Starter questions on “personal data”

In light of recent controversies with personal data unknowingly being uploaded and/or shared, it’s good to take a moment to revisit some basics, which may make or break your relationship with a user, beyond the “pretty pixels” and “smooth usability”. At the end of the day, trust is the foundation for a healthy customer relationship and user experience. Once that goodwill has been earned, you don’t want to break it…

** First ask yourself if you really need such personal data in order to deliver your value prop to the user. Is it a “make or break” issue, really?

** What data are you planning to upload from the user’s device, and WHY? How will having that data lead to positive benefits for the user, thus amplifying your value prop? You want to make sure you’re building a strong customer relationship that lasts a long time!

** If you are uploading the user’s data: What types of data? How much? At what frequency? Is it encrypted? Where is it being stored? Is it being backed up? Can law enforcement agencies access it, and under what conditions? Is there a time limit? Will data be expunged sometime? What happens when the user dies (not just account deleted)? Is personal data being sold for profit? (sorry, gotta ask and just be honest with yourself…you’ll thank me in the morning!)

All of this must be captured like typical business requirements, with full unanimous agreement among product leads, and presumably reviewed by your company’s legal counsel. (I’m not a lawyer, but that’s my hunch, to protect everyone)

** Always err on the side of “Opt-in” first, not “Opt-out”. Make the user decides to opt-in; don’t assume the user is comfortable having their data silently uploaded without consent. Users don’t want an unpleasant surprise that their data was sent without their consent. A great way to break a relationship and lose trust, guaranteed!

** And most critically: Is this all explained up front, in clear language to the user so they can read it, understand it, and take action against it, easily, if they so desire?

Finally, just because you can detect and store certain personal data (due to the way iOS or Android technologies work, and their App Store policies), doesn’t mean you should. And please, don’t use “the other kids are doing it” excuse or “it’s been like this for years”. What are you, a 3 year old? No, you’re (hopefully) a legit business with an amazing vision, and a responsibility to your users and stakeholders.

Always ask yourself what’s your true motive, goal, and benefit to the user regarding data policies. Be honest with yourself. Be transparent and let users know.

Is there another way to deliver value to customers without accessing their personal data? If not, consider making those features that require personal data “premium features” at a micro-payment scale or subscription service. Again, be very clear about your intentions with the data even if the user is paying for that level of use.

Hopefully these starter questions around data-sharing policies will put your team and company on the “happy path” of positive relationships and good user experience overall with your user base!

Intimacy and arrogance in UX

Think for a second. What’s the most private, intimate information on your phone? Well, ok you got your photos from last night’s wild ragin’ party (I won’t go there ;-) but other than that? For me, it’s my address book, a compilation of phone numbers and email addresses of cherished loved ones (parents, family, close friends) and folks who have information of a deeply intimate nature (my primary care doctor, tax accountant, insurance agent for starters…). That is, people with whom I have a veritable trust-worthy relationship of varying degrees of familiarity, including valued co-workers and maybe a few acquaintances via conferences. That’s the key word here: trust. There is a presumptive 2-way street of confidence, reliability, assurance, and social agreement that we “trust each other” with our information and the relationship that info suggests and implies, from a fun Sunday 9 am chat in our pajamas, to that urgent midnight call about a health or financial emergency.

Now imagine a social networking company, with a beautiful slick whimsical interface that breathes a sigh of relief from the confusions of Facebook, but it’s snarfing up that very trust-based information without your knowledge. Without your consent. You don’t have to imagine, because it’s real and was accidentally discovered by a curious developer as reported on The Verge here. The culprit is Path. A startup whose v1 garnered lots of inside-the-Valley interest but didn’t really explode onto the scene until v2 with a nicely redone interface and modified focus, becoming a personal diary for sharing with your “real friends” (as a presumably nice subset of the hundreds via other networks…ok, THE network, aka Facebook :-). Now it seems the wonderful user experience and brand affiliation of Path have been utterly tarnished, with a supreme violation of trust of the very intimate information on my personal device, by uploading the ENTIRE address book of my iPhone to their servers. Why? For what purpose? Who knows. They clearly don’t need to do so, as the app can simply “view” into my contacts list (aka Address Book) to identify “friends” that I can add to my Path for sharing. But why copy that info it to their servers? Seems unnecessary and…frankly arrogant, or perhaps just flat out stupid.

