Privacy/Reviews/AndroidSystemStorage: Difference between revisions

(→‎User Data Risk Minimization: proofreading and added dissemination risk)
Line 192: Line 192:
====Principle: Transparency / No Surprises====
====Principle: Transparency / No Surprises====
Users are going to be upgraded from the previous release of Firefox to the Native UI/Birch release.  
Users are going to be upgraded from the previous release of Firefox to the Native UI/Birch release.  
If they have enabled Google sync, they will be opted in without notice to having some of their data from
If they have enabled Google sync, their data will automatically begin accumulating in a way that is archived by Google Sync. Users may potentially be using Firefox to avoid using this shared system storage, and this change may surprise them.
Firefox for Android browsing synced to Google. Users also may be using Firefox to avoid using system
storage, and will be opted in to using it when upgraded to the Birch release.


Additionally, it may happen that users will sync their Firefox data from Mozilla Sync, this data would then
Additionally, it may happen that users will sync their Firefox data from Mozilla Sync, this data would then
be stored in the system store and then possibly synced to Google - breaking expectations of where and how
be stored in the system store and then possibly synced to Google - breaking expectations of where and how
sync'd data is shared
sync'd data is shared


''Recommendations'': (what can be improved)
''Requirement'': Disclose this switch to Android System Storage to users who may not want to share their bookmarks and history outside of Firefox or Firefox Sync.


What can be improved:
''Recommendation'': Provide an option to store data apart from the global store.  That is, do not use the global system services to store history, bookmarks, and passwords.  But instead, hide them from the rest of the phone and discourage data sharing on the device. Have users opt-in to using the system storage and syncing to Google if that's what they want.
 
* Option to store data apart from the global store.  That is, do not use the global system services to store history, bookmarks, and passwords.  But instead, hide them from the rest of the phone and discourage data sharing on the device.


====Principle: Real Choice====
====Principle: Real Choice====


In the initial shipping version of Firefox for Android, there is no option to not use Android system storage. (There are plans to add this functionality after the initial release).  
In the initial shipping version of Firefox for Android, there is no option to store history and bookmarks ''outside'' or isolated from Android system storage. (There are plans to add this functionality after the initial release).  
 
'''Recommendations'':
 
What can be improved:


* Option to store data apart from the global store. That is, do not use the global system services to store history, bookmarks, and passwords.  But instead, hide them from the rest of the phone and discourage data sharing on the device.
''Recommendation'': Provide an option to store data apart from the global store. (See above).


====Principle: Sensible Defaults====
====Principle: Sensible Defaults====


Opting users in to using the system database on upgrade to the Native UI version of Firefox for Android is a sizable change from previous version of Firefox for Android.  
Opting users in to using the system database on upgrade to the Native UI version of Firefox for Android is a sizable change from previous version of Firefox for Android. While it makes sense to default to the Android System Storage


''Recommendations'':
''Requirement'': Disclose this change in behavior to our users, and do not migrate their old profile data automatically. (See above).


What can be improved:  
====Principle: Limited Data====


* Provide an option to store data apart from the global store.  Use this option by default, preserving the same experience with respect to privacy and data ownership as previous XUL-based versions of Firefox for Android. Have users opt-in to using the system storage and syncing to Google if that's what they want.
Mozilla itself will not collect additional data in the Native UI version of Firefox for Android. Mozilla Sync will continue to be opt in and configurable by the user.  No actions needed for this principle.
 
====Principle: Limited Data====


Mozilla itself will not collect additional data in the Native UI version of Firefox for Android. Mozilla Sync will continue to be opt in and configurable by the user.


''Recommendations'':
{{ResolutionBox|{{new|}}}}
* No action needed


= Follow-up Tasks and tracking =
= Follow-up Tasks and tracking =
canmove, Confirmed users
1,537

edits