We care deeply about user privacy, and privacy is a key part of our app's design. All user trips and profiles are set to “private/followers only” by default, never public. We communicate to our users when they switch their privacy settings to 'Anyone' that this means publicly accessible, even by people not using Polarsteps.
Follow the Money recently published an investigation into Polarsteps. Despite their claim that this is a data leak, we would like to emphasize that is incorrect. FTM only had access to public trip data and to the best of our knowledge, there has been no data breach.
For clarity: all trip data that was never made public by the user has remained private, and no authentication was bypassed (i.e. no passwords were breached and no one got access to any Polarsteps account or private trips).
Public trip data
The journalists have taken public trip data - where users have actively chosen to share their trips and contents publicly - and information that is public in Polarsteps to allow users to find each other (name, profile picture, mutual followers). You can see here on our support page what this information is.
Following other users
FTM also followed a lot of profiles who had set their privacy settings to “Anyone can follow me” rather than “Only people I approve”. This allowed them to see the trips for followers, because they had become followers of these accounts.
Polarsteps allows people to choose to approve their followers, or not, and our default setting is that people must approve their followers. Some people - e.g. travel writers who want to share their trips to inspire others - will decide to override the default privacy setting and accept any follower.
FTM made use of the auto-follow setting to follow some user accounts set to auto-accept followers. They did not breach any privacy controls. They then saw trips that were set to followers-only on accounts that auto accept followers (a tiny fraction of Polarsteps users). No private data was breached or shared because of this.
You can see here the privacy options available to our users and the default settings, which are always private or follower-only, not public.
Security researcher
The FTM piece also says that a security researcher raised issues with Polarsteps six months ago. To be clear: we read the report by the researcher, and were already acting on the things that were raised in it. It is not the case that we knew about security issues and did not act on them.
Security improvements
This investigation did, however, raise a couple of points around security where we could have done better, and we've taken them seriously, as we truly value our users’ security. We’ve already acted on these - we've implemented even stricter API controls to prevent large-scale access to our public user data, and strengthened protections around our secret link feature (which allows people to share trips with non-followers).
And, as ever, we’re working to improve how users understand what's public versus what’s private for their Polarsteps trips. We’ve also been working over the years, long before FTM’s investigation, to add extra privacy features in our app (e.g. this year adding hide start/end location and hide current location options).
We’re a team that cares deeply about security, and as soon as we become aware of issues, we act on them immediately, as we've done in this case.
If any of our users have concerns, feel free to contact us here: support.polarsteps.com/contact
