Spotifyâs Privacy Policy is Mostly Fine
Gordon Gottsegen at Wired:
SPOTIFY RELEASED A new privacy policy that is now in effect, and it turns out that the company wants to learn a lot more about you and thereâs not much you can do about it.
Iâm all for calling out creepy privacy policies, but Spotifyâs actually seems fine. Most of the items mentioned are clearly in service of a user-facing feature in Spotify.
Letâs go through them. All further quotes are from Spotifyâs privacy policy.
âWith your permission, we may collect information stored on your mobile device, such as contacts, photos, or media files. Local law may require that you seek the consent of your contacts to provide their personal information to Spotify, which may use that information for the purposes specified in this Privacy Policy.â
Contacts. Want to be able to check your contacts to find your friends on Spotify? Maybe you donât personallyâand if not, you donât have to give Spotify permission to access your contacts!âbut a lot of people want to be able to do that when signing up for a service with a social component. This would be true of any service with this functionality.
The second sentence sounds weird, but it also sounds like a legalese disclaimer they were forced to put in there. Thereâs a law requiring this somewhere, so here it is.
Media files. Spotify can play the non-DRMed files on your device. To do so, they need to access them. Possibly to make better recommendations, they collect data about these files. Thatâs just a theory, but a music service collecting data about your music hardly seems like an overreach.
Photos. This is the one thing that does seem creepy. I canât think of an explanation for this one.
âDepending on the type of device that you use to interact with the Service and your settings, we may also collect information about your location based on, for example, your phoneâs GPS location or other forms of locating mobile devices (e.g., Bluetooth). We may also collect sensor data (e.g., data about the speed of your movements, such as whether you are running, walking, or in transit).â
GPS location. Popular stuff near you. I donât recall if they have this feature at the moment, but itâs a standard thing to measure and offer.
Sensor data. Spotify Running, which a writer at Wired (UK) found âextremely helpful,â tailors its playback to your workout in real-time. It needs this sensor data to do that.
âYou may integrate your Spotify account with Third Party Applications. If you do, we may receive similar information related to your interactions with the Service on the Third Party Application, as well as information about your publicly available activity on the Third Party Application. This includes, for example, your âLikeâs and posts on Facebook.â
Spotify wants to know about when people use Spotify to post to Facebook (or Twitter or LiveJournal or whatever). Nothing is weird about this â Spotify is already part of the transaction.
Spotify also wants to possibly do things with your publicly available information, which is a little creepy in that thereâs no direct user-facing benefit, but it is public activity. For better or worse, this seems standard these days.
Iâm not writing this because I have some affinity for Spotify and think they can do no wrong. I havenât even been a Spotify Premium subscriber for a while now. Iâm writing this because I care about the abuse of privacy policies and EULAs, and a (deliberately?) sensationalized article like this one is a rather unhelpful thing. Misrepresenting and crying wolf over a policy document thatâs actually rather reasonable makes it harder for everyone to understand and address the truly bad situations where these policies are disrespectful, overbearing, or hostile.