rating - and an opportunity for you to share your opinion. Read the review of the product, then rate how creepy or not creepy you think the product is. Click vote to see how your opinion stacks up with others. It helps other consumers understand the risks of a product and shows companies how creepy customers find their products. Look at the top of the page to see the “people voted” rating of each product in the guide. Privacy
Can it snoop on me?
Just because a device has a camera, microphone, or tracks location doesn’t mean it will snoop on you. It simply means it could and you should be aware of that. Also, many connected devices are controlled by apps on your phone. The apps often ask to use the phone’s camera, microphone or location tracking. Keep an eye on that, as some of the permissions the apps ask for might surprise you.
What is required to sign up?
To use a product do you need to give up your email address, your phone number, or sign in through a third party such as a social media account like Facebook? This is good to know ahead of time so you’re aware of what you’ll need to use the product.
What data does this product collect?
Connected devices collect information on their users. We look at what personal, body-related, and social data a product is likely to collect on you when you use it. Knowing what sorts of personal information you’ll need to give up to use a product is useful to help understand just how much a company could be learning about you. The more information you give up, the better they may know you. Personal data includes things like name, email address, phone number, gender, age, and date of birth. Body-related data includes things like voice recordings, fingerprint, facial recognition, height, weight, heart rate, sleep data, menstrual cycles, and blood oxygen levels. Social data includes things like your contacts and friends or connections you have through a platform, like gamer friends through a gaming console or connections you have through a fitness app.
How does it use this data?
Nearly every company collects some kind of information on its users. That’s how the internet works. It’s how they use and care for this information that matters. You should know whether a company shares or sells your personal information to others and for what reasons. This criteria is one of the criteria we use to determine if a product receives our *Privacy Not Included warning label. Companies that share or sell your data to third parties received a mini-warning label.
How can you control your data?
Many companies collect a lot of data on their consumers. Who controls that data? Being able to contact a company and ask them to delete any data they have on you is a very good thing.
What is the company’s known track record of protecting users’ data? + mini ding
It’s one thing for a company to say they care about their users’ privacy. It’s another thing to show that. We look at the track records of all the companies in the guide dating back three years to see if they had known data leaks, security vulnerabilities, or other privacy missteps. This criteria is one of the criteria we use to determine if a product receives our *Privacy Not Included warning label. Companies that have multiple or serious privacy or security breaches receive a mini-warning label.
Can this product be used offline?
Does every product really need to be connected to the internet to work? What happens if the internet goes out or you just want to use that smart scale as a scale? Some *Privacy Not Included users reached out to us over the past couple of years and asked us to include this in our guide. We aim to please!
User friendly privacy info?
Privacy information should be clear, readable, and communicate basic information to consumers about what happens to their data. Privacy policies are often written more for lawyers than consumers. That’s why it’s nice to see more and more companies creating consumer-friendly privacy pages to outline how they handle your personal information and the data they collected on their users. We hope to see this trend continue. Security
Our Minimum Security Standards
We developed a set of minimum security standards we think all connected products should meet at the very least. Think of it as a “you must be this tall to ride” set of standards. These include five basic things: The product must use encryption, the company must provide automatic security updates, if a product uses a password, it must require a strong password, the company must have a way to manage security vulnerabilities found in their products, and the company must have an accessible privacy policy.
Encryption
Encryption is your friend. It protects your private and personal information by scrambling it up into a code so that the only people or machines who can read it are the ones on the other end who have the key to unscramble that code. Products that don’t use encryption send personal information over the internet unscrambled so anyone can see it.
Security updates
Sometimes security vulnerabilities are found in products after they are sold to the public. For that reason, companies should have a way to quickly push a security update out to the product automatically so it fixes the security vulnerability without the consumer ever needing to worry about it.
Strong Password
Remembering passwords might be annoying, but having a good password is still one of the best lines of defense we have when it comes to protecting our privacy and security. It’s great when a password is required. But default passwords that are the same for all consumers and never change can be just as bad. You should be required to change the default password to a strong password. Products with a default password that does not require changing can leave users’ personal information exposed.
Manages vulnerabilities
Security vulnerabilities in products happen. It’s how companies manage them when they arise that matters. We looked at whether or not companies have a system in place to manage vulnerabilities in the product when they are found. This includes having a point of contact for reporting vulnerabilities or an equivalent bug bounty program.
Privacy policies
Privacy policies detail a lot of important information about how companies collect, use, and share your personal information. Because of that, this information should be easily found and easily understood. Consumers shouldn’t have to buy a product before they can find or read a privacy policy too. A.I.
Does the product use AI?
