Privacy Concerns with Facebook’s Contact Sync

Last post, I pointed out some the issues I was having with SmartSync for Facebook. Most of the functionality provided by SmartSync is now available in Facebook’s official iPhone application since version 3.1, so I thought I’d test it out to see how it compares. Unfortunately, I didn’t get very far.

To enable the feature, choose Friends from the Facebook home screen, and there is a sync button in the upper right. From there you are given two options:

  1. Turn syncing on
  2. Replace existing photos when syncing

Based on the description of each choice, it seems Facebook’s Contact Sync is limited to syncing profile pictures and links, which are presumably links to jump to a contact’s profile from the iPhone address book. By contrast, SmartSync will sync birthdays, company & job title, birthday, and even addresses, although I strongly recommend against the last, as people rarely put thorough and accurate address data in Facebook. Also, based on my previous testing, I can’t recommend using SmartSync to sync birthdays. So from my perspective, the only difference is the lack of syncing for my friends’ companies and job titles.

So I turned syncing on, and was greeted with a small description of how it works along with a request for my consent (emphasis mine):

If you enable this feature, all contacts from your device (name, email address, phone number) will be sent to Facebook and be subject to Facebook’s Privacy Policy, and your friends’ profile photos and other info from Facebook will be added to your iPhone address book. Please make sure your friends are comfortable with any use you make of their information.

This seems to be the complete reverse of the process that SmartSync uses. By comparison, SmartSync downloads your friend list and matches your friends to your contacts locally, on your device. Personally, I’m not very comfortable supplying Facebook with the details of the 700 or so contacts in my address book that are not on Facebook.

What is Facebook going to do with those contact details when the sync is complete? Use it to let me know when one of these contacts finally sign up for Facebook? What does “subject to Facebook’s Privacy Policy” mean? The closest reference I can find in their privacy policy is this passage:

Friend Information. We offer contact importer tools to help you upload your friends’ addresses so that you can find your friends on Facebook, and invite your contacts who do not have Facebook accounts to join. If you do not want us to store this information, visit this help page. If you give us your password to retrieve those contacts, we will not store your password after you have uploaded your contacts’ information.

Well, this really isn’t a contact importer tool. So what happens to this uploaded data? How exactly is it “subject to Facebook’s Privacy Policy”? Unfortunately, until I find out, I won’t be accepting that agreement.

Friday, February 19, 2010 — 1 note   ()
  1. practiceofcode posted this