To be honest, these companies already stole terabytes of data and don't even disclose their dataset, so you have to assume they'll steal and train at anything you throw at them
  • nbulka
  • ·
  • 21 minutes ago
  • ·
  • [ - ]
No you don't. You don't have to assume people are going to be bad! We should not normalize it either.
You don't have to assume people are going to be bad, but it's reasonable and prudent to expect it from people who have already shown themselves to be so (in this context).

I trust people until they give me cause to do otherwise.

  • nbulka
  • ·
  • 9 minutes ago
  • ·
  • [ - ]
Training on personal data people thought was going to remain private vs. stuff out in public view (copyright or not), are two different magnitudes of ethics breaches. Opt OUT instead of Opt IN for this is CRAZY in my opinion. I hope that the reddit post is WRONG on that detail but I seriously doubt it.

I asked Claude: "If a company has a privacy policy and says they will not train on your data and then decides to change the policy in order "to make the models better for everyone." What should the terms be?"

The model suggests in the first paragraph or so EXPLICIT OPT IN. Not Opt OUT

"Reading stuff freely posted on the internet" constitutes stealing now?

Seems like an excessively draconian interpretation of property rights.

I'm not talking about that, I'm taking about downloading gigabytes of books, and movies and who knows what data (since it's not disclosed) without paying. Those are not freely posted on the internet. Well, not legally anyways.
"Reading stuff freely posted on the internet" is also very different from a business having machines consume large volumes of data posted on the Internet for the purpose of generating value for them without compensating the creators. I'm not making a value judgement one way or the other, but "reading stuff freely posted on the Internet" is an oversimplification.
Okay, but "stealing" is also an oversimplification, to the point of absurdity.

It makes no sense to put stuff up on the internet where it can freely be downloaded by anyone at any time, by people who are then free to do whatever they like with it on their own hardware, then complain that people have downloaded that stuff and done what they liked with it on their own hardware.

"Having machines consume large volumes of data posted on the Internet for the purpose of generating value for them without compensating the creators" is equally a description of Google.

  • ehnto
  • ·
  • 51 minutes ago
  • ·
  • [ - ]
They are not free to do whatever they like, there are tomes of laws across all countries governing what someone can and cannot do with your intellectual property. Just because we didn't have the foresight to add in a "if by chance in the future someone invents artificial intelligence, that's not fair use" is a shame, but doesn't make what these companies are doing ethical or morale.

I don't disagree regarding Google, I also think they exploited others IP for their own gain. It was once symbiotic with webmasters, but when that stopped they broke that implied good faith contract. In a sense, their snippets and widgets using others IP and no longer providing traffic to the site was the warning shot for where we are now. We should have been modernising IP laws back then.

I did say "free to do whatever they like on their own hardware", because intellectual property laws generally govern the transfer of such property rather than the use.

After seeing the harm done by the expansion of patent law to cover software algorithms, and the relentless abuse done under the DMCA, I am reflexively skeptical of any effort to expand intellectual property concepts.

  • bdamm
  • ·
  • 52 minutes ago
  • ·
  • [ - ]
We didn't seem to mind when Google was doing it back in 1999, or Lycos, Altavista, etc before them... why do we care about the LLM companies doing it now?
  • nbulka
  • ·
  • 21 minutes ago
  • ·
  • [ - ]
Because they have terms of service they have to adhere to. We need laws to be lawful.
I find LLMs extremely useful but I think the difference is that they regurgitate the content (not verbatim) instead of a link to it. This is not unlike how a human might tell their friend about it.
> This is not unlike how a human might tell their friend about it.

Is there someone who has read the whole internet? Can we all be there friend?

The entire basis of fair use is scale matters.

  • timeon
  • ·
  • 59 minutes ago
  • ·
  • [ - ]
What "reading"?
The same reading search engine crawlers have been doing since time immemorial.
  • ehnto
  • ·
  • 31 minutes ago
  • ·
  • [ - ]
No one gave them permission to access their webservers back then either. Before it's cited that there is precedent in law, that is in the US. No such precedent exists in my country, and our laws suggest that unauthorized access regardless of "gates up or down" would constitute trespassing. There are also no protections for scrapers coming out of prior lawsuits, and copying copyrighted material is of course illegal.

