Skip to content

Conversation

@charlag
Copy link

@charlag charlag commented May 9, 2025

Type of pull request: product edit

Related issues: N/A

Copy link
Collaborator

@doamatto doamatto left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the late review.

value = "yes-72"
notes = [
"Tutanota is based in Germany so it is legally obliged to notify users of data breaches, but does not make any mention about if they will do so."
"Tuta is a German company, and adheres to German law which requires the company to notify users in case of a data breach. Tuta even informed users about a security weakness, which to the company's knowledge, did not cause any data being leaked: https://tuta.com/blog/vulnerability-fixed"
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We err on the side of caution (and pessimism) — I have no doubts Tuta can and will follow the law, but if it's not explictly stated in the privacy policy or some other tightly linked document (like a whitepaper), then we can't grade it higher.

"Insofar as we process personal data during the campaign analysis, this is done on the basis of Art 6 para. 1 p. lit. f) GDPR. Our interest in being able to evaluate advertising campaigns and to improve our marketing activities constitute a legitimate interest within the meaning of Art. 6 para. 1 p. lit. f) GDPR."
]
notes = [
"Note: The privacy policy has been misunderstood. Tuta does not collect personal data from third parties, but explains here how it handles user data in their own campaigns."
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Admittedly, reading over the citation I'm struggling a titbit to grasp the exact "timeline". My understanding is :

  1. You click an AdSense ad or some other Google advert which brings you to tuta.com/abc?utm_id=abc
  2. Tuta stores the IP and user agent as a hash (probably to discern unique visitors rather than generic hits) alongside with the campaign ID from before and, if you came from a search, what you searched.
  3. After 72 hours, Tuta deletes all that information.. except after 72 hours what you searched can still be used for ad testing despite having been deleted ?

If that is the case, then I see no reason this couldn't be graded no

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants