How Google can have its privacy cake while eating its data tracking, too

Google Privacy Policy
Google Privacy Policy (Image credit: Android Central)

Some of us are more concerned about our digital privacy than others, but no matter how you feel about sharing your information online, this area is where the next Big Tech wars are going to be fought. We're already seeing how companies like Apple are just going hard in the paint and giving options to share nothing while others like Facebook merge even more tracking into WhatsApp. Both are doing it wrong, but Google could do it right.

Source: Apple (Image credit: Source: Apple)

As someone who is concerned about digital privacy (both mine and yours), part of me loves how Apple is moving in for the kill. The App Store has privacy nutrition labels (such a bad name) that tell you what an app could do and settings that allow you to completely sandbox an app you've installed so only Apple gets a peek at what you're doing and how you're doing it. And yes, Apple needs some data like that to keep improving its products.

What Apple doesn't seem to care about is an entire industry built on the old way of doing things, where every app just tracked everything and only a few people ever seemed to think about it. Facebook is a great example here. Facebook has an ad platform as big as Google's and it works the same way — collect personal data and serve ads for things you might find interesting. Folks buying ad space love targeted advertising because they know more interested people will end up clicking on one. This makes a company that can place targeted ads pretty valuable.

Facebook is in meltdown mode over Apple's new changes because it stands to lose a significant chunk of its value once people realize they can toggle a setting and opt-out of ad tracking. Google's not immune here and has already advised customers using its ad engine to brace themselves for a significant impact once iOS 14's privacy updates go into effect.

Facebook Privacy settings

Source: Android Central (Image credit: Source: Android Central)

Nobody is predicting that developers will stop making apps for iOS and leave in droves. But Apple is making it very difficult to track usage metrics and performance as well as make some money through digital ads. Making things harder for developers is never a good look, though, and that's where Google might have an ace up its sleeve by taking the individual out of the tracking process.

FLoC is a weird name for an amazing idea.

The idea of FLoC (Federated Learning of Cohorts) is a great idea with a horrible name and it's being worked on right now for the Chrome browser and Chromebooks, because the web is even worse when it comes to tracking than any app store is.

How it works is that you now become a unique and anonymous ID, and based on what you do on the internet, you can be placed in a group. Once it's up and running, I'll quickly be placed into a group that likes fishing, for example. Google is still collecting data from an individual, but I'm not being individually targeted or tracked by any outside company.

Browsers would need a way to form clusters that are both useful and private: Useful by collecting people with similar enough interests and producing labels suitable for machine learning, and private by forming large clusters that don't reveal information that's too personal, when the clusters are created, or when they are used.A FLoC cohort is a short name that is shared by a large number (thousands) of people, derived by the browser from its user's browsing history. The browser updates the cohort over time as its user traverses the web. The value is made available to websites via a new JavaScript API.

This is all related to web ads right now, and nobody even knows if the idea will work. But we do know that Google and Apple were able to find a way to track users without exposing any private information with their joint-effort COVID-19 tracking API. This uses a system where your phone checks in with a server and just says "Hi, I am right here right now" periodically. Nothing else has access to that and even the back end that powers it can't track you through your small encrypted server ping.

NHS COVID-19 app

Source: Android Central / Alex Dobie (Image credit: Source: Android Central / Alex Dobie)

But it can track that someone pinged from a location and a certain time, and if one of those people came in contact with COVID-19 and voluntarily informed the server on the next ping, a flag is raised and everyone else who checked in at the same place at the same time gets notified that they have potentially come in contact with COVID-19. Everything is anonymous and neither Google nor Apple has access to anything more than blobs of encrypted data.

These ideas don't fix the root issue, but they show that Google can do something if it wants to.

This isn't a magic solution to the coming data tracking storm, because ads for fishing products aren't the same as sending encrypted data to a server that monitors COVID. But it does show that a bridge between the need for personal data being used and staying anonymous is completely doable. This is exactly what Google needs.

These ideas are much laxer than Apple's outright war on data tracking, but Google needs rules in place that are a bit more relaxed because Google is an advertising company. These two examples show how far Google is willing to go so that it can protect as much of our privacy as possible but still make buckets of money selling ads.

I mentioned that I hold up data privacy as one of the most important things about using a smartphone. Right now, nobody is doing it right, and overreaching and mostly ineffective (click yes to agree to cookies is a great example) methods are not going to be the solution. Neither is digging in and gobbling up even more data; there has to be a middle ground.

There has to be a middle ground when it comes to data sharing.

I think this is where Google can find a balance that does enhance and preserve our privacy while still offering both developers and advertisers a way to track specific metrics through anonymity by obscuration — use new techniques to centralize and aggregate data into relevant clusters that aren't easily tied to your specific phone.

Google is always going to track Android users somehow. As mentioned, it's a big part of the company's business model. Now is the chance for the company to keep working on the issues of privacy and being developer-friendly in a way that only it can.

Jerry Hildenbrand
Senior Editor — Google Ecosystem

Jerry is an amateur woodworker and struggling shade tree mechanic. There's nothing he can't take apart, but many things he can't reassemble. You'll find him writing and speaking his loud opinion on Android Central and occasionally on Twitter.