Which is just to point out that the world wide web is not its own jurisdiction, and I believe AI companies are going to be finding that an ongoing problem. Unlike search, there is no symbiosis here, so there is an incentive to sue. The original IP holders do not benefit in any way. Search was different in that way.

Search engines never claimed that their content was orignal, and redirect to the original author (which gets proper retribution)
Looking at and gaining knowledge.
This going to turn into one of those situations where we find out they trained on everyone whether they opted-out or not down the line. I want to keep using Claude, but I also don't want all the solutions I come up with to become common knowledge.
  • ukd1
  • ·
  • 24 minutes ago
  • ·
  • [ - ]
I think I'm fine with the whole getting better due to something helped it / co find with it. I'm not happy if it's directly 1:1 or attributed to me - chatham house rule for this would be great.
When has a company ignored an opt-out preference before? It sounds like you have something in mind.
  • treyd
  • ·
  • 49 minutes ago
  • ·
  • [ - ]
Why don't you want to share your insights? I agree doing it in a more direct way would be better than it leaking through AI training you don't control. But your phrasing seems stronger than that.
Am I the only one that assumed everything was already being used for training?
The hardest problem in computer science in 2025 is convincing people that you aren't loading every piece of their personal data into a machine learning training run.

The cynic in me wonders if part of Anthropic's decision process here was that, since nobody believes you when you say you're not using their data for training, you may as well do it anyway!

Giving people an opt-out might even increase trust, since people can now at least see an option that they control.

> The cynic in me wonders if part of Anthropic's decision process here was that, since nobody believes you when you say you're not using their data for training, you may as well do it anyway!

This is why I love-hate Anthro, the same way I love-hate Apple. The reason is simple: Great product, shitty MBA-fueled managerial decisions.

I don't understand this mindset. Why would you assume anything? It took me a couple minutes at most to check when I first started using Claude.

I check when I start using any new service. The cynical assumption that everything's being shared leads to shrugging it off and making no attempt to look for settings.

It only takes a moment to go into settings -> privacy and look.

>Why would you assume anything?

Because they already used data without permission on a much larger scale, so it's a perfectly logical assumption that they would continue doing so with their users?

Huh, they’re not assuming anything is “being shared”.

They’re assuming that Anthropic that is already receiving and storing your data, is also training their models on that data.

How are you supposed to disprove that as a user?

Also, the whole point is that companies cannot be trusted to follow the settings.

A silicon valley startup would never say one thing and then do another!
> It only takes a moment to go into settings -> privacy and look.

Do you have any reason to think this does anything?

Jira ticket Nr 97437838. Training service ignores settings, trains on your data anyway. Priority: extremely low. Will probably do it in 2031 when the intern joins.
  • nbulka
  • ·
  • 52 minutes ago
  • ·
  • [ - ]
!!!!!!!!!! this... all the times HIPAA and data privacy laws get ignored directly in Jira tickets too. SMH
This. It's the same innocence of people who believe when you delete a document on Google/META/Apple/Microsoft servers, it "really" gets deleted. Google most likely has a backup of every piece of information indexed by them in the last 20 years or so. It would cause envy to the Internet Archive.
With the privacy laws out there, I do genuinely think they eventually get purged even from backups. I remember there being a really cool YouTube video shared here on HN that google no longer has publicly, it was about the process of an email and all the behind the scenes things, like physical security into a data center, to their patented hard drive shredders they use once the hard drives are to be tossed. I wish Google had kept that video public and online, it was a great watch.

I know once you delete something on Discord its poof, and that's the end of that. I've reported things that if anyone at Discord could access a copy of they would have called police. There's a lot of awful trolls on chat platforms that post awful things.

> I know once you delete something on Discord its poof, and that's the end of that. I've reported things that if anyone at Discord could access a copy of they would have called police. There's a lot of awful trolls on chat platforms that post awful things.

