SPEAKER_00: Rising Stars of SaaS is brought to you by Pipe. SaaS companies, this is for you. Pipe helps you unlock your recurring revenue as upfront capital. No debt, no loans, no dilution. Sign up in minutes and start trading on Pipe free for 12 months at pipe.com slash twist. Odoo is a fully customizable and fully integrated suite of software that lets you build and scale your stack as you build and scale your business. Your first app is free forever and right now Odoo is offering $1,000 off your first implementation pack at odoo.com slash twist. That's O-D-O-O dot com slash twist. And Outgrow. With Outgrow, any marketer can build calculators, assessments, chatbots, and recommendation tools to double your conversion rates. Go to outgrow.co slash twist for a 30-day free trial and a $250 credit. That's outgrow.co slash twist. SPEAKER_02: Hey everybody, welcome to another episode of This Week in Startups. SPEAKER_04: We're doing our Rising Stars of SaaS, Software as a Service. SPEAKER_05: You know that category that every venture capitalist wants to invest in and a lot of founders are attracted to because you get to sell to businesses and businesses tend to like to pay money for software and services. So it's a very cool business. And when it's a subscription, software as a service, not subscription, but when you're doing a subscription, wait, or SaaS stand for software as a service, right? SPEAKER_06: As a service. SPEAKER_05: Yeah, I was just thinking if people were, I heard somebody say software as a subscription and I was like, no, that's not the right word for SaaS. It's software as a subscription. So we're doing our top 10 rising stars in this space. And we did this through a combination of looking at the funding raise and who was investing in companies, who their customers were. And today's subject, Ben Brook from Transcend, has got some or has his company, Transcend, has a lot of great customers. And that's what we're looking for in this series so that we can break down exactly what it takes to build these companies. And we'll, of course, delve into what they do. So we're going to talk about building SaaS companies. And also, obviously, in this case, the subject, Ben, is privacy and data privacy specifically. What does Transcend do and why did you start it? SPEAKER_10: Sure. SPEAKER_11: So Transcend makes it simple for any company to give their users data rights. So data rights is this sort of new concept that's coming into the world. It largely started with GDPR, which is a modern privacy regulation in Europe. And that's now going to other regions like California with the CCPA coming into effect, to Brazil with LGPD, and to many other countries around the world. And in these laws, consumers are getting the right to actually access all of their personal data, to erase all of their personal data, as well as opt out from a variety of different forms of processing personal data. So users are getting choices over how companies process your data. And these are a new set of rights that are coming in. And effectively, companies have to comply with these requests on a very short timeline. So this is usually within 30 to 45 days. They have to respond to the user saying that they have successfully erased all data within their business about that user. Now, the problem is, companies have been basically spewing data into dozens, if not hundreds of different data systems for decades. And your personal data is scattered across orgs. And so what Transcend builds is data privacy infrastructure. And you can kind of think of that as a layer that sits over top of all types of data systems, whether that's a database, a warehouse, a SaaS tool like Salesforce or Zendesk or Google Analytics, and actually manages all the personal data inside that. So when a user does request to erase their data, we can receive that on behalf of our customer and precision strike that person's data across all different systems. So that's the data privacy infrastructure. And then we also make that entirely self-serve for the end user. So we offer our customers something that we call the privacy center. And this is basically a website that lives at privacy.ourcustomername.com. And that's where users can go to understand in simple terms what the heck this company is doing with your data without having to read a full privacy policy. And then actually offers a control panel where users can exercise these choices in an entirely self-serve way. SPEAKER_05: So this would be at your website or at, as a white label at Robinhood. I know it was one of your customers and obviously we're an investor, I'm an investor in that company. Yeah. So if I went to privacy.robinhood.com, I would see this? SPEAKER_22: Yeah. So if you went to privacy.robinhood.com, for example, patreon.com, you would see this? SPEAKER_11: Not all customers use the privacy center. So that part is optional. The data privacy infrastructure can be interacted with through the privacy center or just through an API. SPEAKER_05: Got it. So if you go to privacy.patreon.com, which I just clicked on, I just said it, you will see what data patreon is keeping on me and I can take control of that. So instead of them having to build this, you built this for them basically. And they just put their data hooks into it. And how long does it take a company like patreon to set up this privacy data center? SPEAKER_22: So it shouldn't take more than an afternoon. Oh, really? SPEAKER_11: So yeah, it's really quick. So the privacy center basically comes out of the box. They customize it to match their brand and they can override any of the text, but the defaults are all good. And so you can really set that up within minutes. The part that takes the rest of the afternoon is hooking up data systems. So if they have, for example, an analytics tool or a database or, you know, maybe a support system like Zendesk, we're going to connect into those because we build first class integrations with each of those systems. And we partner with those other SaaS companies who process personal data to make sure that we can hook into them and serve customers like Patreon together. SPEAKER_32: Now, the GDPR, which is the General Data Protection Regulation that the EU, the European Union, decided to do as a group, was the most intense privacy regulation to date. It got implemented in 2018, I believe, because I remember all these websites basically were so far behind in doing this that they just blocked off access to European countries. SPEAKER_04: And they just said, the New York Post is not available in Europe. I know because I use a VPN and sometimes I have a European address. And it was incredible to see that people were just like, we give up. We're not even going to try to serve you stuff. We don't want to get fined. Has everybody caught up in dealing with that here in the United States in terms of catching up with that regulation? And then what is the gist of what the GDPR does versus, and I know this is a big question, the CCPA, which was California's Consumer Privacy Act, which it passed in, I guess, 2018. I'm not sure what the state of that is in terms of when did you have to start complying to it. SPEAKER_05: So explain to us those two big swaths of regulation in a nutshell. SPEAKER_37: Sure. So to start, the first question was, have companies caught up to GDPR? SPEAKER_22: The simple answer is not yet. A lot of companies are still working with fairly temporary solutions that throw a lot of manual SPEAKER_11: work toward the processing that goes in place. So something that we see a lot and something that is actually new with GDPR is that there are all these sort of day-to-day recurring action items that just come in because users are now exercising choices. Historically, privacy laws have been like, be transparent. Have a privacy policy. Tell people what you're doing, right? That's not something that goes into your day-to-day business processes. But now that users have rights and choices, it means there's just a continuous stream of preferences coming in, typically today via email. And so what happens is in that privacy policy, you can pretty much go to any website and find this. Scroll down and you'll find something that says your rights and choices. And it will