GNOME (Shell Extensions)
- The documents do not say whether your data trains AI.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared with partners and affiliates; you can opt out.
- The documents do not say who can read your content.
GNOME collects account, event, donation, and sometimes sensitive data; public posts stay public even after you ask to delete.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Name, email, payments, device IPs, event details, photos or audio, and sometimes health or other sensitive data.
Read the exact line
Privacy policy
“Sensitive information: information about your race or ethnicity, religious beliefs, sexual orientation, health and whether or not you have any disability.”
Training
They use it to run sites, take donations, market, research, and keep public records of what you post.
Read the exact line
Privacy policy
“To attribute data and content you produce directly and indirectly in our public-facing services (on the basis our to create a public record of the data and content produced by the Foundation's services”
Sharing
Service providers, sponsors and partners, and anyone who reads public lists, wikis, or IRC logs.
Read the exact line
Privacy policy
“Sponsors, partners and collaborators, such as those organizations with whom we host co-branded events.”
Kept
They keep it as long as they say they need it; public archives are not removed if you delete.
Read the exact line
Privacy policy
“We will keep your information for as long as is necessary to provide you with the services that you have requested from us or for as long as we reasonably require to retain the information for our lawful business purposes”
Controls
You can email to access, change, or ask to erase data; public posts stay in the archives.
Read the exact line
Privacy policy
“If you wish to remove your personal data from the Foundation, you may contact us at dsr@gnome.org and request that we remove this information from the Foundation's systems.”
Fine print
Material policy changes get a 30-day homepage notice; the policy is dated April 18, 2019.
Read the exact line
Privacy policy
“A notice will be posted on our homepage for 30 days whenever this privacy statement is changed in a material way.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Ask them to delete your personal data
Email dsr@gnome.org
Opt out of donor emails or all contact
Email info@gnome.org
Change account details on sites that have logins
Log in and update login, contact, preferences; or email dsr@gnome.org
Ask to be when donating
At the time of the donation, ask that your name not be posted
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
Anything you put on mailing lists, wikis, forums, or IRC can be seen by anyone.
Read the exact line
Privacy policy
“Please remember that any information that is disclosed in these areas becomes public information.”
For example, if you post your real name and email on a GNOME list, it can stay public in the archives.
Asking them to delete your data does not take your old posts out of public logs.
Read the exact line
Privacy policy
“Other locations where you may have used your personal data as an identifier (e.g. list postings in the archives, wiki change history, repository changelogs, and IRC logs) will not be altered.”
For example, even after you email dsr@gnome.org, your old IRC nickname and messages can still be online.
They may collect very personal details, especially for jobs, events, or scholarships.
Read the exact line
Privacy policy
“Sensitive information: information about your race or ethnicity, religious beliefs, sexual orientation, health and whether or not you have any disability.”
For example, a conference form might ask your gender, accessibility needs, or diversity information.
They may keep photos, video, or sound of you from events or other contact.
Read the exact line
Privacy policy
“Visual and audio information about yourself: e.g. a photo or video footage, or sound recording.”
For example, footage from a GNOME booth or talk could include your face and voice.
They may email you about events and share your details with marketing vendors.
Read the exact line
Privacy policy
“To carry out marketing and let you know about our news, events, products or services that we believe may interest you, including sharing your information with our marketing services providers”
For example, after you donate they may send newsletters unless you opt out.
Your data can go to other groups they run events with, not only their own staff.
Read the exact line
Privacy policy
“Sponsors, partners and collaborators, such as those organizations with whom we host co-branded events.”
For example, registering for a co-branded conference could share your name and email with the other organizer.
For donations, they say they will not sell the payment info they get from payment companies.
Read the exact line
Privacy policy
“We do not sell or distribute this information to third parties.”
For example, your card details from an online gift should not be sold as a mailing list.
Forms on their sites are sent over an encrypted connection.
Read the exact line
Privacy policy
“Our websites use Secure Socket Layer (SSL) technology, which encrypts your personal data when you send your personal information on our website.”
For example, when you type a donation form, the browser lock icon should mean SSL is used.
They say kids under 13 should not give personal info; it is not a strong age check.
Read the exact line
Privacy policy
“The Foundation does not knowingly accept online personal information from children under the age of 13.”
For example, a 12-year-old could still fill a form unless someone notices and they delete it.
Big privacy changes should show on the homepage for a month; they do not promise a personal email.
Read the exact line
Privacy policy
“A notice will be posted on our homepage for 30 days whenever this privacy statement is changed in a material way.”
For example, if they start using a new analytics vendor, you might only see it if you visit gnome.org.
Words to know
Legal words from the lines above, in plain English.
- sensitive personal information
- Data that could hurt you if exposed, like health, religion, sexuality, race, exact location or bank details. For example, telling a chatbot about a medical condition creates sensitive data that some laws protect more strictly.
- legitimate interest
- A legal reason that lets a company use your data without asking, when it decides its own need outweighs your privacy. For example, an app may analyse how you use it to improve the product, without ever asking you.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
How we got here · grade F · score 33/100 · 15 of 15 policy answers backed by a verified quote · 6 not stated
What does the app collect beyond what it needs to work?
They collect more than account basics: IPs, cookies, event details, photos, job data, and sometimes race, health, or similar sensitive fields.
Does it record your voice, face or body, and what happens to that?
They may collect photos, video, or sound recordings of you and do not say those are deleted after a session.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They list advertising agencies, analytics providers, and marketing vendors among parties who may get information.
Do they sell or share your data, and can you opt out?
They share with service providers, sponsors, and partners; they say they do not sell donation data and donors can opt out of contact.
What rights do they take over what you type and what the AI makes?
Posts on lists, wikis, forums, and IRC are treated as public records they keep for history and research.
How long do they keep your data after you delete it, and can you delete it in the app?
You must email to ask for deletion; they keep data as long as they need it, and public archives are not changed.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe SSL encryption, staff training, and contracts with partners; no independent audit is named.
Is there a real age gate, and are teens protected?
They say they do not knowingly take personal data from children under 13, with extra EU email rules under 16.
Will they tell you when the rules change, and is the policy specific?
The policy is dated April 18, 2019 and they post a 30-day homepage notice for material changes, but retention periods are not specific.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 3,952 words at a college graduate level (Flesch reading ease 35.9).