On 27.03.13 17:38, Winston Bowden wrote:
Hello,

I’d like to make you aware of a new feature the engagement team is working on 
and request feedback on proposed updates to the privacy policy.

The feature will allow us to provide users with a snippet (a message on their 
Firefox home page) based on the country they’re in. We’ve worked with several 
Mozilla departments to develop this feature.  Privacy, legal, product, web dev, 
security and IT have provided valuable feedback to ensure this was implemented 
in a way that maximizes the user value.

What is the snippet?
If you haven’t changed your start page on Firefox desktop, you’ll see an icon 
and a few lines of copy underneath the search box.  We call these messages 
snippets.  Snippets are a feature of the Firefox start page that provide users 
with timely and relevant information on how to get more out of their Firefox 
experience.

How is the snippet changing?
Currently there isn’t a reliable way to communicate with ours users based on 
their country.  For instance, if we need to rally around an important cause in 
Brazil, we don’t have the ability to reach out to those users.  The current 
system can send a message based on build (channel +  language), but builds 
reach users around the world rather than a specific country.

Here are some specific use cases where this service will be used:

Community:
We’ll now be able to broaden our community base in countries by announcing 
regional Mozilla events or opportunities to get involved with the project.  If 
we’re holding a special event in Brazil, we’ll be able to alert that user base 
quickly and easily.
Policy:
If and when Mozilla needs to rally against legislation like SOPA in countries 
outside of the U.S., we’ll have the ability to reach the users that will be 
impacted and exclude those who aren’t.
Firefox OS:
With the launch of Firefox OS and Marketplace, there are many opportunities to 
provide users with content that is relevant to their region.  For example, as 
phones become available in certain countries, we’ll have the ability to inform 
those users.

What’s the technical change?
Currently, snippets are delivered based on the build (channel + language) the 
user has downloaded.   This can be problematic if we’re trying to talk to users 
in a specific region or country.  For example, if you’re on the en-us build in 
Japan, you’re going to see the EN snippets.   We’re limited in terms of 
delivering relevant content and information to our user base.

How it will work:

- Mozilla will use a geo location service that is internally hosted.  We 
purchased a license to a database and serve it from Mozilla servers using a 
custom service we’re developing.  The database is specifically designed to 
return the country of origin for a given IP address.

- Once a month, when the user opens the about:home page, Firefox desktop will 
send the browser’s IP address to this internal service, and the service will 
return the name of the country the user is located in.  The browser will store 
the country name in localStorage.  Note that it is the actual country name that 
is being stored – NOT the IP address.  The IP address is not stored after 
country is established on either the client or server.

This is a privacy friendly implementation:

- Mozilla does not store the country location of a user to provide this feature
- IP addresses are collected as a part of standard web connections. The country 
information is maintained in HTML5 localStorage on the user’s Firefox. The 
result of a lookup – a particular IP and country – are not stored in the same 
place, ever.
- We will be updating our privacy policy.  Proposed changes are included below 
for your comments.
- If users change their default homepage, the snippet service, including this 
function, will be disabled.

We’ll be updating the section dealing with snippets to:

Our proposal for updating the privacy policy:

--------------------

Firefox's default home page (<about:home>) loads snippets of info that we think 
will be useful to you. Snippets are designed to provide you with timely and relevant 
information on how to get more out of your Firefox experience. You can see them right 
below the search bar.

Once per day, Firefox gets new snippets from Mozilla. Whenever you see a 
snippet, that snippet makes a request to Mozilla, so that we can count how 
often snippets are viewed.  This request to Mozilla sends the name of the 
snippet and is securely transmitted over HTTPS. Aside from this and standard 
log data collected as a part of any web request, snippets in Firefox does not 
send other information to Mozilla.

To help display relevant snippets, your Firefox browser sends Mozilla a monthly 
request to resolve your location at a country level using your IP address. We 
then send that country level information back to your Firefox browser, where 
it's stored in HTML local storage. Your Firefox browser (not our web servers) 
will then pick snippets to show you based on the locally stored country 
information.

Aside from providing you with the snippets service, we use the information from 
these requests to estimate what fraction of Firefox users click on each 
snippet, and we break down this info into general categories like Firefox 
version and geographic area. We will not use any of the information in this 
request to attempt to identify you or your activity anywhere else online, and 
we aggregate the info we receive into these general categories as soon as is 
practical.
You can turn off Snippets by following the instructions here: https://support.mozilla.org/en-US/kb/How%20to%20set%20the%20home%20page.

--------------------

Thanks for your feedback-
Winston Bowden

I have some implementation questions, too, where's the best place to discuss those? m.d.a.firefox or firefox-dev, or some other forum?

On to the actual privacy policy: I think there's a host of jargon and technical detail in that part. I'm afraid that's not all that human-readable, in particular for non-technical audience who's not native English speaker.

Much of that is already in http://www.mozilla.org/en-US/legal/privacy/firefox.html, but I'd prefer to make things better. If we could reword it to just not say "snippet" at all, for example.

Example of too much detail: does is really matter if the region is stored in HTML local storage instead of just stored locally?

Axel
_______________________________________________
governance mailing list
[email protected]
https://lists.mozilla.org/listinfo/governance

Reply via email to