How private is user personal non encrypted data with Ente? Findings in privacy policy

I created a post yesterday mentioning situation between Ente and other service that took place some time ago. I am specifically not using the name of this other service because for some reason my yesterday’s post has been removed and marked as “Spam” since it “feels it is an advertisement, something that is overly promotional in nature instead of being useful or relevant to the topic as expected”.

So I am making a new post now that hopefully is “useful and relevant”.

But I need to give some context first: Let’s call it “service A” recently started working on improving their photos and this created a whole new “discussion” on other forum. In my yesterday’s post I gave a summary of what is going on, how people are reacting and what they found. I double checked everything before I posted links and screenshots. Ok, straight to the point:

There is information in Ente’s privacy policy about non encrypted data that Ente collects, like email addresses, IP, logs, device identifiers, other personal information and more:

How Ente uses it:

" a. Disclosure to provide our Services: We will disclose personal information (i) to fulfill the purpose for which you have provided it, and (ii) to enforce or apply our Terms and other agreements, including for billing and collection purposes

b. Disclosure provided by law or for protection: We will disclose personal information (i) to comply with any court order, law, or legal process, including to respond to any government or regulatory request, or (ii) if we believe it is necessary or appropriate to protect the rights, property, or safety of Ente, our customers or others.

c. Disclosure in the event of merger or sale: We may disclose personal information in the event of a merger, sale of business, etc. "

Then when you scroll down there is info about who is Ente 3rd party providers meaning who they can share personal user information with:

Apple, Goolge, Amazon, Anthropic, PayPal, BitPay, Wasabi, Zoho, Stripe, Hugging Face, Grafana, Open Street Maps, Stadia Maps, PostHog, Postmark, Hetzner, BlackBlaze, Scaleway, Cloudfare.

Link to Ente privacy policy:

So my question is, how private is user personal non encrypted data with Ente?

Also, a big request to the mods: if you still feel that this is promotional, please send me a message explaining what changes I need to make before removing the post completely. I’m happy to cooperate.

3 Likes

As is always the case, not at all. It can be lawfully demanded by governments which Ente must comply with and it is totally exposed to rogue employees.

That can be ok though as what Ente collects is minimal and clearly disclosed. As is the case for any service recommended by PG’s.

It’s important to remember that privacy is never really protected by policy. It is protected by technical solutions.

The ultimate digital truth is: If you do not own the encryption keys for a piece of data, then you don’t own the data.

6 Likes

It seems to me that they collect too much data to be included in the PG recommendations. This is particularly dangerous for a jurisdiction such as the United States.

1 Like

I would prefer that the sentry.io be opt in not opt out but they do self host it iirc.

Just so you know, Ente main office and developers are based in India. Yes, it has virtual address in US but the main operation takes place in India, so technically jurisdiction is US and India.

It is from my understand that if we are using their products combined with a VPN some of this is mitigated.

I only use their multifactor authentication app, I guess they might know the time my email access their app. Which is annoying but probably won’t be the end of the world for my threat model.

This is a good reminder that I could do better reading privacy policies. I had no idea about this.

I’m really interested in Anthropic, Hugging Face and PostHog, I’d like to know exactly what data Ente shares with these.

2 Likes

I asked Vishnu on Discord and this was his response

Some of our support interactions are piped to Claude to augment Home | Ente Help

I think hugging face is used to download models for Ensu, not sure about PostHog. I think they self-host it. It’s probably for crash reports and you can disable it.

Honestly this post makes it seem like Ente shares all your information with these companies. It doesn’t. For example it says Google because Ente is on the playstore. Most of these companies Ente shares data with are not in their control. They likely use many of these platforms for running Ente. Technically your data is being shared with them but everything is E2EE.

I think they just list them for legal reasons. They also clarify what is being shared in the privacy policy. Everything seems reasonable to me.

5 Likes

I don’t know, you see Ente collets not E2EE users data too. Hugging Face was hacked recently so it would be good to know what they have.

1 Like