Maxfiylik xabarnomalari

Qanday ma’lumotlarni yig‘ishimiz haqida KSS sahifamizda yozilgan. Ba’zida ma’lumotlar yig‘ilishini vaqtincha o‘zgartirishimiz (oshirishimiz) mumkin, bunday o‘zgarishlar qachon va nega sodir bo‘lishini shu yerda bayon qilamiz.

2020-06-19: Privacy exception: Accidental user IP retention

What happened
We use AWS S3 to host websites, client applications, and remote server lists. We discovered that logging had been enabled for many of our S3 resources since June 2015. These logs include IP addresses of users who accessed those resources.
Impact
We have no indication that any logs were obtained by any external party, so this is not a user data breach. However, it is a violation of our Privacy Policy.
Resolution
Logging has been disabled for user-accessible S3 buckets and all logs have been deleted. We are working on a system to keep track of privacy exceptions and issues, and investigating AWS resource auditing.

2019-12-11: Temporary data retention extension

Nima qilyapmiz
We are temporarily halting User Activity Data pruning, effectively extending the data retention period.
Nega bunday qilyapmiz
We need to keep granular activity data longer to give us time to analyze recent censorship events.
Qachon bunday qilyapmiz
This will be in effect starting 2019-12-12T00:00Z. It will be in effect for one month. We will update this bulletin if it needs to be extended beyond that.
Yangilash
User activity data retention was returned to normal by 2020-04-10.

2019-12-11: Privacy Policy update

Nima qilyapmiz
We are updating our Privacy Policy. We are changing the retention period of User Activity Data from 60 days to 90 days. We also expanded the information about Privacy Bulletins. For the exact changes, see the GitHub commit.
Nega bunday qilyapmiz
To ensure the Privacy Policy accurately reflects our data practices.
Qachon bunday qilyapmiz
This will be in effect on 2019-12-12T00:00Z.

2015-06-01: Maxfiylik siyosati yangilanishi

Nima qilyapmiz
Biz maxfiylik siyosatimizni yangilayapmiz. Bu yangilanishga KSS dagi “Psiphon qanday ma’lumotlarni to‘playdi” savoliga javob qo‘shildi.
Nega bunday qilyapmiz
Maxfiylik siyosati sahifasi endi Psiphon ma’lumotlar maxfiyligi va to‘planadigan axborot siyosatini tekshirish uchun yagona manbadir. Sahifada reklama, analitika, ba’zi saytlardagi ma’lumotlarning yozilishi ham yangilandi.
Qachon bunday qilyapmiz
Bu 2015-06-01T00:00Z dan beri qo‘llaniladi.

2014-04-17: S3 qutisiga jurnal yozilinishi yoqish

Nima qilyapmiz
Biz bir sayt uchun Amazon S3 “qutisiga” (alohida xotira konteyneri) ulanishlar jurnali yozilishini yoqamiz. (texnik sabablarga ko‘ra sayt nusxalari bir nechta S3 qutilarida ishga tushirilishi mumkin.)
Nega bunday qilyapmiz
Biz buni qutidagi “masofaviy serverlar ro‘yxatida” nechta ulanishlar yozilganligini aniqlash uchun qilamiz. Bu bizga foydalanuvchilarning nechtasi uzilib qolayotganini aniqlashda ham yordam beradi.
Qachon bunday qilyapmiz
Jurnalga ulanishlar yozilishi 2014-04-17T15:00Z dan 2014-04-18T15:00Z gacha yoqiladi.
Qanday foydalanuvchi ma’lumotlari yig‘ilmoqda
Qaydlar jurnalida IP manzillar, foydalanuvchi agentlari, saytlarga ulanish vaqtlari kabi ma’lumotlar yig‘iladi. Bu axborot tahlil qilingandan keyin faylga murojaat qilgan foydalanuvchilar geografik mintaqalari bo‘yicha ajratiladi.
Bu ma’lumotlar qaysi muddatda saqlanadi
Jurnal qaydlari ko‘pi bilan bir hafta saqlanadi. Foydalanuvchilar soni esa deyarli cheksiz saqlanib qoladi.
Nechta foydalanuvchiga tegishli
Biz nechta foydalanuvchi ma’lumotlariga ta’sir qilishini oldindan bilmaymiz, lekin 10000 tadan kamligi aniq.
Bu axborot Psiphon Inc. jamoasidan tashqari yana kimlarga ko‘rinadi
Ulanish qaydlari Amazon S3 qutisida saqlanadi, demak Amazon bu qaydlarni ko‘ra oladi. (Chunki, Amazon baribir bu fayllar bilan ishlaydi, demak ular bu axborotni aniq ko‘radi.)