The thing is, I don’t agree to those new permissions. So I tweeted this:
Looks like this new update to Facebook for Android means it's time to uninstall the app.
It seemed to hit a popular nerve and got retweeted a handful of times, but then I started to get people telling me I was in error or having a knee-jerk reaction. Twitter’s 140 characters are great for short bites but somewhat lacking in context, so I thought I’d (hastily) put together this explanation.
I don’t believe that my personal data should be a condition for installing an app. I believe that when an app or service wants my data, it’s entering into an exchange with me. For me to be happy with the exchange, I need a satisfactory answer to these three questions:
- For what purpose do you want my data?
- What do I get in return?
- How can I get my data deleted if I change my mind?
In my opinion, Facebook’s explanations aren’t satisfactory. In the case of SMS permissions, they give the example of using SMS confirmation codes for authorisation. This is a reasonable example, but the wording is clear that it is only an example of what they require the permission for.
That causes what is, to me, an unacceptable ambiguity: a permission may be granted for a use I deem reasonable now, but once granted it doesn’t have to be requested again for a reason which I may find unreasonable.
Perhaps it doesn’t mean that, and maybe I’m being paranoid, or uncharitable, or thinking the worst, but to be honest, I’m a very light Facebook user and I don’t need the hassle of working out whether that’s the case or not.
So I don’t agree with the latest permission requests, and as they’re not optional requests I took the only course of action open to me and uninstalled the app. I’m not thinking about terminating my Facebook account, I can avoid the permissions issue by using the mobile website instead, so I will.
If Android had an optional permissions model, or if there were definite guarantees from Facebook about what these permissions were required for, this would have all passed without incident.
There are, of course, much bigger conversations being held about personal data and privacy, but it’s almost Christmas and I should stop writing this.