The web exploded yesterday after blogger Arun Thampi discovered the app Path sends every contact in a user’s address book to Path’s servers via a. plist upon registering for the service. The .plist includes full names, phone numbers, and e-mails. Path did not ask users to accept the feature, and it went ahead and saved contact information without telling them. Obviously, people have the right to be worried.
Path’s CEO Dave Morin issued an apology today after yesterday’s data scare and tried to reassure users about Path’s stance on protecting privacy.
We made a mistake. Over the last couple of days users brought to light an issue concerning how we handle your personal information on Path, specifically the transmission and storage of your phone contacts.
As our mission is to build the world’s first personal network, a trusted place for you to journal and share life with close friends and family, we take the storage and transmission of your personal information very, very seriously.
Path released a new update to the iTunes App Store (version 2.0.6) to help remedy the situation that let’s users opt in or out from Path storing address books on its server. If you opt in at first, and then later realize you would like to opt out—you can email Path and it will remove the address book from its servers.
Path also deleted the data it stored.
We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path.
Path users (that have not bailed on the service) might want to visit the App Store for an update.
In Path 2.0.6, released to the App Store today, you are prompted to opt in or out of sharing your phone’s contacts with our servers in order to find your friends and family on Path. If you accept and later decide you would like to revoke this access, please send an email to email@example.com and we will promptly see to it that your contact information is removed.