say, if you would like to exercise your data rights, email us at privacy at company name.com. And so you basically have to write in a letter saying, I want to delete my data. I want to see my data. I want to opt out of this. SPEAKER_41: That seems completely insane and inefficient. SPEAKER_22: You're absolutely right. And it's bad UX. And it also translates to really rough internal processes. So there's actually a legal person sitting on the other end of that email address, right? Right. And they're receiving these emails and they have to basically scramble around the organization, SPEAKER_11: shoulder tapping people to log into their respective systems and operate on this user's data. Wow. Yeah. That's crazy. Yeah. And so it takes forever. And more often than not, as you can imagine, it's not really complete. So it takes a lot of manual labor to get one request done. But you can imagine what happens when you have dozens, hundreds, thousands of these coming in. SPEAKER_04: Yeah. I mean, you just and so when we get back from this quick break, I want to know what's at stake for startups if they were to miss that email or forget it and not delete a person's data, what happens and has anybody started getting fined by the European Union over GDPR when we get back on this week in startups. SPEAKER_48: SaaS companies with reoccurring revenue used to have two ways to grow. You could get equity from an investor like myself, or you could get debt from a bank and get a loan. Well, now there's a brand new third way to grow without debt or dilution, and that's Pipe. It's a two-sided marketplace that connects a SaaS company, software as a service, you know, subscription software company. And they basically take your monthly, quarterly, reoccurring revenues, and they have institutional investors who want to bid to purchase those revenues for their annual value up front. So let's say you're getting paid monthly. Somebody will buy the year from you, give you that money up front, and then you pay it back. Pipe is a smarter way to grow your business. SPEAKER_49: It's the most founder-friendly way to finance your growth, and it's not even close. With Pipe, there's no debt, no loans, and no dilution. SPEAKER_48: Pipe is also frictionless and completely transparent. It only takes a couple of minutes to sign up, and you'll have this cash in your bank for all those yearly contracts within 24 hours. So you're charging monthly, maybe quarterly. They take the value for a year. They put it in their marketplace, and financial investors will buy that from you, and you'll find out what that revenue's worth. So Pipe is so confident you'll love trading your SaaS subscriptions that if you sign up by the end of October, they'll eliminate your trading fees for one full year. Wow, a full year. This could save you tens of thousands of dollars, depending on the size of your business and the volume you trade. So happy piping, everybody. Sign up today at pipe.com slash twist to get that first year free. SPEAKER_49: So once again, pipe.com slash twist. Okay, let's get back to this amazing episode. SPEAKER_51: Hey, it's the rising stars of SaaS here on This Week in Startups. Ben Brooke from Transcend is our guest today. SPEAKER_04: It's our second rising stars of SaaS. Rapid Deploy was on the first episode. They were helping people increase, decrease, one call response time. SPEAKER_54: Very cool SaaS company. And today we're talking with Ben from Transcend.io. You can go check it out. SPEAKER_04: So with people in GDPR and businesses, has the EU started giving fines? And how hardcore are they about this? SPEAKER_10: It's a great question. So they are starting to issue fines. SPEAKER_11: So the pace of regulation and enforcement is, it's pretty slow in general. I mean, this isn't something that's a new concept that everyone knows government moves quite slow. So what GDPR actually did was it also started standing up data protection authorities, which are effectively like the privacy cops in a way, right? And so these are new bodies of government that have to be stood up. And then they can start prosecuting. They can start charging companies. They can start going through trials. And this actually takes years to get the first fines out. But we are starting to see them now. And that's actually kind of light speed for a new regulation being enforced. We're still seeing trials held for things like Cambridge Analytica, which were years ago, right? So to see the first fines come out has shown that they're actually moving very quickly. They're also staffing these data protection authorities very quickly. SPEAKER_05: And these are government jobs. These are they're not deputizing third party companies to do this. They're literally creating a police force. SPEAKER_57: What do you know the scale of it? Are we talking about a dozen people or hundreds of GDPR officers out there? SPEAKER_60: So each country is different. Each country within the European Union will have their own data protection authority. SPEAKER_23: Some of these will be hundreds or thousands of people. SPEAKER_40: Wow. Yeah. And then how and are they each looking at American companies as targets? SPEAKER_04: Because we've seen the American companies are the biggest. We have a different privacy regulation here. SPEAKER_05: So are they you know, is this going to be a cottage industry for generating revenue for a company where Italy or Spain or Greece or some country that is, you know, got to balance their budget is going to look at American companies and say, Oh, we should just find the heck out of them and try to find mistakes. What's the I know that's a little cynical, but I have seen these fines act that way. We all know how speeding tickets work when you have to balance the budget in a particular, SPEAKER_54: you know, town or county. SPEAKER_22: Yeah. So so GDPR applies to any company that is operating in Europe is serving Europeans. So if there's a European whose data is sitting over in a Silicon Valley company, that company has to comply with GDPR. SPEAKER_11: So data protection authorities are absolutely going over after American companies, but they are also going after European companies. SPEAKER_22: We see we see penalties across the board here. Um, so it's, it's mixed, but, uh, American companies are absolutely in scope here. SPEAKER_32: And do American companies have to record the origin of where, um, a citizen was coming SPEAKER_05: from, or if I wanted to, you know, run my own version of Reddit, let's say, and I didn't SPEAKER_04: want to keep IP addresses. So I created like Reddit or Hacker News, my own little news forum, message board, let's say a message board. I started a message board, but I said, you know, I'm not tracking IP addresses and you can't use it if you're from, uh, the European union. You can only use it if you're in America, but I'm not tracking IPs. SPEAKER_70: Then can the GDPR come, come after me. If somebody says, I'm going to just sign up anyway. SPEAKER_72: Yeah, technically. SPEAKER_22: Um, so if you have, uh, personal data of a European citizen, it doesn't matter. Whether you tried to prevent them from using your platform, uh, frankly, it's, it's still in scope and a lot of companies may do this, do what you just mentioned and, uh, decide that SPEAKER_11: the legal risk is worth it because it's not at the scale at which they believe a DPA, a data protection authority is going to pursue them. Um, so it does, it doesn't completely absolve you of GDPR, but it may be a way for a small company to, uh, to try to avoid that. SPEAKER_05: Because that has become the, the dialogue in America, which is, you know, I've heard people say your data is my liability. Um, and I don't want to even store your data. And that's the approach I've taken. Even with this podcast, I told my team and everybody, I don't want any of these crazy analytics companies cooking the listeners to the podcast or figuring out who they are and then selling that data to other people. We're going to use no tracking or metric software. So, I mean, we do have metrics like downloads and stuff like that, but I don't want to start tagging my customers. It just, to me, it's just, I don't know, distasteful, I guess would be the word or SPEAKER_04: whatever. Um, but the GDPR has started giving off fines. I saw one, I don't know if you're familiar with the case of H&M got hit with this giant fine, but that wasn't for their users. This was for their employees. I guess they had kept their employees data and their employees data got hacked. So, as a lot of this, the, if you didn't take steps to lock up the data or that you SPEAKER_81: were recording it in general. SPEAKER_11: Um, so data, data breaches, uh, under GDPR are in fact illegal. And so it, it actually doesn't matter whether you were collecting it or, um, whether you tried to protect it, uh, it will still be, uh, in violation of the criminal code. SPEAKER_54: So, um, so wait a second, this GDPR fine was for 35 million Euro, something like 41 million USD at the time of this article. SPEAKER_85: I'm reading, um, if you get hacked by somebody, you're responsible for being broken into whether that was the most sophisticated hacker in the world or not, you're still responsible. SPEAKER_22: That's correct. Yeah. SPEAKER_89: Um, and I will say that the person who broke in, I mean, they're also responsible, I guess SPEAKER_85: on a criminal basis, but is this not crazy that if you took reasonable precautions and SPEAKER_05: you had your servers updated and some hackers very sophisticated and they figure out how to break into your system that you're now responsible? I mean, what if they, what if an employee gave the passwords that they had and they weren't SPEAKER_51: supposed to do that now, could the GDPR then still find you? SPEAKER_60: Well, I think it's good that there are financial incentives in place to protect data. SPEAKER_22: And so it's, at the end of the day, it is about the result of, of your security practice. SPEAKER_11: And, um, the courts can actually decide whether to be lenient because, you know, maybe HNM did everything, uh, within their power or to a reasonable degree, uh, to protect data. SPEAKER_22: And frankly, 35 million, uh, on GDPR scales actually isn't that high. SPEAKER_11: So under a data breach, uh, the European union could have, uh, actually find HNM for 2% of their global revenue. If HNM, uh, were, uh, failing to respond to data rights requests. SPEAKER_17: So this is like access erasure and things like that, that can go up to 4% of their global revenue. SPEAKER_05: Wow. So they're, they're, they're looking at this, I guess, like the way I guess they were doing speeding tickets in Norway or whatever. Like we're not just giving you a fine in a vacuum. They were giving speeding tickets. I think it was Norway or, or Sweden were giving fines based upon your income. So it was a percentage of your income. So if you were like a famous NHL player, famously, they got a speeding ticket. It wound up costing about a hundred thousand dollars. Like the speeding ticket was the price of the car in that case. So they're really going after you for a percentage, um, of, uh, your revenue for the year. SPEAKER_90: What, do you know what the largest fines have been to date? And do they feel fine? SPEAKER_98: And British Airways facing a $230 million GDPR fine. Wow. SPEAKER_11: Yeah. That was one of the big ones. Yeah. Yeah. Um, I'm not sure what the current record is, but I do expect they will continue going up. Uh, as I said, the regulation, the regulators are effectively only getting started and they're internally spinning up their own organization. Um, there also hasn't been a very large window to see, um, to see these big breaches. So, um, for example, Facebook and Cambridge Analytica are very lucky that that came out in 2017 before the GDPR came into effect, because that would have been one of the cases where it would have gotten closer to the maximum penalty. SPEAKER_101: 4% of revenue or 4% of the value of the enterprise was what you said? SPEAKER_90: 4% of revenue. 4% of global revenue. Wow. SPEAKER_85: So it doesn't even impact that, that seems, that they even have the authority to do that, to tax your global revenue. I would think it would be 4% of the revenue in Italy or whatever. SPEAKER_05: It makes sense. It occurred in Italy, but that's not a little overreaching. SPEAKER_60: Well, that's something that will be determined in court because, um, whoever gets that penalty SPEAKER_11: first is going to, uh, fight that in court. And then there will be jurisprudence set on whether that actually is something that the European union has, uh, authority over. SPEAKER_04: All right. When we get back from this quick break, I want to know if it's even worth it for American companies to operate in Europe, given this type of framework, uh, or if people are considering SPEAKER_05: like they did early on, which was just saying, we're not making that much money in Europe. Anyway, it was just block those IP addresses when we get back on this week in startups. SPEAKER_49: One of the toughest parts of building a company is choosing which tools and providers to use you want to pick the best solution for each and every department to help your employees succeed because they all deserve the best and you want to make their lives easy. SPEAKER_48: But there are so many functions in a startup and each space has endless vendor sales tools, email marketing, accounting, HR, and payroll, project management, customer support, point of sale, e-commerce. It goes on and on and on and on. And eventually you end up with a Frankenstack of tools that cost a lot and don't integrate properly with each other. And while Odoo is here to change that, Odoo is a fully customizable and fully integrated SPEAKER_49: suite of software that lets you build and scale your stack as you build and scale your startup. It's that simple. It's simple and modular. So you use what you need and all their apps integrate perfectly with each other. SPEAKER_48: Plus, it's open sourced so you can spend your freshly raised capital on talent instead of expensive software. So here is the CTA, the old call to action. Your first app is free forever. And right now, Odoo is offering you $1,000 in credits on your first implementation pack. SPEAKER_49: Think about that. $1,000 is one of the best offers in the history of the show. So I want you to go to odoo.com slash twist. That's odoo.com slash twist, odoo.com slash twist. Go ahead and do it now. Sign up. Get that $1,000 credit before it goes away because these things don't always last. And thank you to Odoo for supporting This Week in Startups. SPEAKER_114: Let's get back to this amazing episode. Welcome back to This Week in Startups. Our guest today, Ben Brooke from Transcend. You can go check them out at transcend.io. SPEAKER_05: They build tools to help companies be compliant. Did I get it right? SPEAKER_04: So if you're a company, you can either spend 10,000 hours doing this with your internal developer team, or you can just buy your software. SPEAKER_72: That's right. I would also say that we go a little bit beyond that and help companies from a more first principle SPEAKER_11: find a way to really build trust with users and actually respect their privacy choices without putting them through kind of a maze to exercise their choices. So some companies may still have that maze up front. We try to get rid of that because we've actually automated the processes to such a point where it has no incremental work for the company to fulfill a new request. SPEAKER_18: What should companies... I'm going to put aside, should you operate in Europe or not, you know, based on this? I think people make their own decision on that. SPEAKER_04: But I think a more interesting thing is, what is the right balance of what should be stored by a SaaS company or a consumer company? SPEAKER_18: Obviously, these are two different things. And we're doing our rising stars of SaaS right now. Thanks for being the second guest on the series. SPEAKER_05: But they're obviously different. So if I was starting my own clubhouse or space or Twitter today versus I was starting my own Slack or, you know, Asana, what is the right amount of data to store in order to enable me to do, you know, to have a rich product offering versus it's just you're keeping too much stuff? SPEAKER_22: Yeah, so the reality is, is it really depends on the use case. And there's kind of two like simple principles that