Privacy of Streaming Apps and Devices
Total Page:16
File Type:pdf, Size:1020Kb
2021 PRIVACY OF STREAMING APPS AND DEVICES: WATCHING TV THAT WATCHES US Common Sense is the nation's leading nonprofit organization dedicated to improving the lives of kids and families by providing the trustworthy information, education, and independent voice they need to thrive in the 21st century. www.commonsense.org Common Sense is grateful for the generous support and underwriting that funded this report from the Michael and Susan Dell Foundation, the Bill and Melinda Gates Foundation, and the Chan Zuckerberg Initative. CREDITS Authors: Girard Kelly, Common Sense Media Jeff Graham, Common Sense Media Jill Bronfman, Common Sense Media Steve Garton, Common Sense Media Data analysis: Girard Kelly, Common Sense Media Jeff Graham, Common Sense Media Copy editor: Jennifer Robb Designer: Jeff Graham, Common Sense Media Suggested citation: Kelly, G., Graham, J., Bronfman, J., & Garton, S. (2021). Privacy of Streaming Apps and Devices: Watching TV that Watches Us. San Francisco, CA: Common Sense Media This work is licensed under a Creative Commons Attribution 4.0 International Public .License TABLE OF CONTENTS Privacy of streaming apps and devices 1 What are streaming services? ......................................... 1 Apps we rated ............................................... 1 How do streaming services make money? ............................... 2 How we rate privacy ........................................... 2 What we found .............................................. 6 Compare privacy ratings ......................................... 6 What are streaming devices? .......................................... 7 How we test security ........................................... 7 Devices we rated ............................................. 8 What we found .............................................. 11 Compare privacy ratings ......................................... 11 Compare security practices ........................................... 12 Data sharing ................................................ 14 Data safety ................................................. 14 Account protection ............................................ 15 Parental consent .............................................. 16 Child privacy policy ............................................ 18 Advertisements, marketing, and tracking ................................ 20 Software updates ............................................. 25 Security testing methodology ......................................... 25 Security framework ............................................ 25 Security testing .............................................. 26 Network testing environment ...................................... 27 Process overview ............................................. 28 What should parents and educators do? ................................... 30 What should streaming apps and devices do? ................................ 31 Children and data privacy ............................................ 32 Appendix 33 Traffic analysis methodology .......................................... 33 Tracking categories ............................................... 33 App traffic analysis ............................................... 34 Amazon Prime ............................................... 34 Apple TV+ ................................................. 34 Discovery+ ................................................. 35 Disney+ .................................................. 36 Hulu ..................................................... 37 Netflix ................................................... 38 Paramount+ ................................................ 39 HBO Max ................................................. 41 Peacock ................................................... 41 YouTube TV ................................................ 43 Device traffic analysis .............................................. 44 Amazon Fire TV Cube .......................................... 44 Apple TV .................................................. 48 Google TV ................................................. 50 Nvidia Shield TV .............................................. 53 Roku Smart Streaming Stick+ ...................................... 56 "Do not sell" links ................................................ 59 Apps .................................................... 59 Devices ................................................... 59 CREATIVE COMMONS ATTRIBUTION 4.0 INTERNATIONAL PUBLIC LICENSE PRIVACY OF STREAMING APPS & DEVICES TV+ or Netflix, and more complex streaming apps PRIVACY OF that offer multiple subscription services with access to hundreds of other third‐party content channels. There are even streaming apps designed only for STREAMING APPS one specific genre or type of content, like animated kids programming, cooking, sports or talk shows, or apps associated with only a particular film studio's AND DEVICES content. Some streaming apps collect very little be‐ Consumers, parents, and educators are looking for havioral data, and some say they don't sell your data streaming content services that can be used not to third parties. But others are designed to collect as only for entertainment and personal development, much behavioral data as possible, using thousands but also to support distance learning. However, of data points to create a personalized profile about many households don't have reliable high‐speed a user. internet or sufficient data plans to stream media With so many apps to choose from, it was difficult content, let alone enough adequate devices, such to limit our selection, but we carefully selected the as computers, laptops, TV sets, or tablets. Under top 10 that we believe are representative of most these circumstances, children and students might types of streaming apps available across different use a parent's mobile device and parent's account platforms today. We chose streaming apps based to stream free media content or tutorials, which on the film studios, features, type of content pro‐ may result in the collection of behavioral infor‐ vided, Apple and Google App Store popularity, and mation about their viewing habits and interactions the number of free and paid subscribers. We also with content that could lead to privacy risks1 and chose streaming apps used by children and students harms that may affect children, students, and fam‐ in every major age group at home, on the go, and in ilies. There are many articles available that com‐ the classroom. pare all the "best" streaming apps and services on price, content catalog, and features. However, none Apps we rated of these articles adequately compares streaming apps and services on the most important feature— The streaming apps chosen for this report are listed privacy. This report examines the privacy practices in Table 1. All prices reflect the standard or basic of the most popular streaming apps and devices. streaming plan available as of the publication date of this report. Most streaming apps we tested of‐ fer free trial periods of varying lengths, and some What are streaming include bundled discounts or add‐ons if multiple services? streaming services are purchased together. Others have annual payment plan discounts, and most ser‐ Streaming media apps and services are typically free vices have separate free, basic, or premium price or paid subscription‐based services that offer on‐ plans based on the type of content available. In ad‐ line streaming of TV shows and movies. Many paid dition, many streaming services allow users to pay streaming services offer a free trial period after giv‐ extra to stream additional content on‐demand such ing a valid credit card number. Some streaming ser‐ as renting movies or TV shows that are not included vices are owned by major film studios that pro‐ in the product's main content catalog. duce their own content, while other free streaming We evaluated the privacy policies of the top apps don't produce their own content, but simply 10 streaming apps: Apple TV+,2 YouTube TV,3 integrate third‐party apps to create content "chan‐ Disney+,4 Paramount+,5 HBO Max,6 Peacock,7 nels." Some, of course, offer both original and shared content. However, not all streaming apps are designed to be the same. There are easy‐to‐use streaming apps with only one type of subscription service, like Apple 2Apple TV+, https://www.apple.com/apple‐tv‐plus. 3YouTube TV, https://tv.youtube.com/welcome. 1See Kelly, G., Graham, J., Bronfman, J., & Garton, S. (2019). 4Disney+, https://www.disneyplus.com. Privacy risks and harms. San Francisco, CA: Common Sense 5Paramount+, https://www.paramountplus.com. Media, https://privacy.commonsense.org/resource/privacy‐ 6HBO Max, https://www.hbomax.com/. risks‐harms‐report. 7Peacock, https://www.peacocktv.com. CREATIVE COMMONS ATTRIBUTION 4.0 INTERNATIONAL PUBLIC LICENSE PRIVACY OF STREAMING APPS & DEVICES 1 Amazon Prime Video,8 Discovery+,9 Hulu,10 and How do streaming services make Netflix.11 There are also dozens of completely free money? and ad supported streaming services that aggregate third‐party content such as Tubi TV12, Crackle13, Most streaming apps and services like traditional ca‐ IMDbTV14, and PlutoTV15. Apple TV+ has only a ble TV require a paid monthly subscription to stream single subscription plan, while Peacock has both unlimited content to any TV or device. There are free and paid price plans that include additional also many free streaming apps that make money paid streaming content, such as live sports,