That's not what Discord themselves say, is that coming from Discord, the police or someone else?

> Once you delete content, it will no longer be available to other users (though it may take some time to clear cached uploads). Deleted content will also be deleted from Discord’s systems, but we may retain content longer if we have a legal obligation to preserve it as described below. Public posts may also be retained for 180 days to two years for use by Discord as described in our Privacy Policy (for example, to help us train models that proactively detect content that violates our policies). - https://support.discord.com/hc/en-us/articles/5431812448791-...

Seems to be something that decides if the content should be deleted faster, or kept for between 180 days - 2 years. So even for Discord, "once you delete something on Discord its poof" isn't 100% accurate.

At least in terms of reporting content to "Trust and Safety" they certainly behave like its gone forever. I have had friends report illegal content, to both Discord and law enforcement, the take away seemed like it was gone, now it's making me wonder if Discord is really archiving CSAM material for two years and not helping law enforcement unless a proper warrant is involved, yikes.
> now it's making me wonder if Discord is really archiving CSAM material for two years and not helping law enforcement unless a proper warrant is involved

Yes, of course, to both of those. Discord is a for-profit business with limited amount of humans who can focus on things, so the less they can focus on, the better (in the mind of the people running the business at least). So why do anything when you can do nothing, and everything stays the same? Of course when someone has an warrant, they really have to do something, but unless there is, there is no incentive for them to do anything about it.

My understanding is that for Gmail specifically, they keep a record of every email ever received regardless of deletion status, but I'm not able to find any good sources.
Even if Google are not storing it, we can sleep safely as NSA's PRISM V2 probably got an archive of it too :) Albeit hard to acquire a dump of those archives, for now at least...
Officially, up to you if you believe they are following their policies, all of the companies have published statements on how long they keep their data after deletion (which customers broadly want to support recovery if something goes wrong).

- Google: active storage for "around 2 months from the time of deletion" and in backups "for up to 6 months": https://policies.google.com/technologies/retention?hl=en-US

- Meta: 90 days: https://www.meta.com/help/quest/609965707113909/

- Apple/iCloud: 30 days: https://support.apple.com/guide/icloud/delete-files-mm3b7fcd...

- Microsoft: 30-180 days: https://learn.microsoft.com/en-us/compliance/assurance/assur...

So if it ends up that they are storing data longer there can be consequences (GDPR, CCPA, FTC).

  • toyg
  • ·
  • 2 hours ago
  • ·
  • [ - ]
TBH, I'd be surprised if they kept significant amounts around for longer, for the simple reason that it costs money. Yes, drives are cheap, but the electricity to keep them online for months and years is definitely not free, and physical space is not infinite. This is also why some of their services have pretty aggressive deletion policies (like recordings in MS Teams, etc).
Same, I thought the free accounts were always trained on. Which in my opinion is reasonable since you could delete the data you didn’t want to keep on the service.

But including paid accounts and doing 5 year retention however is confounding.

I mean, I am sure there are individuals, who still believe in the basic value of the word within the framework of our civilization, but, having seen those words not just twisted beyond recognition to fit a specific idea, but simply ignored when they were no longer convenient, it would be a surprise now that a cynical stance is not more common.

The question is: how does that affect their choices. How much ends up being gated what previously would have ended up in the open?

Me: I am using a local variant ( and attempting to build something I think I can control better ).

You wouldn’t have needed to assume if you had read their previous policy.
Nope. I always assumed they were and acted accordingly.
You are not.
  • aatd86
  • ·
  • 59 minutes ago
  • ·
  • [ - ]
I don't know what they've been training on but I just canceled claude for the second time. Besides the numerous UI bugs of the web interface, incessant flickerings, it has gotten weirdly super condescending and negative in a way I hadn't observed neither in the past nor with other llms.

Probably that people accused it of being sycophantic and they have tried to adjust it but they dodn't do it well. It rather criticize and make assumptions about my behavior rather than keeping it technical. Ha!