you can follow. One is just start from a place of respect for your end users. Like at every step, ask if you're serving your customers best. And if they knew about these processes, would they object to it? And so have you baked in a good default, right? Is that something that is that users expect of your platform? And then furthermore, use data minimization. So are you collecting data because you think it might be useful later, but you don't have a use case right now? You probably don't need that data. Are you collecting data to perform the service? SPEAKER_11: Then yeah, I mean, so it depends on the company, right? So some companies may require audio recordings because we're hosting podcasts or something. But that shouldn't apply to, you know, your weather app. The weather app may need geolocation, but the podcast app probably doesn't. And so there's a lot of context that you bake in. But by starting from those principles, I think you can kind of navigate that territory for yourself. SPEAKER_48: And companies like Facebook, who's the biggest offender of everybody, they just basically took the philosophy of let's store everything in case we need it at some point. It's all signal. It'll all make the ad network better. SPEAKER_04: Where does that philosophy stand, you know, in 2020? That philosophy of just store it all, throw it into the machine learning, and let's learn. SPEAKER_69: Because that is Zuckerberg's approach. And I mean, he's part of the reason this GDPR and all this stuff actually happened, correct? SPEAKER_72: Yeah. I mean, I would argue any platform with that much data and that many eyeballs has a long way to go. SPEAKER_11: And I think they've inspired a lot of the legislation. SPEAKER_132: That's incredibly diplomatic. So the translation to that for me would be Facebook is one of them. SPEAKER_05: They've made horrible decisions to store everything. And they've been reckless with, you know, how to keep it private. I mean, let's call it what it is, right? I mean, this stuff would not have gone down this severely if there wasn't the bad actor of Facebook there. So your best practices, unless you have the need for it today, don't store it. And if you would be ashamed, or embarrassed, if your users found out you were storing this, don't do it. Yeah. SPEAKER_136: Okay. SPEAKER_05: It seems completely fair and logical. SPEAKER_138: Yeah, just not something that Zuckerberg or, you know, some competitors you might be up against would do. SPEAKER_60: And it's surprising how many companies have very similar tracking technologies, often through SaaS, right? SPEAKER_22: So you don't have to have 100,000 or 10,000 engineers to build surveillance infrastructure. SPEAKER_11: Pretty much every website, news website, will be sharing your visit with hundreds of other companies, right? If not thousands. Through cookies. Through cookies and other tracking technologies. Yeah. Cookies are one of them. SPEAKER_48: What are the other tracking technologies people are doing? They're fingerprinting your browser to kind of know it's you? Is that the big one? SPEAKER_12: That's another one. Explain what that is to people. SPEAKER_144: Because I don't think they understand the fingerprinting of a computer. SPEAKER_60: Sure. So when you visit a website, there is a pretty easy way of finding out some characteristics of your browser. SPEAKER_22: For example, are you using Firefox? What's the dimension of your browser window right now? What language are you using? There's a series of things that websites can access for perfectly good purposes. But then what they do is they actually structure that to assign a probability that you are a given person. SPEAKER_11: So because your browser is probably the full width of your screen, that's a piece of information that can help identify you. And so by amalgamating that information, you can actually fingerprint individuals. SPEAKER_146: So even if I have an app blocker on, you still know the width of my browser, you still know my operating system. SPEAKER_05: I logged in one time from that sort of footprint. And it's kind of like maybe you didn't get the picture of my face on the surveillance camera, but you saw my sneakers, you know my gait, you know my body type, my height, my weight. You kind of got an idea that that's me and you could serve me ads. And then there's, of course, your IP address, which for your household doesn't change. And so if somebody in the house is looking at a certain, you know, I don't know, iPhone case, you're going to see it come up and retargeting all the time. It's kind of a charming, narrow kind of scope there. What can users do to protect themselves? What is the state of the art there? Because it does seem to me that a conscientious individual could remove a large portion of tracking from their life. Am I right or wrong? SPEAKER_60: Unfortunately, I don't think it's possible today. I think there are so many different methods of tracking that putting the burden on the consumer SPEAKER_22: to find all of those methods that are becoming increasingly covert. It's just not feasible. Kind of like the current default today is like there are 50,000 hidden cameras and wiretaps in your house, and it's on you to find them and disable them. And like that's not a good default right now. And so it's very hard as a consumer. And this is why regulators are stepping in and saying we need to change the playing field a little bit where we change these defaults. SPEAKER_11: And we give these users a very clear way of understanding where all those trackers are and have an easy way to push the off button. David Friedberg: So if I had a VPN and I put my IP address in another state, another country, and I have ad blocker plus or whatever on my browser I'm using, I think the Brave browser has that built in, and I'm using DuckDuckGo, SPEAKER_54: and I pay for my email from ProtonMail. ProtonMail. SPEAKER_48: So how safe would that person be using a VPN, an ad blocker, or the Brave browser, and not using Gmail as an example? SPEAKER_38: How much more private would I be? SPEAKER_11: You would be more private. So you would be able to slice away a lot of technologies by doing that. You may be able to get rid of common third-party cookies. You may be able to get rid of tracking pixels in your email. SPEAKER_22: But at the end of the day, there are signals which can easily fingerprint you. And so you can try really hard as a consumer, but you will never get through everything. And because there's very few laws around this, at least in America, those will continue to exist. So fingerprinting is one example. SPEAKER_11: But when I say there are many others, I mean there are thousands of many other ways. SPEAKER_161: What are some of the others? I'm curious. SPEAKER_11: Sure. So just in terms of protocols and technologies, there are web beacons. There are... What's a web beacon? It's a browser technology. Oh. SPEAKER_22: There are so many ways. So like a pixel tracker is like a sort of one-by-one GIF that sits in an email or on a website. And when it gets loaded, it pings a URL to say, hey, this user just clicked this unique pixel. SPEAKER_04: Yeah, that's when you're using an email client that says the other person's opened the email or they opened it. But if you're using something like Outreach or something, they've opened it 17 times, which means they forwarded it to some internal list or whatever. So you can track the number of times it's open. David Friedberg: So there really is no way in your mind for a consumer to take control of this, really? SPEAKER_72: Yeah, really. Really, right now, there are things that you can do to limit it, but you can't get rid of it. SPEAKER_166: What's the best browser to stop people from tracking me? SPEAKER_05: Does the Brave browser or one of these browsers... Brave is great. Does that actually stop fingerprinting? SPEAKER_166: It'd be cool if there was an anti-fingerprinting technology available for browsers. SPEAKER_60: You can only mitigate. So I'll give you a more complex example of fingerprinting. SPEAKER_11: So Apple has the Apple Watch, and there are applications that exist on there which have the ability to track... to use the Motion API. Perfectly good reasons to do that. Like if you're