More and more products use artificial intelligence these days. It’s not just smart speakers and facial recognition in security cameras either. It’s AI in dog toys and fitness trackers and connected workout equipment. For our reviews, we defined AI as: Automated technology that makes decisions for you and/or changes continually based on your user data. What does all this mean for consumers? We’re just starting to understand. However, most consumers don’t know when AI is being used or how it may affect their experience. We believe companies should provide this information to consumers as AI-enabled products become more prevalent and its decisions about you - and for you - more consequential. For more on Mozilla’s position on creating trustworthy AI, you can read our whitepaper Creating Trustworthy AI.
Is this AI untrustworthy?
Too often, AI in our world comes with bias or unethical behavior. Unfortunately, it’s nearly impossible to tell if a company’s AI algorithms are trustworthy and ethical or not, and there’s not a commonly agreed upon framework for ‘trustworthy AI’ features and policies. However, we do know that companies are often not transparent about how their AI algorithms work, and that leaves us concerned overall. If we are able to find credible reporting that shows an AI is untrustworthy, we will note it here and issue a warning label with a clear description about how we came to this conclusion.
What kind of decisions does the AI make about you or for you?
We think consumers should know if a product uses their personal data to make decisions for or about them. To answer this question, we look to see what the company says the product’s AI is doing? We can’t always tell though, and that is not good.
Is the company transparent about how the AI works?
One of the biggest issues surrounding artificial intelligence in our consumer products is having access to essential information about how AI-enabled features work. For example, what data does it collect and how does it use that information to make decisions for or about you? Knowing how it works lets users evaluate if there may be a chance of bias or ethical implications they should consider before using a product driven by AI. We think companies should have publicly available information explaining this. We’ll let you know if they do.
Does the user have control over the AI features?
We let you know if there is any way to opt out of AI or adjust the settings of the AI if you would like.
Updates
When news breaks or we come across a relevant article about a product in this guide, we will share it in the updates section on each product page.
Comments
We love to hear your thoughts and feedback on the products in this guide. And other users might like to join you in a conversation about any experiences or concerns you’ve had with a product. Please join the conversation in the comment section at the bottom of each product page.
Methodology
If you would like to read more about the research methodology we used to create this guide, please check out our methodology section.
About our Methodology
The goal of Mozilla’s *Privacy Not Included buyer’s guide is to help consumers shop smart — and safe — for products and apps that connect to the Internet. It is often difficult for consumers to get clear, concrete information from companies about the security and privacy of their connected products. Is your personal data being shared or sold in ways you may not have expected? What is the company’s known track record for protecting the user data they collect? How does the company regularly test for and fix security vulnerabilities?
With this guide, we hope to help consumers navigate this landscape by understanding what questions they should ask and what answers they should expect before buying a connected tech product.
The way we approach our research here at *Privacy Not Included is from the viewpoint of a consumer, but with a bit more time and expertise. We don’t purchase the products and test them in a lab. Consumers can’t do that. Instead, we look at all the information we can find that is publicly available to consumers before they purchase a product to try and understand the privacy and security concerns consumers should be aware of. We look at things like privacy policies, company websites, news reports, research whitepapers, app store listings, consumer reviews, and anything else we can find and trust to inform our research. Too often, the information companies make publicly available is vague or incomplete. We often have no way to verify if a company is doing what it says even after they reply to our requests. We seek a future in which hours of research like this aren’t required to buy safe, responsible products.
Here is the methodology we used to develop this guide. Methodology Product Selection
When we select products for *Privacy Not Included, our goal is to choose connected products and apps that are likely to be popular with consumers in North America and Europe. We make our decisions based on our own research of top selling products that are highly rated across a variety of consumer product websites such as Consumer Reports, Wirecutter, CNET, and more.
- Privacy Not Included Warning Labels
We assign our *Privacy Not Included warning label to products we have determined to have the most problems when it comes to protecting a users privacy and security. A product will earn the *Privacy Not Included warning label if it receives two or more warnings from us on the following criteria: How the company uses the data it collects on users. We ding companies for selling users data or collecting more data than is necessary for general business purposes, for example, buying data from data brokers. How users can control their data. We ding a company if they don’t have a clear and manageable way for users to delete their data from the company or explain how long they retain users’ data. What is the company’s known track record of protecting users’ data? We ding a company if they have a bad track record of not protecting users’ data based on known and reported security breaches, leaks, or vulnerabilities. Finally, we ding a company if we can not confirm if the product meets our Minimum Security Standards. In rare exceptions we might ding a company if they only receive one warning from us if we determine that warning is particularly concerning for consumers.