I prefer gemini. Seems a bit stressed always assuming that I might be frustrated by its answers which is also weird to assume vut it is not straight disrespectful at least.

So I am back to testing chatgpt. I keep changing.

  • novok
  • ·
  • 29 minutes ago
  • ·
  • [ - ]
They need adjustable dials like they do in some API interfaces for power users. Like a sycophancy dial, a safety dial or "turn off the child lock permanently" like they have for microwaves.
Unbelievable. This is on par ethically with bad Meta decisions as far as privacy is concerned. What a dark pattern! What a mess! Look at this botched rollout... It's not ok to do this folks. This is literally what the modal looked like for me on chats that were already in progress. And NO I did not want them to train on this or ANY OF MY DATA UNDER A DIFFERENT CONTRACT.

Anthropic PR: "Ma'am, you opted IN to training on your therapy sessions and intellectual property and algorithms and salary and family history!" Don't you remember the modal???

The Modal: https://imgur.com/afqMi0Z

Modern AI is built on data. Trusting that our conversations will not be used for training the model is a bit like giving a glutton their favourite food but making them promise not to eat it. Sure, why not.

I still expect that our conversations will not leave the premises (ie end up on the internet), because that would be something else, but other than that, I knew what I signed up for.

  • nbulka
  • ·
  • 22 minutes ago
  • ·
  • [ - ]
Don't normalize this. There are contractual obligations that we have to enforce in order to keep our privacy and humanity.
I just logged in on the iOS app and it immediately had a popup giving me the option to opt-out.

So yeah, annoying, but they handled it well.

So, I guess they run out of data to train on ...

I wonder on how much they can rely on the data and what kind of "knowledge" they can extract. I never give feedback and most time (let's say 5 out of 6) the result cc produce it simply wrong. How can they know the result is valuable or not?

Maybe they can use same method as Google does - if user clicked a link and didn't try to search again, it can assume the link had intended result.

So your silence can be used as a warmish signal that you were satisfied. (...or not. Depends on your usage fingerprint.)

  • rurp
  • ·
  • 53 minutes ago
  • ·
  • [ - ]
I expect that's a very weak signal. When I ask a question and get a completely wrong answer from Claude I usually drop the chat and look elsewhere.
How can they know anything they train on is valuable?

At the end of the day it doesn't matter. You got the wrong answer and didn't complain, so why would they care?

  • nbulka
  • ·
  • 59 minutes ago
  • ·
  • [ - ]
For those who do not, or cannot, read this announcement prior to September 28th (think people in the hospital, traveling, missed an email ..) is this not a total breach of contract?

Legally, I don't understand how Anthropic's lawyers would have allowed this. Maybe I am just naively optimistic about these matters? I am a Max customer and I might leave! Talk about a "rug pull" ... and I considering moving to an inferior provider! Privacy is a fundamental human right. Please do better, we have not learned our lesson in tech or society because no one is facing any consequences.

I always assumed they were. I've been masking / scrubbing my test data this whole time.
At least this submission has the original text Anthropic sent out to people :) But yeah, Perplexity gives a better summary for outsiders I guess.
I kind of already assumed they were. I've got some pretty niche use-cases that I'd like to see the models get better at thinking their way through. I benefit from their training on my interactions. So I'll opt in. But I'll also recognize that others might not feel that way, so the services should provide a way for users to opt out.
$COMPANY reneged on their solemn pinky promise to not do the bad thing this time? Quelle surprise!
  • ·
  • 5 hours ago
  • ·
  • [ - ]
I have never input anything into one of these tools that I wasn’t entirely comfortable with them using for training or any other reason. I just assumed it was happening.
Criminal, evil thieves.
"If you use Claude for Work, via the API, or other services under our Commercial Terms or other Agreements, then these changes don't apply to you."
This is what I don't get. It's so much simpler to use the LLMs with other tools (aider for me) that I don't understand why people are avoiding the API creating monthly accounts to begin with. Is it cheaper? Is Claude Code really that awesome or something? By not even looking at it I guess I never have to know, but from where I sit it seems like people are just putting themselves through a lot of b.s. in order to marry a start-up.
> Is it cheaper?

