Current problem
theoretically, for legal reasons, bot operators need to communicate to their users (guild administrators) how they use or persist user data. and guild admins need to communicate that with their users (e.g. in an onboarding/rules/welcome channel).
most of the time this doesn't happen. and it can lead to users not being clearly informed of data collected about them. because people don't like writing or reading legal documents.
Proposed change
bots on Fluxer should be able to declare how they process and store and share user data.
for instance, a moderation bot might state something like this:
- message contents are retained for up to 7 days, and viewable by community moderators for the purpose of investigating recent incidents.
- message contents and basic user metadata will be shared to a public matrix room, where other servers may process your data in unknowable ways
- message contents and basic user metadata will be shared with Discord. their privacy policy describes how they process that data
- (maybe one or two important points about how Discord's privacy policy differs from Fluxer in important ways)
Platform
API
Additional information
this idea is heavily inspired (down to the catchy name) by Apple's "privacy nutrition labels": https://www.apple.com/privacy/labels/
every app on their App Store must self-report how it processes user data in an easily digestable summary.
other app stores implement this too, most notably Google Play.
2 comments
Comment by tempest:squll.fartcore.ai
Comment by vicky
- Giving more work to the Fluxer dev team and;
- Having Fluxer Platform AB indirectly endorse 3rd-party bots.
Now that I've written that down, that pretty much rules out the "officially reviewed" thing. I thing community-reviewed could definitely be a thing though. In both suggestions, I think we do have to find a way to explicitly differentiate self-affirmed privacy policy and audited privacy policies.