While we currently can assign a product a warning for the use of untrustworthy artificial intelligence, we don’t use that rating to factor into our decision to assign the *Privacy Not Included warning label as the information from companies is currently very limited and we cannot easily compare one product another with a high degree of confidence. What could happen if something goes wrong?
We include this section to help people understand what could potentially go right or wrong related to the privacy and security with each product. We aim to identify risks and concerns that are relevant to consumers specifically. While it is likely nothing bad will happen with most of the products in this guide, it is also good to think through what could happen if something goes wrong based on real life situations. Tips to protect yourself
We review suggestions from both the product manufacturer and draw upon published privacy and security guidance from a range of experts, both within Mozilla and outside sources, to provide a few simple tips for each product users can take to protect themselves. These tips are recommendations for protection, not guarantees. Permissions
We look to see if it is possible the device could snoop on you if it were hacked, leaked, or not working correctly. Please note, just because a device could snoop on a user doesn’t mean it will. Simply that it is a possibility users should consider before purchasing.
To determine this, we check product websites and the Google Play Store or the Apple App Store to check on the permissions requested by each app to determine whether the device and its app uses a camera, microphone, or tracks your location. (Note: an app may access “approximate” or “network” based location. “Tracks Location” was marked as “Yes” if an app requests any location information, including approximate location.)
The apps that control connected devices will typically need to request permissions from your phone for the app to work. This is mostly OK. However, we want consumers to understand when to look for things that don’t feel right, like a children’s fitness tracker app requesting permission to use the phone’s microphone or a home exercise workout machine requesting permission to track location. Privacy
We evaluate the publicly available privacy documentation provided by each company for each product. This includes privacy policies, privacy pages, and FAQs. We attempt to determine (1) what kind of information is generally collected by a product, including personal, body-related, and social, (2) how the data is used by the company, (3) how you can control your data, including how you can access and delete your data, (4) the known track record of a company for protecting user data, (5) if the product can be used offline, (6) and whether the privacy policy is user-friendly. If a company does not provide a product-specific privacy notice, we rely on their general privacy policy for this information. This often means we cannot verify which information mentioned in a company’s privacy documentation may or may not be true about a specific product. In our requests for information from companies before publication, we ask for product-specific privacy policies and if a company shares it, we analyze the product-specific policy. We believe consumers should be able to access privacy policies and documentation before they purchase a product. Learning what data a company collects and how it uses that data is important to know before downloading an app or buying a product. What kind of data does the company collect? Personal
We list the personal data collected by each product, as specified in the privacy policy. This kind of information includes, but is not limited to, name, email address, phone number, and address. Body-Related
Body-related (including biometric data) is data that describes our bodies and distinctive personal characteristics such as fingerprints, voices, and heart rates. Many devices collect sensitive data about stress, sleep patterns, and menstrual cycles, for instance. Some products use face and voice to identify users. Social
Social data includes information about your friends and contacts. We detailed which products collect this social information. This does not include the sharing of links or other information on social media through the product itself (e.g. sharing your route for a run on Facebook). How does the company use this data?
How do companies collect, use, and share or sell user data with third parties? Do companies combine user data with data from other sources? Is data used for advertisement? For this question, we analyzed the company’s privacy documentation to determine how and when personal customer data is shared with third parties for reasons other than expected. For instance, if a company can share or sell personal customer data with third parties, or if third parties can use data for commercial purposes, then we noted this. Often, privacy policies are written to allow a company the widest set of options for data sharing and sales, even if they don’t currently engage in those activities. To determine current practices, we look for FAQs or other information on company websites to provide additional information. Additionally, if a company provides us with posted information about these practices, we include that information and relevant links.
When determining if a product receives a warning on this criteria we look at three major factors. (1) How much data does the company collect on a user? What can and does the company learn about you with this data? Does it collect a large amount of personal data or only what seems necessary for their product to work? (2) Does the company share, combine, or sell this data with a large number of third parties for purposes beyond the normal function of the product? (3) Does the company provide clear and explicit notice before sharing user data with third parties? (4) What types of data are shared for advertising and marketing purposes? We attempt to explain to users what sorts of data collection they should be concerned about in our reviews. How can you control your data?
Does the company provide a way for users to request access to and deletion of their data? We look for language around this in the privacy policy and/or whether the company has an online portal or contact that allows users to delete their data quickly and easily. We also look for clear retention periods and deletion methods, keeping in mind that retention periods vary greatly and may have different use cases for different types of products. Where anonymization is offered as an alternative to data deletion (which is allowable under GDPR) we note that some forms of anonymization do not completely eliminate the potential for identification.
