Summary: DropBox now scans the contents of your private documents to train A.I., shares your data with tech giants like OpenAI and Google, records all browser activity of Dash application users, and has humans manually reviewing data.

In my opinion, it is no longer suitable for private or confidential data of any kind.

Key quotes:

We may build models that identify keywords and topics from a given document. These models may be trained on your documents and metadata

We may review which of a given set of search results you click on [...] This can be done manually by Dropbox employee, or as part of a machine learning model

If you use Dash Answers, we may manually review questions you ask and the responses you receive.

When you use Dropbox Dash, Dropbox will import your browser history, starting with the previous 90 days, [...] The data collected includes the URLs of websites you have visited, as well as the contents of those websites (including page titles, images, and page content). [...] we may share your data with trusted third parties

In order to provide, improve, protect, and promote our Services, Dropbox shares your personal information with trusted third parties [...] Trusted third parties include:

  • Amazon Web Services, Inc.
  • CloudConvert (Lunaweb, Inc.)
  • Concord Technologies Corporation
  • ElasticSearch
  • FileStack
  • FullContact
  • Google LLC
  • IDnow GmbH
  • Intercom, Inc.
  • Mailgun Technologies, Inc.
  • MaxMind
  • Metrics Enterprises, Inc. (Kissmetrics)
  • NG Communications bvba
  • OpenAI, Inc.
  • Oracle America Inc.
  • Salesforce.com, LLC
  • Stripe
  • Teleperformance A.E.
  • Twilio, Inc.
  • Voxbone, S.A.
  • Zendesk, Inc.
  • Zoom Video Communications, Inc.

Dropbox has collected and disclosed the categories described [below] to trusted third parties in the preceding 12 months:

your real name, alias, unique personal identifier, or online identifier, and it could also include other personal information like your postal address, Internet Protocol address, email address, account name, profile picture or other similar identifiers

what you decide to store in your Dropbox account

identifying information about contacts that you’ve chosen to give us access to. It can also include identifiers such as a real name, alias, or email address

information relating to your use of the Services

device-specific information, such as an online identifier or Internet Protocol address, or geolocation data

all 15 comments

sorted by: hot top controversial new old
[–] 3 points 18 hours ago

I still have a dropbox account but it's empty. So you're saying I should fill it with AI generated memes? Slop to train the slop machine. Text documents that just say "Albuquerque, New Mexico" 10,000 times. Let's all poison the well.

  • source
  • [–] 18 points 6 days ago* (6 children)

    In my opinion, it is no longer suitable for private or confidential data of any kind.

    Really it never was. No centralized service is.

    I've even had Mega block my own access to files I uploaded (and didn't share) when it deems them to be copyright infringement, and files there are supposedly encrypted.

  • source
  • hideshow 6 child comments
  • [–] 11 points 6 days ago (1 child)

    Yeah, I have allways been suspicious of major companies that pretend to not be able to access the data you store on the servers.

    This is also why I don't understand why so many companies are abandoning on-prem infrastructure in favour of Microsoft 365.

    Sure, it may be cheaper and leaner for companies to just use 365, but you give up control and any real crisis options.

    OneDrive does have it's advantages, but it is just so damn annoying to troubleshoot.

    I absolutely prefer the old normal network drive approach.

  • source
  • parent
  • hideshow 1 child comment
  • [–] [S] 3 points 6 days ago (3 children)

    Surely a centralised service like Proton Drive which is zero access encrypted would be a good alternative, right? There's a difference between "encrypted (but we also have a spare key)" and "encrypted (not even we can access it)"

  • source
  • parent
  • hideshow 3 child comments
  • [–] 5 points 6 days ago (1 child)

    To be fair, a centralized service with your own layer of encryption on top is an option. Like Borg supports that. Not a real option for miscellaneous small file sharing or organization though, but there may be an OSS solution to that.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 6 days ago

    I don't know enough about that one to say, but if it's properly E2E than yes. But even then there's still the possibility that metadata might not be encrypted and the user could get banned for filenames, etc.

  • source
  • parent
  • [–] 2 points 4 days ago

    You guys are still using Dropbox?

  • source
  • [–] 6 points 6 days ago

    It would be a shame if people started using Dropbox to store their lemonparty photographs.

  • source
  • [–] 5 points 6 days ago (1 child)

    thank you for this summary. i was going to delete dropbox anyway but this was the kick in the ass i needed

  • source
  • hideshow 1 child comment
  • [–] [S] 3 points 6 days ago

    Same here… what prompted this research was an event that caused me some anxiety. I searched the keywords "sunshine" to find the song "walking on sunshine". I noticed it came up with health document PDF results and even photos containing sunbeams. I'm like wait… how did it find those files?! I was horrified and went to check their privacy policy, only to become even more horrified lol

    I've been dragging my feet migrating out of Dropbox but now I need to get out ASAP. Really lit a fire under me. 10 year paying customer btw

  • source
  • parent
  • [–] 1 point 6 days ago* (2 children)

    Yeah I mean I would simply assume as much about literally any modern corporate product. Because 99% of them are and have been doing this for a long time. And no one cares.

  • source
  • hideshow 2 child comments