building a swimming app or a running app, you want to know... Tennis app, whatever it is. You want to know your stroke, yeah. Whatever it is. SPEAKER_22: Every person's gait, the way they walk, has a uniquely identifiable fingerprint of that person. And so there are advertisers that create basically machine learning models that look at that API and they're able to say, okay, this is a unique person. SPEAKER_11: So every time we see this gate, this way they walk, we know that this is Jason. SPEAKER_173: Oh boy, that is dark. SPEAKER_176: All right, when we get back from this quick... SPEAKER_04: No, no, it's totally terrifying and awesome. When we get back from this quick break, I want to know what you think of Apple's recent jihad against Facebook and Google and, you know, their desire to protect privacy on the hardware level and on the operating system level. And if that will give people a reprieve or not, we get back on this week in startups. SPEAKER_49: What do Adobe Salesforce and Marketo all have in common? SPEAKER_48: Well, they're obviously the heavyweights in marketing in the technology space. So what else do you need to know? They all use Outgrow.co to boost their marketing and lead generation. With Outgrow, any marker can build calculators, assessments, chatbots, and recommendation tools to double their conversion rates. And you need these tools as well. They have ready-to-use templates, powerful integrations, analytics, and segmentation options that are built for the modern marketer. When you think Outgrow, you should think growth. It's really that simple. SPEAKER_49: So I want you to go to Outgrow.co slash twist for a special 30-day free trial with no credit card required and a $250 credit with their small business incentive package. So go to Outgrow.co slash twist and get that 30-day free trial and $250 in credits. Thanks again to Outgrow.co for supporting the show. SPEAKER_05: Welcome back to This Week in Startups. We're having a terrorizing, dystopian discussion about privacy and the lack of privacy people have. But there is now regulation, which is making it extremely costly. And all this scary stuff we've been talking about and my misconception that consumers could protect themselves to a certain extent. I still believe they can sort of protect themselves. But I'm kind of getting education here that it's, in your mind, a never-ending battle. And that's probably correct. SPEAKER_48: So, Ben, tell me, what about Apple now doing interesting things? Like, I noticed when I was logging into a bunch of apps, they said, SPEAKER_04: Hey, you want to log in with your iTunes credential, which is Jason Eccalacanis. And do you want to use an email relay so they don't actually get your email? Which is sort of like the Craigslist email relay, I think, where I guess they're going to give you give that person a unique forwarding email. This seems like they're really going over the top. And then I noticed they fixed the camera roll thing where I guess people were taking your camera roll. You give them access to your camera. They would have access to all your photos. Now they're saying, only give this app access to the photos that I specifically, explicitly give them, not give them access to it. And then I think the clipboard was another issue. TikTok had access to people's clipboards. So if you were using a password manager and you clipped your password, now the Chinese government has your password for whatever app that was. And people don't change their passwords. And okay, now they're in your Gmail, your bank account, create terrorizing stuff. David Friedberg: What do you think of Apple's performance here? Can Apple save consumers privacy or not? SPEAKER_11: I think they can do a lot as a hardware platform. So locking down APIs is something that we're seeing across most major platforms. Um, and there's good reason for it because we do find that there are companies that find, uh, ways to sort of abuse those APIs, which may otherwise be used for perfectly good reasons. Um, so, you know, the geolocation API, it does make sense that an app should ask you before getting your geolocation. So you may not want to disclose geolocation to, you know, a newspaper app or something, right? SPEAKER_185: Or Facebook. Like, why should I be getting a Facebook mine location? SPEAKER_22: Right. And so, so Apple is, is pursuing that and making sure that they aren't leaking more data than they need to. SPEAKER_11: And if you look at Cambridge Analytica, this is the exact same thing. So Cambridge Analytica was using Facebook APIs that were more permissive than maybe they should have been. SPEAKER_22: And they were able to find a way to, to exfiltrate data on about 70 million Americans, um, and build psychological profiles from that. So, um, yeah, the, it, it makes sense what Apple is doing and they've also, um, they've also taken this charge on privacy in general. SPEAKER_11: So I think they've really woken up to the fact that consumers are, uh, having this growing distrust of Silicon Valley and that they are starting to value companies who go out of their way to protect their privacy and start turning this narrative around. Um, so, so yeah, the, I applaud Apple for what they're, what they're doing. SPEAKER_04: And, and, and that, that is a viable way to do it. They took out the Mac address, right? You used to be able to know the Mac address. So I think is what it's called of the iPhone. So you would actually be able to know the hardware basis whose phone that was. I mean, talk about fingerprinting, you knew the, the actual hardware. Um, but when you were, uh, undergrad at Harvard, you reached out to 21 companies to try to get your, uh, data, explain that little, uh, experience that you did. SPEAKER_189: And, and why did you choose to do that? SPEAKER_60: Yeah. So, uh, my co-founder and I were classmates and we would spend a lot of late nights together, uh, just hacking on personal projects. SPEAKER_22: Um, one of them that we decided to do was, um, basically study ourselves. So, uh, let's do data science and let's figure out, um, how things like our sleep patterns correlate with our productivity during the day. And the first step of that is let's go get our behavioral data. Right. And so we knew these apps, um, on our phones, on our laptops, they had all this behavioral data. And, um, and really it's, this data kind of paints the picture of our lives. It's kind of our life story. And, um, so we went to these companies and we asked, uh, you know, can we get a copy of this information? And when was this five years ago, 10 years ago, five years, four, four and a half. Yeah. Yeah. Um, and immediately hit, we hit a brick wall. No company was willing to give us access to any of that information. And we didn't think that made any sense, uh, surely as a consumer, I should be able to know the information, uh, did Twitter have the download feature. SPEAKER_48: You could download, I used to download all your tweets, but you wouldn't know the data they had on you, like IP addresses you'd use or whatever. SPEAKER_60: Yeah. So a lot of companies started building some export features. SPEAKER_22: Uh, it's kind of like a layer one export under new laws, like CCPA, um, under GDPR and SPEAKER_11: under upcoming federal privacy regulation, it's like everything you have to go all the way down into the full stack. And so that's, that's a pretty big change there. SPEAKER_202: Uh, when you look at the backing up of data, I always thought this was interesting because SPEAKER_04: I tried to close my Facebook account at one point. It was like really hard to do. They make it just insufferably hard to get your data off of there. But I'm curious, um, if I would successfully get my data from Facebook and ask them, I SPEAKER_05: don't want you to have any data on me, all my data, I want it wiped. Don't they have backups over time of the entire system? So in cold storage, or maybe on tape somewhere, I know it sounds crazy. Um, so what happens to that data? Are they, if I asked them to wipe my stuff with GDPR and they've got a backup tape somewhere in a server room or somebody made a mirror of that data, whatever, how does backup policies? I know this is wonky, uh, play into this because then couldn't