When determining if a product receives a warning on this criteria we look at three major factors. (1) Does the company have a means for a user to request access to the data the company has collected? (2) Does the company have a clear means for users to request the deletion of their data in a reasonable timeframe? (3) Does the company provide retention details for user data? Does the company promise to delete data after it is not needed to fulfill the purposes for which it was collected? What is the company’s known track record of protecting users’ data?
We evaluated each company’s history of storing and protecting customer data within at least the previous three year period. We conduct research to find any known public hacks, data breaches, data leaks, or other incidents.
When determining if a product receives a warning on this criteria we look at four major factors. (1) Has the company had any major security vulnerabilities or data leaks in the past three years? (2) If the company has had known security vulnerabilities, have they acted quickly and openly to fix these security vulnerabilities and leaks? (3) Does the company have a track record of being honest and ethical when it comes to protecting user data? (4) What was the volume and sensitivity of leaked data? Can the product be used offline?
We checked to see if the product could be used offline or if being online was a requirement to use the product effectively (if applicable). We include this to let consumers know, for example, if an app that might collect data on them is required. User-friendly privacy information
We evaluate how easy it is to find clear, specific, easy to understand information about a device’s privacy policies. How clearly is that information stated? Privacy information should be clear, readable, and communicate basic information to consumers about what happens to their data. We looked for whether the company provides easy-to-read privacy information, either in the privacy policy or in another privacy page. Vaguely worded, dense, overly long and complex privacy policies are not considered user-friendly in our research Minimum Security Standards
Mozilla established a set of Minimum Security Standards we determine should be met by any manufacturer developing connected products. We email each company at least three times (the first email at least 30 days prior to the publication) to ask for more information about their product and how it meets our standards. For the companies who do not respond, we conduct additional research to find the answers wherever possible. If we cannot determine an answer based on the company response and our own research for any of the five criteria below, we indicate the company does not meet our Minimum Security Standards. When a company responds, even after publication, with additional information, we add this information to product listings.
We evaluated each product on our list against five criteria: Encryption
A product should use encryption in transit and at rest (where applicable). The product must use encryption for all of its network communications functions and capabilities, ensuring that communications aren’t eavesdropped on or modified in transit. User data should be encrypted when it is stored. While end-to-end encryption is preferable, it is not a requirement to meet our Minimum Security Standards. Security updates
The product must support automatic security updates for a reasonable period after sale, and be enabled by default. This ensures that when a vulnerability is known, the vendor can make security updates available for consumers, which are verified (using some form of cryptography) and then installed seamlessly. Strong passwords
If the product uses passwords or other means of security for remote authentication, it must require that strong passwords are used, including having password strength requirements. Any non-unique default passwords must also be reset as part of the device’s initial setup. This helps protect the device from vulnerability to guessable password attacks, which could result in a compromised device. In cases where a device is protected with something other than a password, for example a secure Bluetooth connection, we put NA in this field. Vulnerability management
The vendor must have a system in place to manage vulnerabilities in the product. This must also include a point of contact for reporting vulnerabilities or a bug bounty program. This ensures that vendors are actively managing vulnerabilities throughout the product’s lifecycle. Privacy Policy
The product must have a publicly available privacy policy and/or another privacy page that applies to the device, app, or service we are evaluating. The product must also have work contact information consumers can reach in a privacy policy for privacy related questions or concerns. Artificial Intelligence
We evaluate whether or not a product uses artificial intelligence. We defined AI as: automated technology that makes decisions for you and/or changes continually based on your user data. This would cover Alexa changing to better understand what you say, to your fitness wearable making recommendations on exercises to do so that you meet a specific wellness goal, or your security camera deciding not to alert you because it can distinguish a raccoon from a human. For more on Mozilla’s position on creating trustworthy AI, you can read our whitepaper Creating Trustworthy AI. Does the product use AI?
Based on responses from companies and our own research, we note whether or not a product uses AI, or if we could not determine whether or not the product uses AI. Is the AI untrustworthy?
When determining if a product receives a warning on this criteria we look at two major factors. (1) If we are able to determine if AI decisions demonstrate biases based on reporting from experts and trusted sources. (2) If we are able to determine if the AI behaves in some other way we consider unethical and/or untrustworthy based on reporting from experts and trusted sources. What kind of decisions does the AI make about you or for you?
What does the company say the product’s AI is doing? To answer this question, we analyzed the product description and, if available, AI documentation and white papers. Is the company transparent about how the AI works?
