Facebook will pull its data-collecting VPN app from the App Store over privacy concerns

Photo by Michele Doying / The Verge

Facebook will soon pull a mobile VPN app called Onavo Protect from Apple’s App Store, after the iPhone maker declared it violated the store’s guidelines on data collection, according to a report from The Wall Street Journal.

Onavo, which began as an Israeli analytics startup focused on helping users monitor their data usage, was acquired by Facebook in 2013. Its VPN provider then became a data collection tool for Facebook to monitor smartphone users’ behavior outside its core apps, helping inform Facebook’s live video strategy, competition from other social apps, and its decision to acquire companies including WhatsApp.

“We’ve always been clear when people download Onavo about the information that is collected and how it is used,” said a Facebook spokesperson in a statement given to The Verge. “As a developer on Apple’s platform, we follow the rules they’ve put in place.”

Apple did not forcibly pull the app, but it does seem to have pressured Facebook into removing it. According to the Journal, Apple informed Facebook earlier this month that Onavo Protect violated new privacy rules, implemented back in June, that restrict developers’ ability to create databases out of user information and sell it to third parties.

Onavo Protect also allegedly violated a part of the iOS developer agreement that regulates how app makers make use of data outside the core function of the software. Onavo Protect is a VPN service, and yet Facebook has been using the traffic routed through its private servers for broad analytic purposes. Apple was not immediately available for comment

According to the report, discussions between Apple and Facebook occured last week, and Apple suggested that Onavo Protect be voluntarily removed from the App Store. Facebook agreed, and the app is scheduled to be pulled later today. Users who have already downloaded Onavo Protect can continue using it on iOS devices, but Facebook will be unable to issue updates. The Android version of the app will remain in Google’s Play Store, WSJ notes.

Update 8/22, 6:58PM ET: Added statement from Facebook.

Comments

[Apple] declared it violated the store’s guidelines on data collection

Good on Apple.

The Android version of the app will remain in Google’s Play Store, WSJ notes.

Of course it will.

Would be a bit like the pot calling the kettle black, wouldn’t it?
To be clear, Apple do collect data about what apps are on your phone and how they are used but they do that to manage memory on the device and to advertising apps in the App Store. Google do the same but also use the data in their overall advertising profile and, of course, much of the in-app advertising is Google’s.

Small nit:

Apple was not immediately available for comment

This sentence is missing a period at the end.

Good move Apple.
No one should of trusted Onavo even before it was acquired by Facebook.

According to other tech blogs, Apple provided the following statement on the removal of Onavo:

We work hard to protect user privacy and data security throughout the Apple ecosystem. With the latest update to our guidelines, we made it explicitly clear that apps should not collect information about which other apps are installed on a user’s device for the purposes of analytics or advertising/marketing and must make it clear what user data will be collected and how it will be used.

I don’t trust Facebook for anything. I never would have dreamed of using a VPN by them. That’s like dancing with the devil and letting him stand on your feet while doing it.

I prefer Apple’s privacy policy compared to Google data mining and how freely they give it away.

Kudos to apple watching out for us when everyone is out to get our private info.

Ugh. They don’t "give it away". Google does not give your data to anyone. That’s how they make their money, by not giving it away and keeping it to themselves. That could change in the future but it’s not the case right now.

Isn’t every free VPN app a data collector? Why else would it be "free"?

No, not every VPN collect data they have mention in their privacy policy that they will be going to keep any logs as in online activities but unfortunately there are some black sheep available in the herd who not even keeps logs but also sell to the advertisers and government agencies also.

I will calling it "spyware" might be a step too far… and it seems Facebook didn’t fight Apple, so there’s a silver lining here. Let’s see what changes Facebook makes to the way the software works when it returns (I assume it will reappear at some point).

View All Comments
Back to top ↑