they restore my entire profile down the road? SPEAKER_22: Yeah, it's, it's a great question. And this is something that gets covered a lot in, in GDPR and CCPA. Um, what we see is either the company stops backing up personal data. SPEAKER_11: That's the rare scenario. The more common scenario is they keep a list of who not to restore. SPEAKER_85: And so they technically have it, but they have a do not restore list. SPEAKER_22: Yeah. SPEAKER_60: And that's about the best that most companies can do. And, and, and it's a hard problem, right? SPEAKER_85: I can't blame them for, yeah, you have to go restore the tape, delete it and back it up again. It's like almost impossible, right? SPEAKER_22: Yeah. So, so it's, it's fairly common practice, uh, to see that, um, whether the law permits it is another question, but I think most companies have decided that that is something that is, uh, kind of crosses the threshold of like risk versus reasonable. SPEAKER_54: So, what are these, um, virtual assistants, whether it's Alexa or Siri, what kind of data SPEAKER_04: are they storing and are you personally concerned about that? David Friedberg: What would you tell your mom, your dad, your cousin, your brother in terms of, should I have these in my house? SPEAKER_72: Yeah. SPEAKER_11: I mean, and I'm not, I'm not an expert on this, uh, but I know they have audio recordings, right? So they actually do take the audio recordings. They don't trans transpose it on the device. Um, so it goes to a server and it gets backed up. Um, so it is a little bit concerning. Uh, you know, we have microphones in our houses now. SPEAKER_22: Um, to some extent we are putting our own wiretaps in. Um, I am not, yeah, I mean, I'm personally, I'm like everyone else in terms of like what consumers want. I think these technologies are also great, right? I, I, I have an Alexa in my house. Um, and so I'm not, um, overly paranoid about, you know, having these microphones in the home, but I do think it's important that these companies are making it very clear to consumers, right? SPEAKER_11: Like the fact that these recordings are, are safe, right? I think that's something more consumers should know. I think. SPEAKER_218: What do you charge for your service? I'm curious. And what, what point should a startup start using your product? SPEAKER_22: Yeah. So, um, so I'll start with the former, so, or sorry, with the latter. So, um, it depends on the region that the company is operating in. And so just to, just to zoom out for a second, we've talked to a lot about GDPR today, but there, these laws are going everywhere, right? It's like every region in the world has a privacy law, including, uh, or has a privacy law being made, including the United States. And so I think within two and a half years, we'll have something as strict or stricter than GDPR. Really? In America. Yeah. Um, this is, this is actively, um, being, uh, drafted in Washington right now and everything that's in GDPR is basically already a given and it's, it's about what else. Um, so this is coming no matter what. And so actually just to go back to that European question, should companies leave Europe? They can only hide for so long. So, um, so startups should, uh, startups in California should check out CCPA, see if it applies to them. It doesn't apply to all startups. So once you cross a certain threshold of users, uh, or if you sell user data, then you should start, uh, working to comply with these laws. Um, at Transcend, the companies that we typically serve are larger mid-market companies, right? So these are the Robin Hoods, the Patreons, the Indiegogos, the HashiCorps, um, and that's kind of our sweet spot, but it doesn't mean that startups shouldn't start from a place of SPEAKER_11: thinking about privacy by design. SPEAKER_34: So, and so how do you charge? I'm curious. SPEAKER_04: Is it by the footprint is just somebody like raw, like a Robin Hood level, you know, say millions of accounts, tens of millions in revenue. So put Robin Hood out of that, but just let's say somebody had not Robin Hood, but somebody SPEAKER_48: had millions of accounts and they did tens of millions in revenue. Do you charge them based on the users, the revenue, the jurisdiction, and are you charging SPEAKER_114: them 10,000 a year or a million dollars a year? What does it cost to use this software for that level of startup? SPEAKER_22: Yeah. So, so we charge based on, uh, a base platform fee plus usage. So the usage is when users exercise their rights. Got it. Um, so if someone says download my data, um, and then it also, the usage is also, uh, based on how many data systems there are. So at company X, there may be a hundred data systems and a thousand requests. Um, so a hundred thousand, uh, credits there. Um, and, uh, and so it scales like that. Um, so typically we charge, um, in, uh, I, I, I don't want to disclose everything here, but, uh, typically the, the pricing is, is like within 50,000 to, uh, half a million. SPEAKER_227: A year. SPEAKER_22: Mm-hmm. SPEAKER_04: Yeah. It seems completely reasonable. If you were to put two or three engineers on it, you'd be spending a lot more. Uh, so, I mean, that's sort of how SAS works best, right? Is when the cost of doing it yourself is five times more or 10 times more, you know, in terms SPEAKER_05: of time and headache and cost than just finding a solution for it. And a big part of what you're doing too, is if I have data and I'm using something awesome like Zendesk, or I'm using Salesforce, I have copies of my user data, not just on my platform, but Patreon, if they were using Zendesk as an example, or Robin who was using Zendesk, or they were using Salesforce or HubSpot, they might have that data in five locations. So when they delete it on their servers, who's responsible for deleting that data off of a Zendesk or, uh, or, you know, those tickets off of a Robin hood or a Salesforce rather or a HubSpot, is that the responsibility of HubSpot or the responsibility of the company that was using HubSpot? SPEAKER_22: Um, it's the responsibility of the company that was using HubSpot. Got it. SPEAKER_11: HubSpot does have the obligation to the customer to provide a way to do that. Um, so if HubSpot has an API, if HubSpot has an API or some method that, uh, their customers SPEAKER_22: can follow to run those erasures, um, then, then HubSpot is clear. Um, that's, and that's the, what we do is we power that whole vendor relationship network because to the, to us, those are just more data systems. And so, um, you know, you, you said there may be five vendors. Typically this is like hundreds, like it is incredible. Yeah. How many data systems there are in these businesses. Yeah. And when you look at just the, just like the dispersion of personal data, it really is like throwing confetti into a ceiling fan. It's just literally everywhere. SPEAKER_239: Yeah. SPEAKER_48: I mean, if you had, if you were using like Twilio or send grid, they probably have a whole set David Friedberg: of data they're storing where they might have the phone number and the number of times you've called them or the emails, the number of times they've opened the email on their servers. SPEAKER_04: In addition to yours. Yeah. And that's the reason you guys exist. Yeah. That's right. SPEAKER_244: Fascinating. SPEAKER_04: Right. Is there the equivalent of ambulance chasers who are looking at this new regulation to specifically shakedown companies? I know, um, there were people who were taking accessibility and they were going and, um, you know, which with ostensibly good intent saying, Hey, this doesn't work for somebody who's blind or who, you know, is deaf. SPEAKER_05: Um, but they were basically going after people and just shaking them down. These law firms were taking 30 K a pop. Every time they found somebody who was venture back, they would just go down the venture list. If you raised $5 million and your accessibility wasn't good, they would just bam you with a $50,000 fine, or they would shake you down. Basically they're threatened to sue you and take it to, uh, all the way. Does that exist yet in this space where people are filing complaints on behalf of people to David Friedberg: try to sort of make a quick buck? SPEAKER_22: Well, it