A report by the Wall Street Journal has revealed that third-party app developers can read the emails of millions of Gmail users.
Access settings for Gmail enable app developers and data companies to view people’s emails and private information. Time stamps, recipient addresses and even entire messages composed by users of the mail app are potentially subject to prying eyes.
Who Can Read Your Emails?
The Journal’s report specifically highlighted two apps; Return Path and Edison Software. The former is an app that analyses users’ mailboxes and collects data for marketing companies. At this firm, the newspaper claims, employees are alleged to have read around 8,000 emails in order to finetune and better develop the company’s software.
Edison – another inbox management app – also allowed employees to read thousands of emails over the course of several months as it developed its “Smart Reply” feature.
Now, it’s not exactly groundbreaking news that app developers had access to data. However, the concern should lie in users’ understanding of how their data is being accessed – a discussion we’ve heard repeatedly for the last several months – and the involvement of humans in the process.
Google claims it only gives data to third-party developers after obtained explicit consent from users. Vetting processes are strict and involve ensuring that a company must adhere to stringent guidelines. Additionally, Google’s privacy policy states that it will monitor emails and that the data being accessed will allow it to improve its service.
Google employees may also read emails, however, the company states this only happens in “very specific cases” where the user has given consent, or if the company is investigating security issues such as bugs, criminality or abuse.
Allowing Google employees access to emails for security purposes is one thing, but for third-party developers to allow employees is rather concerning. How much access does Google allow and do users have a complete understanding of what they were signing up for?
Privacy: 2018’s Hot Topic
Data privacy has been hot on the lips of technologists and media figures throughout 2018. Our relationship with data has changed and the organisations for whom it is a commodity have come under intense scrutiny for their lax attitude toward sharing it.
Last year, Google announced it would stop scanning emails for data to help marketing firms develop targeted ad campaigns. Since the Cambridge Analytica scandal erupted in March, people across the globe have become increasingly suspicious of data companies and social media giants. Has Google acted in an equally irresponsible manner though?
The two developers in question think not…
Company Policies
Both developers have defended allowing employees access to user emails, with Return Path stating in a blog post: “Any time our engineers or data scientists personally review emails in our panel (which again, is completely consistent with our policies), we take great care to limit who has access to the data, supervise all access to the data.”
Edison also defended its actions, telling the Journal: “Our email app was mentioned in the context of our engineers having in the past the ability to read a small random sample of de-identified messages for R&D purposes.
“This method was used to guide us in developing our Smart Reply functionality which was developed some time ago”.
CEO Mikael Berner claimed that the company has “since stopped this practice and expunged all such data in order to stay consistent with our company’s commitment to achieving the highest standards possible for ensuring privacy.”
This couldn’t have come at a worse time for Google, which is coming under increased pressure – both in the United States and Europe – to improve its privacy policies. While there is little evidence to suggest that third-party developers have misused data in a Cambridge Analytica-style free-for-all, allowing engineers to view thousands of emails appears to be intrusive in nature.





