Youper

Youper

Youper, Inc
Wi-Fi

Passé en revue le : 25 avril 2022

|
Mozilla a effectué 16 heures de recherches
|

L’avis de Mozilla :

|
Vote du public : Très flippant

Youper is a digital mental health service "powered by Artificial Intelligence." It offers online therapy, behavioral coaches, medication services, and an AI chatbot. Youper really touts their combination of psychology and technology (especially AI) for their mental health solutions. How does Youper handle their users' privacy? Well, they just might be the most improved app for privacy we saw over the past year.

Que pourrait-il se passer en cas de problème ?

First reviewed April 20, 2022. Review updated, April 25, 2023

In 2022, Youper's privacy policy raised a bunch of eyebrows for us. In 2023, things look much better. They seem to share much less data. In fact, according to their privacy policy, they seem to share almost no data with third parties (we hope!). Yay for getting better in 2023 Youper. And more good news from Youper, they updated their password requirement to require a strong password after we reached out them in 2023. Youper is doing much better this year indeed, and might just be our most improved app overall.

One thing we should mention we'd love to see Youper do better though. They drop new people into a questionnaire asking sensitive personal questions before giving users an opportunity to review a privacy policy and see how the answers to these questions might be used or protected. That's a practice we really don't like, and one too many mental health app companies seem to use.

Read our 2022 review:

Yikes Youper! When you say you're "the only mental health service that understands you," it seems maybe you mean that literally.

Youper's privacy policy says they can collect a whole lot of personal information. Everything from name, address, email, birth date, race, religion, sexual orientation and political beliefs, to "Information stored on your mobile device, including in other applications" and even real-time information about the location of your devices. Heck, when you download the Youper app, it asks for permission to access your wearable sensor data (like heart rate monitors). They even say they "will combine information we receive from other sources with information you give to us and information we collect about you." Yikes again!

Not only does Youper collect a ton of personal information, they say they can share this personal information with a number of subsidiaries, affiliates, and third parties, including for marketing purposes. Now, not all that personal information can be used or shared with third parties for things like marketing purposes -- they say personal health information won't be shared with third parties for marketing purposes without your consent, for example. But a lot of that information can be used and shared with third parties for things like targeted advertising and that's what worries us.

That's a whole lot of personal information Youper collects that you really have to hope they keeps secure. Just a reminder, they say on their own privacy page, "Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your data transmitted to our Website and App; any transmission is at your own risk." This is a good reminder, what you share on the internet is never, ever 100% safe and secure.

Is there more that worries us? Yeah, there's more. Youper says they "may disclose aggregated, de-identified information about our users, and information that does not identify any individual, without restriction." Here's where we remind you that such de-identified data has been found to be relatively easy to re-identify, especially if location data is included. And Youper doesn't meet our Minimum Security Standards as we were able to login to the app with the weak password "111111". Requiring a strong password on an app that collects and stores so much personal information seems like an easy way to show you care about protecting the privacy of yours users. Too bad Youper doesn't do that.

So yeah, Youper's huge personal data collection and rather scary privacy and security practices leave us thinking there might be better apps to help you manage your anxiety and depression. What's the worst that could happen? Uhg, we don't even want to go there. It would really suck if your personal profile leaked and went up for sale on the dark web where a sketchy group of bad guys accessed it and used it to make your life miserable by outing your mental health problems to the world. Nobody needs that.

Conseils pour vous protéger

  • Do not log in using third-party accounts
  • Do not give consent for sharing of personal data for marketing and advertisement.
  • Choose a strong password! You may use a password control tool like 1Password, KeePass etc
  • Do not use social media plug-ins.
  • Use your device privacy controls to limit access to your personal information via app (do not give access to your camera, microphone, images, location unless neccessary)
  • Keep your app regularly updated
  • Limit ad tracking via your device (e.g. on iPhone go to Privacy -> Advertising -> Limit ad tracking) and biggest ad networks (for Google, go to Google account and turn off ad personalization)
  • Request your data be deleted once you stop using the app. Simply deleting an app from your device usually does not erase your personal data.
  • When starting a sign-up, do not agree to tracking of your data if possible.
  • mobile

Ce produit peut-il m’espionner ? informations

Caméra

Appareil : Ne s’applique pas

Application : Oui

Microphone

Appareil : Ne s’applique pas

Application : Non

Piste la géolocalisation

Appareil : Ne s’applique pas

Application : Oui

Que peut-on utiliser pour s’inscrire ?

Apple and Google sign-ups are possible

Quelles données l’entreprise collecte-t-elle ?

Comment l’entreprise utilise-t-elle les données ?

"We may need to share your personal information in the following situations: Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company."

Comment pouvez-vous contrôler vos données ?

"We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than twelve (12) months past the start of the idle period of the user's account. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible."

You have the right to request your personal information be deleted.

Quel est l’historique de l’entreprise en matière de protection des données des utilisateurs et utilisatrices ?

Moyen

No known privacy or security incidents discovered in the last 3 years.

Informations liées à la vie privée des enfants

"We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at [email protected]."

Ce produit peut-il être utilisé hors connexion ?

Oui

Informations relatives à la vie privée accessibles et compréhensibles ?

Non

Liens vers les informations concernant la vie privée

Ce produit respecte-t-il nos critères élémentaires de sécurité ? informations

Oui

Chiffrement

Oui

Mot de passe robuste

Oui

Youper update their password requirement to require a strong password after we reached out to them. Thank you Youper.

Mises à jour de sécurité

Oui

Gestion des vulnérabilités

Oui

Politique de confidentialité

Oui

Le produit utilise-t-il une IA ? informations

Oui

Youper says "Youper AI Assistant is based on therapy and meditation. Through quick and insightful conversations, Youper helps you master life's ups and downs."

Cette IA est-elle non digne de confiance ?

Impossible à déterminer

Quel genre de décisions l’IA prend-elle à votre sujet ou pour vous ?

Suggestions and meditative audios.

L’entreprise est-elle transparente sur le fonctionnement de l’IA ?

Impossible à déterminer

Les fonctionnalités de l’IA peuvent-elles être contrôlées par l’utilisateur ou l’utilisatrice ?

Impossible à déterminer

*Confidentialité non incluse

Pour aller plus loin

Commentaires

Vous avez un commentaire ? Dites-nous tout.