looks like that, uh, under CCPA that this is very likely. Um, so CCPA does have a private right of action, which means that, um, people like you and me can bring civil suits, uh, and say, I'm suing company X because, uh, they've violated my data SPEAKER_11: rights, which means you can have class action suits. You can have legal teams who, uh, earn money based on this. SPEAKER_22: Um, in Europe, it's a little bit different where it's a governing body, right? It's like you have the police and you have the courts. Um, so there's a little bit less of those civil lawsuits. Um, what we're likely to see in, um, in the federal government, uh, with the, with a new federal privacy law is, um, the current thinking is that it will probably be no private right of action if there's a Republican government and a private right of action if there's a democratic government. It's not for sure. It could go either way still. But, um, and, and the other part that's likely to happen is that the federal law will override CCPA. SPEAKER_11: So whatever happens at the federal level will become, uh, will become unanimous. SPEAKER_48: And this would become civil litigation. You basically have the GDPR providing a framework for people that then sue and get some monetary SPEAKER_18: damages. SPEAKER_254: Well, the, the, the CCPA. Yeah. SPEAKER_48: The CCPA. The California one. Yeah. Cause the GDPR one, you're saying they have their own enforcement team. David Friedberg: So you can't take an individual can't take action or they would, they could file a complaint SPEAKER_255: with the GDPR, I guess. They can file a complaint to the government, to the DPA. SPEAKER_04: Do they get money if there's a fine or the fine gets taken by the EU or who gets the money from the fines? SPEAKER_22: I think it's the DPA. Um, there may be some ability to recoup, uh, in GDPR. I actually can't remember on that point. Yeah. I wonder what the CCPA, uh, CCPA is going to have damages. SPEAKER_05: Yeah. Companies are paying damages to individuals. What should the damages be? If you, uh, you know, expose my reading habits, my password, what would be a, what's the SPEAKER_38: fine? What should be the penalty on companies that, you know, uh, are tracking stuff they didn't tell me about, or they, I asked them to remove my stuff and they didn't actually remove it. SPEAKER_60: Yeah. So this typically comes with data breach. SPEAKER_11: So at the next data breach, if you're a part of it, you may get one of those letters saying, uh, you know, we're opening a class action. You're, you're entitled to compensation of, uh, up to $750, um, or, uh, any, any additional actual damage. So if you, um, if like it resulted in your identity being stolen and you can prove that SPEAKER_17: like you lost a hundred thousand dollars, you're also entitled to recoup. Hmm. David Friedberg: And so there's no disclaimer you can put on your website or service that says, Hey, listen, SPEAKER_04: this is, this service is as you, uh, is provided as is we're not storing any of your data. You know, there's really no way to get around this. Now this is legislation. It's going to be the law of the land. SPEAKER_18: You're going to have to be compliant as a, as a at scale startup and quickly, probably all startups. SPEAKER_60: Absolutely. Yeah. Yeah. And, and, and just, just to show the, the more positive spin and the opportunity that SPEAKER_22: they're also, uh, that we're also seeing now, users really want to work with companies who respect their privacy. Uh, we, we did a survey, um, uh, with Kelton, um, the research firm. Uh, and we do this annually and we asked consumers whether they would switch to a company that, you know, all other things equal would, uh, it protects their privacy better. And 93% would switch consumers really do care. And, and it is something like 43% would pay more. Um, so there actually is a strategic opportunity and this is why we see Apple spin up an entire privacy marketing division and all these like privacy that's iPhone ads. It's a result of this new consumer trend where consumers really, really want to, uh, work with. SPEAKER_48: Yeah. I mean, it's going to become a marketing plan. I, I, I don't understand why Facebook. Facebook doesn't just, you know, tomorrow prompt people and say, if you want to pay $10 a month or $15 a month for Facebook, we will not store or share any of your data. Yeah. And done. Because if they did that, how are people going to complain? It's like, it's free if we can sell your data and it's paid if you don't want us to even have your data. The end. I mean, wouldn't that be acceptable to you? SPEAKER_271: Um, I, I wouldn't be, I, I, I think it would be acceptable. SPEAKER_60: I think it would probably be feel like extortion to some reading that, you know, we, if you give, SPEAKER_22: if you pay up, we won't sell your data. But, uh, I, I, I could see that being a way to have people switch over. Um, but I don't know. I mean, I don't, I don't know the internals of Facebook. I don't know what it's worth to them and what the tradeoff is. SPEAKER_153: I mean, I, what percentage of people do you think would actually take them up on that? SPEAKER_76: I don't know. Uh, I don't really use Facebook. Me neither do I. It's too creepy. I don't get a lot of value out of it. SPEAKER_04: I gotta think it would be like low one, maybe one or 2% of people would, would opt for a paid version and just to see no ads. SPEAKER_05: It's just like Hulu has like the Hulu premium with no ads where you can get it for, for five extra dollars, you get it with no ads, or I'd pay for my NBA league pass with no advertising. It's not a really a privacy issue, but it's more just the annoyance of ads. And they just show you the cat for an extra 10, 20 bucks a year. Instead of showing you ads. During the commercial breaks, they show you the in house camera of the garden, which I just like to see what they're doing. SPEAKER_38: And the throwing t-shirts in the audience or whatever, just sort of interesting watching anyway for 20 extra bucks. But, um, it does feel like security and privacy as a service will be a great marketing tool. And, and Apple is, is leading that Google and Facebook can't, can't hope to compete in that because their entire businesses are predicated off of data. SPEAKER_69: Well, those businesses collapse if they can't, I mean, I think they are constantly complaining that they can't provide these kinds of free services if they didn't have data. Do you think that's true? Um, do you think they need as much data as they have? SPEAKER_72: I think it would, they don't, but I think they've benefited greatly from the amount of tracking they've done. SPEAKER_11: And to some extent, they've kind of already gotten their lead here. And so even if this disappeared tomorrow, you know, the machine learning models have been trained to an extent and may not be trained better tomorrow. Uh, but even if they threw out the raw data, they have a pretty big, uh, lead and they've figured out a lot of the psychological profiles of folks. So it's, it's, uh, it's a difficult one. SPEAKER_22: Um, you know, even if you force Facebook to, uh, minimize the new data they collect, um, it's, it's pretty, they're pretty far along. SPEAKER_206: Um, and so, so they have this psychographic profile of everybody already and they have all the algorithms trained. SPEAKER_04: They know who should be getting ads for depression medication versus high blood pressure medication versus pregnancy tests or birth control, whatever it is. They just know already. So they don't need to worry about it. Would you, do you think, uh, apps out of China are safe for Americans to use? SPEAKER_52: If you were the president, would you block a tick tock from being in the United States? I'm curious how you think about that? SPEAKER_11: Yeah. Um, so I do believe in the national security concern around it. Um, this is the same thing that's happened with other apps. Um, so under the Obama administration, um, they did the same thing and they requested that hinge, um, or sorry, grinder, uh, switch, uh, to an American company. SPEAKER_102: And they, they split it, uh, because they were concerned that this information maybe wouldn't be so good, uh, if, if the Chinese government had access to this. SPEAKER_04: I mean, explicitly think about it. If there was somebody who was closeted, I mean, it's the, that's the classic compromise that Russia used against people. Tragically, somebody was a closeted homosexual in the United States in the cold war or whatever. SPEAKER_206: And now they've got that over their heads. Hey, we're going to tell your family you're gay or your wife. Uh, now your whole life's going to come apart. SPEAKER_114: And if you have that data on Grindr, you know, when people were meeting up with and who was meeting up with who, I mean, can you imagine if the, what the Chinese could do with that data? Oh my Lord. SPEAKER_11: Exactly. Yeah. So you, you don't want this data to be in the hands of intelligence. Um, and I actually think it's, it's perfectly reasonable. SPEAKER_22: Yeah, me too. And, um, and yeah, so it, it, it's going to happen. Um, and, and it's, it's, it's actually a good thing that we're, uh, being a little bit more careful about, uh, the information held by other companies. SPEAKER_11: I mean, the reality is, is it's all just happening in our backyard instead. SPEAKER_22: Yeah. Um, you know, the, the Snowden revelation showed very clearly that this is happening in America as much as you might suspect it would be in China. SPEAKER_303: As much or maybe not as much. And certainly we're not putting people into concentration camps based on that data. So, you know, when we do the, when we do the also ism or whatever they call that, like, but isms, like, it's like a communist country might actually act on this data. SPEAKER_166: Whereas an American company might spy or the American government might spy or an American company might spy and they might have edge cases of people using it. Right. SPEAKER_38: It's institutionalized to put the Uyghurs into concentration camps, institutionalized to find dissonance or people selling books, uh, and, and have them reeducated. I'm using air quotes here, which, you know, is colloquialism for torture. SPEAKER_22: So I agree that the U S government is not, uh, is not using it in extremely malicious ways right now, but I think it is something to be concerned about when the government has that degree of information. Yeah. I mean, Edward Snowden would call this turnkey tyranny, right? Where it's like, as soon as you get the wrong person, it's, it's pretty scary. Yes. You have the infrastructure in. Yeah. David Friedberg: So I wonder where that puts you on the issue of like full scale encryption, uh, the unlocking of the iPhone case or point to point encryption. SPEAKER_69: You know, we've heard, Hey, it's gonna be impossible to catch pedophiles or terrorists if they have this end to end decryption and law enforcement has always had it previously. And all the FBI agents who speak on this subject are like, listen, we really need this tool. SPEAKER_04: If you take this away from us, we're not going to be able to catch these, you know, child trafficking rings or, uh, terrorists. That's obviously true. They're going to have a really hard time catching them if they, if they use that end to end encryption. So where do you stand on that? Do you think the iPhone should be or WhatsApp or any point to point encryption signal? SPEAKER_69: I'm not sure which ones have the best encryption, but do you think the government with a subpoena should be able to backdoor those systems? SPEAKER_60: With a subpoena. Yes. Yeah. SPEAKER_11: And, and so I, but we're not, we're not in that default right now. So end end encryption can still have back doors that can be opened through subpoena. Where we're at right now is actually a different default, which enables dragnets, which means all of our data, all of our communications are being analyzed today. SPEAKER_212: The metadata, not the actual calls themselves. SPEAKER_22: The metadata is more than enough, uh, to, to, to figure a lot of things out. So, you know, someone calls, uh, their sister and then immediately calls their husband or something. And like, there's all these little stories that come out of the metadata. Um, and, um, and so the, we're in the default of allowing for a dragnet and I don't, I don't think we should have dragnets on us citizens. That's what, that's my stance. So, um, end to end encryption, I think blocks that. SPEAKER_11: Uh, but it's not hard to, um, you know, be able to open a back door. Yeah. Yeah. SPEAKER_18: Yeah. Yeah. Israeli companies to unblock that iPhone. I think for the San Bernardino shooter back in the day, it seems like the Israelis have some pretty good technology on this front. Uh, well, listen, Ben, you've been tremendously honest and helpful in all of us thinking about this and congratulations on you guys who raised a bunch of money and you're off to the races. SPEAKER_69: And I think it's really great that you're helping companies navigate this and think about this from first principles because for anybody who's building a company out here, just assume that, you know, whatever shady shit you're doing, you're going to get caught at some point. SPEAKER_04: And it's going to be a pretty big, um, you know, hole in the side of your ship. And if your ship's big, it could sink your ship or any hole could sink a ship. Like, be careful and only collect what you need and what you would be proud to share with your users. I mean, if you said to a user, Hey, you programmed in, in your Tesla home and office so that when you get in the car, it automatically turns on the navigation. Seems reasonable, but may not want the cameras on my Tesla on all the time and may want to have the option to turn those off. Right? Like, I think there's some common sense here that seems to have gotten lost in an industry that just said the default is collect all data. SPEAKER_114: The default means to collect no data. Yeah. I say collect nothing. SPEAKER_321: Mm hmm. SPEAKER_114: Just don't even collect it. Just build the business without the data. And then if you have a real reason to use the data, that makes sense. SPEAKER_98: Yeah. SPEAKER_324: Basically the best starting from that place of respect, giving can users easy choices. Yeah. SPEAKER_326: I mean, I don't know if you've ever gone to that Facebook privacy center on the choices there. I mean, that is, I can't figure it out. I'm in the industry. SPEAKER_138: You know, I've been on Facebook since the day it opened and I can't figure it out. SPEAKER_328: Convoluted. Yeah. SPEAKER_05: I really think if Facebook, I think if Facebook hadn't, if, if we didn't have Zuckerberg in the industry, I think that how people would look at the entire industry would be different right now. Yeah. SPEAKER_38: I think they really just poisoned the well and you know, like a lot of the goodwill is gone. Right. Uh, for our industry. Interesting. SPEAKER_219: Yeah. You believe, you believe that, that there were the big offender. SPEAKER_11: I, I, I certainly agree that Facebook is, is one of the bigger offenders right now. Yeah. Uh, I, I think if it weren't Facebook, it would be someone else as well. Interesting. I think we have been in a void, um, where there's been very little regulation and a lot of money to make. SPEAKER_22: Yeah. SPEAKER_280: Yeah. I think there has to be regulation. SPEAKER_04: That's, I mean, after this discussion with you for an hour, what I realize is my position has been take control of this, you know, don't be a victim, use a VPN. SPEAKER_69: I've always used fake accounts on certain sites just so, you know, like people don't have a recognizable name. It's misspelled at Ellis Island, but you know, like, and I'm using privacy.com burner cards now. SPEAKER_54: And, you know, I'm proactive about my privacy to a certain extent. Um, but the truth is, you know, we need to have some sort of standards here for people to take it more seriously because there are bad actors or, you know, clever actors are even probably worse than the bad actors. SPEAKER_206: The bad actors, at least you know, they're why they're doing it. It's just people who are clever, right? Like Facebook's a little too clever. SPEAKER_18: Yeah. And their approach to all this. All right, listen, continued success, Ben. And I really appreciate you being on the pot and we'll see you all next time on this week in service.