Most companies would bury this change in a deceptively boring T&Cs update, but we value transparency, so here's what you need to know in an internet-friendly numbered list:
Users on our EU cloud instance are opted out by default
So too users with agreements that prevent training (e.g. BAA, MSA, or similar)
All other users on our US cloud instance are opted in by default
We will anonymize all data before it's used for training
We will only use data that already exists in your PostHog instance
We will do all the model training ourselves, which means...
We won't sell or send your data to third-party model providers
You can opt out at any time via your org settings in PostHog (admin access required)
Training won't start until June 29, so there's plenty of time to decide
If "we will opt everyone in because otherwise we won't get enough data because we know users won't opt in" is your business model, maybe it's time for a rethink.
There is no such thing as opt in by default - and burning that amount of customer goodwill because you want something instead of say, giving a discount to people who are willing to do it is a choice for people who have a lot more market share and their customers would have more trouble leaving.
> Most companies would bury this change in a deceptively boring T&Cs update, but we value transparency, so here's what you need to know in an internet-friendly numbered list:
This feels like a really bad defense. It’s great you provide transparency but I don’t want my analytics system writing my code. There are already so many other first movers that are better that I would rather connect to your analytics.
> We will anonymize all data before it's used for training
Anonymize by what definition? GDPR? Do note that this very high bar.
> All other users on our US cloud instance are opted in by default
Including end users in the EU? You should remember that you are obtained the personal data directly from data subject meaning Article 13 obligations apply. Article 13 omissions cannot be cured retroactively. Can you show all of your customers have provided sufficient Article 13 notice to cover this processing?
And do note that you are almost definitely within the scope of 3(2)(b).
Cant wait to see posthog crash and burn, i have hated their service for years now.
Hey man, respectfully, opt-in by default is not opt-in. That's opt-out, and it's scummy.
I feel like you either know that already, or should, but either way I won't be using your product anymore. Just pulled it out of the projects I'm personally in charge of and in the future I'm going to recommend against using it both internally and for clients.
Legitimately disappointed.
There is definitely some confusion on the EU part. I am a European citizen, but some of my activity data on some of the sites I host is logged in US Posthog, which means Posthog is subject to the GDPR, even if the data is US hosted!
> We will do all the model training ourselves
That's actually an interesting note. So you all will be managing the training runs on hardware you own or rent and manage?
as a user i dont like it, and am disappointed. it will take a bit of time to transition our systems off of posthog, but we will need to.
if you are looking at your metrics, I want to be clear that this transition will not happen overnight, but it _will_ happen for this reason, so just be aware that your short-term metrics won't tell the full story
> All other users on our US cloud instance are opted in by default
This is slimy.
> All other users on our US cloud instance are opted in by default
Cool, cool. Glad to see that you are the arbiter of what your users have "opted" to do, and their input isn't required.
While we're at it, I'm going to "volunteer" your time to rebuild my patio this weekend. You don't need to worry about volunteering, I've done it for you.