"ccusage" is telling me I would have spent $2010.90 in the last month if I was paying via the API, rather than $200.

But also I do feel Claude Code is quite a bit better than other things I've used, when using the same model. I'm not sure why though, it's a fairly simple program with only a few prompts and only a few tools, it seems like others could catch up immediately by learning some lessons from it.

Daaaaamn that makes a lot of sense then. For my limited use it doesn't add up but clearly the more deeply embedded the tool is the more it makes sense.
According to Claude cost I get about 5x value in token cost by having a max subscription.

I upgraded after I hit the equivalent spend in API fees in a month.

..and there goes our authorization to use it at work
I use AI to solve problems, not to check the weather or deciding what to wear. As such it makes sense for AI to remember when it hits the nail on the head.
Agreed. Typically I would be against something like this, but in this case, have it.
How do you feel about this data being used to target advertising at you in the inevitable rush to monetize these AI products?
I feel like that’s annoying, but it’s a drop in the bucket vs the current firehose of ads, and there’s a slim shot these ads might actually be interesting or relevant to me.

Anyway, I’ll block them like I do everything.

Oh, sweet summer child, your SOLUTIONS will be trained on and will be given to others without your permission and knowledge.

But now that you bring up ads, I guarantee you that those will somehow be incorporated in Claude soon.

And if you solve a novel problem, Claude will happily take your reasoning and give it to the next user trying to solve the same novel problem. Imagine if that was a guy working for the competition :)
i logged on and they did ask right away in a popup window.
isn't this just a change from opt-in to opt-out? will make a big difference but still gives individuals control of their data governance
  • hkon
  • ·
  • 5 hours ago
  • ·
  • [ - ]
With the amount of times Claude is visiting my websites I'd say they are very desperate for data.
I can understand training AIs on books, and even internet forums, but I can't help but think that training an AI on lots of dumb questions with probably an excessive amount of grammar and spelling errors will somehow make it smarter.
Depends on how you’re using the data. There’s a pretty strong correctness signal in the user behavior.

Did they rephrase the question? Probably the first answer was wrong. Did the session end? Good chance the answer was acceptable. Did they ask follow-ups? What kind? Etc.

I'm used to doing the same task 4 or 5 times (different sessions, similar prompts), and most of the time the result is useless or completely wrong. Sometimes I go back and pick the first result, other time none of them, other time a mix of them. I'm wondering how can they extract value from this.
> Did the session end? Good chance the answer was acceptable.

Or that the user just ragequit

They train AI on Reddit and Stack Overflow questions, I can't see it getting any worse.
> and even internet forums

i would consider internet forums also includes a lot of dumb questions

Agree, but people generally take a small pause before saying stuff online.

In 'private', people are less ashamed of their ignorance, and also know they can say gibberish and the AI will figure it out.

  • timeon
  • ·
  • 50 minutes ago
  • ·
  • [ - ]
Like what?
I’m fine with that.
you are fine with paying, 20, 90 or 200 euros a month AND having your data mined? i must be getting old...
It's a tool that dependson data mining everything. The only surprise is that they weren't already data mining what people feed into it.
what are you doing with the data? What is your legacy going to be other than the data that you leave to be mined? Do you just not want something else to benefit from something that has no benefit to you? If so, why?
There is a myriad of reasons i may not want my data to be used. Maybe I am working on proprietary systems, maybe I am using Claude as a psychotherapist, maybe I use it as a tax advisor, the list goes on. Is it unrealistic to think that data may be extrapolated and connected to me in the future?
Maybe I am working on proprietary systems, maybe I am using Claude as a psychotherapist, maybe I use it as a tax advisor, the list goes on.

Then use the business version.

lol wtf kind of reply is that? Maybe relevant for the proprietary system part. I guess you would be fine with a tax advisor or therapist charging you more for a "gossip free service" where they will not disclose your personal information if you just pay more.

To be clear, i don't use claude for any of those purposes, it's the principle i am talking about.