Is there publicly available information about how the algorithm behind the AI makes decisions? One of the biggest issues surrounding artificial intelligence in our consumer products is access to essential information about how AI-enabled decisions are made. Such as, how does the algorithm avoid bias and ensure fairness. We asked, does the company publicly inform and explain how their AI works? If we are able to find technical documentation, academic papers, open source code, or other documentation about the AI, we mark this as yes. Does the user have control over the AI features? Yes/No/Limited/NA/Can’t Determine
We attempt to determine if there is any way to opt out of AI, and/or adjust the settings of the AI.
Press Samples
Privacy Not Included helps consumers shop for trustworthy connected products while shining a light on products with poor privacy and security practices. We also uplift companies who get it right. If you’re looking for inspiration for your company’s own privacy policy, start here.
The people have spoken! Mozilla’s *Privacy Not Included won two Webby awards in 2023: the “Responsible Information” award in the Inaugural Responsible Technology category and the “People’s Voice” award. This win marks their second “People’s Voice” win since 2020.
Since launching 2017, *Privacy Not Included has reached millions and garnered hundreds of stories around the world. The guide’s groundbreaking product reviews scrutinize the privacy features and flaws of connected gifts, sex toys, dating apps, reproductive health apps, mental health apps, and cars.
BBC Top Gear: Modern cars branded a ‘privacy nightmare’ by Mozilla Published September 2023. “First up, Mozilla says every car brand collects “too much personal data”... Secondly, the survey concluded that 84 per cent of motor manufacturers share your data and a worrying 76 per cent sell drivers’ personal data.” For generations, the car in America has come to symbolize freedom… And for many, freedom and privacy go hand in hand. It's hard to have one without the other. But according to a new report, your car could be worse than your phone when it comes to privacy.
— Scott Detrow, NPR
The Washington Post: Carmakers fail privacy test, give owners little or no control on personal data they collect Published September 2023. “Cars are getting an “F” in data privacy. Most major manufacturers admit they may be selling your personal information, a new study finds, with half also saying they would share it with the government or law enforcement without a court order.”
Gizmodo: If You've Got a New Car, It's a Data Privacy Nightmare Published September 2023. “Mozilla found brands including BMW, Ford, Toyota, Tesla, and Subaru collect data about drivers including race, facial expressions, weight, health information, and where you drive.”
Los Angeles Times: Mental health apps may put your privacy at risk. Here's what to look for Published May 2023. “Jen Caltrider, director of Mozilla’s Privacy Not Included work, said it’s important to read an app’s privacy policy before downloading it because some of them start collecting data from users moments after they’re activated.”
The Verge: Mental health app privacy language opens up holes for user data Published May 2022. “Mozilla researchers said this week that mental health apps have some of the worst privacy protections of any app category.”
VICE: Period-Tracking Apps Won’t Say Whether They’ll Hand Your Data Over to Cops Published August 2022. “In total, of the 25 apps and products Mozilla reviewed, 18 were slapped with its ‘Privacy Not Included’ label, indicating that people should be cautious of using them.”
The Guardian: How private is your period-tracking app? Not very, study reveals Published August 2022. “Experts at internet research non-profit Mozilla studied more than 20 pregnancy and period tracking apps for privacy and security features and said the results were grim.”
Daily Dot: These sex toys and dating apps may jeopardize your privacy, Mozilla warns Published February 2021. “Mozilla’s new Privacy Not Included report looks at 50 sex toys and dating apps and ranks them based on how they respect users’ privacy. And the answers aren’t sexy.”
Mashable: Privacy experts reviewed popular video-chat apps, and *yikes* Published April 2020. “[Mozilla] researchers combed through privacy policies, sifted through app specifications, and looked at critical questions.”
NPR: Mozilla’s Latest “Privacy Not Included” Buyer’s Guide Published December 2019. Ashley Boyd, Mozilla’s VP of Advocacy and Engagement, spoke with host Steve Inskeep about the surveillance features that are often built into consumer technology. Here’s a warning that should be on some of the items on your holiday shopping list—*Privacy Not Included. That’s the point of a shopping guide put out by the Mozilla Foundation.
— Steve Inskeep, NPR
USA Today: Before you buy, consider privacy, please Published November 2019. Mozilla researcher Becca Ricks spoke with technology columnist Jefferson Graham about the privacy and security flaws of connected doorbells.
WIRED: Mozilla Makes a Naughty List of Gifts that Aren’t Secure Published November 2018. “In its second annual Privacy Not Included guide, the nonprofit highlights internet-connected items that value your privacy—and the ones that may not.”
New York Times: Don’t Give Kids Holiday Gifts That Can Spy on Them Published December 2017. Writes Ashley Boyd in this print and digital op-ed: “During the holiday season, my husband and I tend to offer suggestions to those who are generous enough to insist on buying presents for our kids. This year we’re adding a new rule to our list: No toys that can spy.”