I admit it, I’ve been using Zoom during the COVID-19 crisis to carry on with my yoga classes without having to leave my home. It’s been a lifeline using the video conferencing app to take an exercise class, and Zoom’s so functional it allows multiple people to be in the same “virtual” room at once.
Other friends are using it for virtual parties, and of course, business meetings and conferences. Even UK Prime Minister Boris Johnson was seen using Zoom for his recent cabinet meeting.
But now the COVID-19 crisis is increasing the frequency people use the video chat service Zoom, it’s important we are aware of the implications for our privacy. And Zoom might not be the best choice for privacy-conscious users, it seems.
But Zoom’s policy also covers what it labels “customer content,” or “the content contained in cloud recordings, and instant messages, files, whiteboards … shared while using the service.”
This includes videos, transcripts that can be generated automatically, documents shared on screen, and the names of everyone on a call.
Consumer Reports points out that your instant messages and videos can be used to target advertising campaigns or develop a facial recognition algorithm, like videos collected by other tech companies. “That’s probably not what people are expecting when they contact a therapist, hold a business meeting, or have a job interview using Zoom.”
Consumer Reports reached out to the company for comment on its privacy practices. A Zoom spokesperson told me via email that the firm “does not sell user data of any kind to anyone.”
Data that can be collected and shared by your meeting host
The information that Zoom itself can share and collect is a worry, but what about the data handled by your host? Another big concern about Zoom, which you might not be aware of, is that the video app offers hosts “rights that might not be immediately apparent to other participants—or, in some cases, to the hosts themselves,” Consumer Reports states.
You might be using Zoom for work, so your boss could be the host, or you might be buying a service such as a class. Perhaps even more concerningly during this COVID-19 crisis, you may be using Zoom to talk to a health professional about your symptoms.
“Zoom puts a lot of power in the hands of the meeting hosts,” says Justin Brookman, director of privacy and technology policy at Consumer Reports. “The host has more power to record and monitor the call than you might realize if you’re just a participant, especially if he or she has a corporate account.”
Another particularly intrusive Zoom feature offers hosts the ability to turn on “attention tracking” to check whether you are paying attention during the call. This allows the hosts–who could be your boss or client–to monitor whether you click away from the Zoom window for more than 30 seconds while a screen is being shared.
Zoom privacy: “A bucket of red flags”
“They collect a potentially huge amount of personal data from accounts, calls made through the service and from scraping social profiles, but there’s no way to opt out of specific use purposes while continuing to use the service.”
In addition, she says, although the policy is careful to state that no data is “sold”, it is still used for targeting and marketing purposes. “This in many cases is the harmful use that individuals most object to, especially if programmatic advertising, such as real-time-bidding, is involved.”
Fielding warns: “For an employee or contractor whose boss or clients require them to use Zoom, this is bad news because they are required to expose, or accept the passive collection of, personal data which is not strictly necessary for the operation of the call, and which is then used for a variety of vaguely-described purposes by Zoom.”
She says that while the policy might meet U.S. privacy standards, she’d give it a C- for transparency and accountability according to the more stringent EU data protection regulation’s (GDPR) standards.
Can you use Zoom while protecting your privacy?
Given these concerning privacy flaws, it almost seems impossible to see Zoom as a privacy conscious option. However, sometimes it’s your only choice, especially when the decision is made by a boss or provider of a service.
Consumer Reports experts advise you to keep your camera and mic turned off unless you’re actually speaking. If you feel that you need to have the camera turned on, the experts advise you use a background image so the host can’t see inside your home.
If you care about your privacy, Fielding advises using a unique email address specifically for Zoom, clearing cookies and blocking trackers after every call, opting out of all secondary data uses where possible, and leaving feedback that explains the problems with the service’s privacy.
And if you don’t have to use Zoom, why not choose something else? Many of us are stuck inside for a while during COVID-19, and Houseparty might be a good idea for social chats, while Signal provides a much more secure video service. Jitsi, an open source app that supports multiple chats, is also a good option.
Zoom has now sent me a longer statement in response to this story. “Zoom takes its users’ privacy extremely seriously,” a spokesperson told me via email. “Zoom only collects data from individuals using the Zoom platform as needed to provide the service and ensure it is delivered as effectively as possible. Zoom must collect basic technical information like users’ IP address, OS details and device details in order for the service to function properly.
“Zoom has layered safeguards in place to protect our users’ privacy, which includes preventing anyone, including Zoom employees, from directly accessing any data that users share during meetings, including – but not limited to – the video, audio and chat content of those meetings. Importantly, Zoom does not mine user data or sell user data of any kind to anyone.”
Meanwhile, Zoom says its attention tracking feature is “built for training purposes.”
This is “so hosts can tell if participants have the app open and active when the screen-sharing feature is in use,” the spokesperson says, adding that the feature is off by default and only the account admin can enable it.
“It is important to note the attention tracking feature only tracks if a participant’s Zoom video window is open and in focus when the host is sharing their screen. It does not track any aspects of the audio or video content of a call, and it also does not track any other applications or activity on your device.”
I’m a freelance cybersecurity journalist with over a decade’s experience writing news, reviews and features. I report and analyze breaking cybersecurity and privacy stories with a particular interest in cyber warfare, application security and data misuse. Contact me at email@example.com.
Please follow my instagram: http://instagram.com/arminhamidian67