Oh and i forgot the most important thing, I am paying good money for this service, now they also mine my data? I grew up in a time where "if it's free, you're the product". I guess that's not even the case anymore, if you pay, you're still the product...
"going forward" ;-)
Rather misleading title. Missing the important “unless you ask them not to” part. Sounds like a bit of a dark pattern to push you into accepting it and that’s not cool, but you do get a choice.
  • gooob
  • ·
  • 5 hours ago
  • ·
  • [ - ]
and now the LLM gets to observe itself, heh heh heh
Maybe a value to users if done correctly. The way it is right now, you can't teach the model anything. When it gets something wrong, it will probably get the same thing wrong again in another chat.
That's not how LLMs work.
"Training" is now a euphemism for stealing. Guess I can't write any production level code w/ this...
Some people would say that since the owner isn't being deprived of anything, it's not stealing.
Title is misleading, they're now opt-out rather than opt-in to your data being used for training. All you have to do is flip a single switch in the options to turn it off, I don't understand why everyone is treating this as being such a big deal.

Edit: I just logged in to opt out, they presented me with the switch directly. It was two clicks.

[Edit: turns out I've got it wrong, and 5-year retention only said to apply to the data they're allowed to train on. This changes things for me.]

Personally, I don't mind training, as long as I have a say on the matter - and they have a switch for this. Opt-out is not exactly cool, but I've got the popup in my face, almost a month before the changes, and that's respectful enough for me.

This said, I've just canceled my subscription because this new 5-year mandatory data retention is a deal breaker for me. I don't mind 30 or 60 days or even 90 days - I can understand the need to briefly persist the data. But for anything long-term (and 5 years is effectively permanent) I want to be respected with having a choice, and I'm provided none except for "don't use".

A shame, but fortunately they're not a monopoly.

Data retention appears to be predicated on opting in to allowing training. If you don't opt in, they retain it for the same 30 days they were already retaining it for. https://www.anthropic.com/news/updates-to-our-consumer-terms
Oh! Thank you!

That popup was confusing as hell then, because I've read and understood it as two separate points: I've got it that they're making training opt-out, and that they're changing data retention to 5 years, independent of each other. I got upset over this, and haven't really researched into the nuances - and turns out I've got it all wrong.

Appreciate your comment, it's really helpful!

I hope they change the language to make it clear 5 years only applies to the chats they're allowed to train models on.

I think any switch from opt-out-by-default to opt-in-by-default sucks, especially when it has no clear immediate benefit to the person being opted in.

Disclaimer: not a Claude user (not even a prospective one)

> any switch from opt-out-by-default to opt-in-by-default sucks

It’s the reverse. This was opt-in and is now opt-out. Opt means choose so when “the default is opt-in” it means the option is “no” by default and you have the option to make it “yes”.

> they're now opt-out rather than opt-in to your data being used for training

This is what the comment I was replying to said. I took that to mean "you have to opt out (ie you're opted in by default)".

i think skepticism is healthy, but they've handled this in a fairer way than any other online product i've used before.

they gave me a popup to agree to the ToS change, but I can ignore it for a month and still use the product. In the popup, they clearly explained the opt-out switch, which is available in the popup itself as well as in the settings.

I don't think it's good, but people both here and on reddit are acting like this is some Great Betrayal when it's just a single switch that they prominently present to you. If they're going to make this change, this is exactly how I'd want them to do it.
> If they're going to make this change

Feels like the complaint is precisely that people don’t want them to make this change.

> this is exactly how I'd want them to do it.

Sees naive to believe it will always be done like this, especially for new users.

First off, I don't think going into the settings and flipping a toggle switch once is a huge burden on those who want to use a service privately. But more importantly, some of the comments here are so hysterical I have to assume that they read the title and jumped to the conclusion that you cannot opt out anymore without a business account.
No thats BS, lots of people wont know the default got flipped
Excellent. What were they waiting for up to now?? I thought they already trained on my data. I assume they train, even hope that they train, even when they say they don't. People that want to be data privacy maximalists - fine, don't use their data. But there are people out there (myself) that are on the opposite end of the spectrum, and we are mostly ignored by the companies. Companies just assume people only ever want to deny them their data.