Ultimately, it just makes me wonder who was the fucking douchebag(s) that decided that copying this kind of sensitive information was a) necessary b) justifiable and c) unimportant to let users know it was even happening. I don’t mean the actual names of the people, but the roles and positions. What was the nature of the conversation tucked away in some conference room? Or maybe there was no discussion–even scarier! Yikes. Just a set of silent consensual assumptions that this was all permissible …This is the glaring arrogance of young eager feisty start-ups driven to impress and “get to the market”. To believe that whatever they think (or not-think) and decide is somehow good for everyone…oh, and by the way, it’s not an issue anyway, so just keep using our app, right?

Trust is an absolutely fundamental element of a user’s experience and core to the creation of a viable customer relationship, even the business model itself, embedded in the value proposition. Yes, trust is a cornerstone of the business. It ensures a healthy customer – provider connection with positive multiplier and viral effects. Trust is infectious as “good word of mouth” spreads, and transactions increase, usage grows, value is augmented. It’s a virtuous cycle.

But just as infectious is distrust. A violation of the customer’s sense of identify, privacy, and of their own dignity. But especially their sense of pride in a brand they enjoyed and believed in and defended, trying to persuade friends to participate and join in. All of that gets eradicated in a few seconds. The “path” from success to disaster is a quick and easy route. And this saddens everyone, including it’s fan base of faithful users.

It’s high time such hungry young firms pause for a minute, take a breath from their “barbarians at the gate” mentality rushing out the door, and carefully reflect upon the principles and values that enable a good design, product, and experience: trust, dignity, respect, and pride. Recall Dieter Rams, the pursuit of what is ethical and aesthetic. What’s the balance between using a customer’s data versus preserving a sense of caution and judiciousness. Where’s the line between rushing to do bold things and wariness of the risks against people’s privacy and security. Because once you go over that edge, there’s no coming back, period. That’s when the company’s true values are exposed for what they really are. That’s when users know who you are, and trust me, it won’t be forgotten.

Living the Cloud (talk notes)

I recently attended a couple of events in SF pertaining to “cloud computing” and “designing business models”. Below are my notes…

Smart Salon: Living in the Cloud

This panel discussion (featuring folks from Sugar Sync, Autodesk, and Smart Design) was held as part of Smart’s regular salon series in their SF studio. Interesting thoughts and questions around the ambiguous buzzword of the moment, “cloud”. No real answers per se, but as a fellow Citrix attendee said, it’s good to know we’re all at the same starting point of lacking clarity and concrete solutions and answers. Yep, many issues and questions…

* Quite simply, “the cloud” is just “the internet”, from a typical consumer POV
* From IT admin/back-end POV it’s a server farm with constant high availability and stability and (ahem) security
* Going deeper, it’s a connected set of services, structures, processes that should (ideally) be a pervasive enabler of working/playing/studying/doing anything with your data at anytime, from anywhere, on any device, as a fluid seamless experience. The key concept is being “connected” to the data servers via wireless internet or cellular or whatever transmission tech.
* The “cloud” metaphor should hide the complexity of systems and transactions, being something “grokkable” by ordinary masses (but do they really need to know about it at all…beyond the advertising buzz?)
* Security and Privacy are major issues for consumers to trust their data “in the cloud”, without feeling taken for a ride. How to convey this in clear, easy language? How to balance the data storage, with data efficiency, processing speed/power, user accessibility, etc.
* Also challenges of “where is my data” when it’s “out there”…layers of place, locality, navigation, positional knowledge. Leads to trust impacts too.
* How can we support graceful degradation of cloud abilities across legacy devices and platforms? Reduced feature sets and abilities, etc.
* Some discussion around “hybrid experiences”: a combination of local storage and content stored elsewhere, to help transition folks not used to cloud or provide local confidence in cloud-based data