Hi everybody, I’m ready to unveil my year-end-holiday-hack project:
Meet Searchtodon: ***Private*** Timeline Search for Mastodon
It fills a gap that I have been missing over on Twitter as well: “I remember seeing this THING, where was that again?”
It is built with privacy and consent in mind (pls see the FAQ), but is also *an experiment* to see if something like this is accepted by the larger Mastodon community.
Here goes: https://searchtodon.social
@janl the moment you put the word search and private in the same sentense you didn't think it was a bad idea?
@mxfraud I’d prefer if the trust relationship is with the instance owner. If this experiment proves useful, I’m sure we can find a way to make it happen so there doesn’t have to be a third party involved.
@janl I'm sorry but your whole model is rubbish, not just being a 3rd party (but that tool.
My expectation is that I don't have to opt out of anything.
My data is not there for you to store, until I tell you its ok, opt out is not good enough.
You are solving a problem lot of poeple dont want solved. Actually it is not a problem it is a design choice we come to expect.
Create a new social network where you index everything if you are into that, and see who follows you there.
@mxfraud thanks for your input and for taking the time to write this up.
@mxfraud this is only fair, given how other folks have treated this community you can not trust me any further than them. I can only differentiate myself by doing better, if that’s at all possible. Just re making a buck: I’d be looking to cover hosting costs, not more. This will never pay dev/ops time for real. And I’m not selling this or the data, but again, you’d have to trust me on this, which you are under no obligation to do.
@mxfraud I appreciate that POV, thanks!
Where's your GDPR statement? Handling a lot of people's identifable personal data here.
And storing it indefinitely.
Why do you think "opt out only" is safe for minorities?
I quite like searching stuff but these seem like very obvious concerns. Maybe you could address them in your FAQ?
@Homebrewandhacking @janl @mxfraud GDPR has an exemptions for individuals and their websites.
My understanding is If an individual is running a webssite but are not selling anything on the website than any information that they collect is excluded from GDPR legislation.
That is quite the assumption. You may wish to check it.
Also a GDPR statement to that effect delineating the data, which is being collected and how it is to be handled rather than "IDk, keep it on a server in Germany?" Might be helpful.
Secrecy around a project that will be scraping people's profiles on an "opt out" basis seems... sketchy.
@stephen it is not excluded from GDPR
"[The UK GDPR] does not apply to ... the processing of personal data by an individual in the course of a purely personal or household activity"
Article 2(2)(a) ok uk gdpr @janl
cc / @Homebrewandhacking
@mxfraud @stephen @janl Thank you. I was genuinely unsure. I did a GDPR statement for a social RPG club with memberships. It was something like "we want as little of your data as possible for the purposes of giving you a membership price".
It seemed unlikely that this wide reaching project would be fine.