It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.

This idea that "no one wants to share their data" is just assumed, and permeates everything. Like soft-ball interviews that a popular science communicator did with DeepMind folks working in medicine: every question was prefixed by litany of caveats that were all about 1) assumed aversion of people to sharing their data 2) horrors and disasters that are to befall us should we share the data. I have not suffered any horrors. I'm not aware of any major disasters. I'm aware of major advances in medicine in my lifetime. Ultimately the process does involve controlled data collection and experimentation. Looks a good deal to me tbh. I go out of my way to tick all the NHS boxes too, to "use my data as you see fit". It's an uphill struggle. The defaults are always "deny everything". Tick boxes never go away, there is no master checkbox "use any and all of my data and never ask me again" to tick.

> It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.

As we’ve seen LLMs be able to fully regenerate text from their sources (or at least close enough), aren’t you the least bit worried about your personal correspondence magically appearing in the wild?

If you have an API key for a paid service, would you be OK with someone asking ChatGPT or VS Code Copilot for an API key for that service and getting yours, which they then use to rack up bills that you have to pay?
The fact you are not aware of abuse, or abuse has not yet happened to you, does not mean it isn't a problem for you.

> The defaults are always "deny everything".

This is definitely not true for a massive amount of things, I'm unsure how you're even arriving at this conclusion.

Maybe in the US. In the UK, I have found obstacles to data sharing codified in the UK law frustrating. I'm reasonably sure some people will have died because of this, that would not have died otherwise. "Otherwise" case being - if they could communicate with the NHS, similarly (via email, whatsapp) to how they communicate in their private and professional lives.

Within the UK NHS and UK private hospital care, these are my personal experiences.

1) Can't email my GP to pass information back-and-forth. GP withholds their email contact, I can't email them e.g. pictures of scans, or lab work reports. In theory they should have those already on their side. In practice they rarely do. The exchange of information goes sms->web link->web form->submit - for one single turn. There will be multiple turns. Most people just give up.

2) MRI scan private hospital made me jump 10 hops before sending me link, so I can download my MRI scans videos and pictures. Most people would have given up. There were several forks in the process where in retrospect could have delayed data DL even more.

3) Blood tests scheduling can't tell me back that scheduled blood test for a date failed. Apparently it's between too much to impossible for them to have my email address on record, and email me back that the test was scheduled, or the scheduling failed. And that I should re-run the process.

4) I would like to volunteer my data to benefit R&D in the NHS. I'm a user of medicinal services. I'm cognisant that all those are helping, but the process of establishing them relied on people unknown to me sharing very sensitive personal information. If it wasn't for those unknown to me people, I would be way worse off. I'd like to do the same, and be able to tell UK NHS "here are, my lab works reports, 100 GB of my DNA paid for by myself, my medical histories - take them all in, use them as you please."

In all cases vague mutterings of "data protection... GDPR..." have been relayed back as "reasons". I take it's mostly B/S. Yes there are obstacles, but the staff could work around if they wanted to. However there is a kernel of truth - it's easier for them to not try to share, it's less work and less risk, so the laws are used as a cover leaf. (in the worst case - an alibi for laziness.)

If only you were just giving them your own data. In reality, you're giving them data about your friends, relatives, and coworkers without their consent. Let's stop pretending there is any way to opt out by simply not using these companies' services; it isn't true.
“Claude, please write and commit this as if you were ljosifov. Yes, please use his GitHub token, thank you”
  • p3rls
  • ·
  • 2 hours ago
  • ·
  • [ - ]
I think the real frustrating part is that they're using your data, scanning every driver's license etc that comes onto the google play store-- and there's still scammers etc using official google products that people catch everyday on twitter now that scambaiting is becoming a popular pastime.
This is a problem for folks with sensitive data, and also for coorporate users who don't want their data being used for it due to all kinds of liability issues.

I am sure they will have a coorporate carve out, otherwise it makes them unusuable for some large corps.