🆕 Software Suggestion | Cozy Cloud #2401

Open
opened 2021-08-03 08:54:18 +00:00 by fgamess · 5 comments
fgamess commented 2021-08-03 08:54:18 +00:00 (Migrated from github.com)

Basic Information

Name: Cozy Cloud
Category: Provider/Cloud Storage
URL: https://cozy.io/en/

Description

I do believe that Cozy Cloud should be mentioned on your website as it provides multiple secure cloud services (bank aggregator, cloud storage, notes, password manager). They seem pretty transparent and concerned about the privacy of their customer.

Why I am making the suggestion

Cozy Cloud is a set of open-source services that give you the ability to store and manage multiple data that you own on the cloud.

Cozy Cloud seems to give detailed information about how they collect and process our data and with who on the Privacy page

It provides multiple services:

Cozy Cloud is located in France and so will be your data when stored on their servers. Might be a source of concern?

My connection with the software

I am simply an early adopter. I used it several times.

  • I will keep the issue up-to-date if something I have said changes or I remember a connection with the software.
## Basic Information **Name:** Cozy Cloud **Category:** Provider/Cloud Storage **URL:** https://cozy.io/en/ ## Description I do believe that Cozy Cloud should be mentioned on your website as it provides multiple secure cloud services (bank aggregator, cloud storage, notes, password manager). They seem pretty transparent and concerned about the privacy of their customer. ## Why I am making the suggestion Cozy Cloud is a set of open-source services that give you the ability to store and manage multiple data that you own on the cloud. Cozy Cloud seems to give detailed information about how they collect and process our data and with who on the [Privacy page](https://cozy.io/en/privacy/) It provides multiple services: - [Cozy Banks](https://cozy.io/en/features/#bank) is a bank aggregator licensed under [GNU AGPL-3.0](https://github.com/cozy/cozy-banks/blob/master/LICENSE). Source code can be found on GitHub: https://github.com/cozy/cozy-banks - [Cozy Pass](https://cozy.io/en/features/#pass) which is a password manager like BitWarden or KeyPass. It is licensed under [GNU GPL-3.0](https://github.com/cozy/cozy-pass-mobile/blob/master/LICENSE.txt). Source code can be found on GitHub: https://github.com/cozy/cozy-pass - Cozy Notes is an application that gives you the ability to save personal notes on the cloud like Joplin. It is licensed under [GNU AGPL-3.0](https://github.com/cozy/cozy-notes/blob/master/LICENSE). Source code can be found on GitHub: https://github.com/cozy/cozy-notes - [Cozy Drive](https://cozy.io/en/features/#synchronise) is a cloud storage that gives you the ability to store and manage files like NextCloud. It uses cozy aggregators and third-party aggregators to grab data and files from other services that you use. It is licensed under [GNU AGPL-3.0](https://github.com/cozy/cozy-drive/blob/master/LICENSE). Source code can be found on GitHub: https://github.com/cozy/cozy-drive Cozy Cloud is located in France and so will be your data when stored on their servers. Might be a source of concern? ## My connection with the software I am simply an early adopter. I used it several times. - [X] I will keep the issue up-to-date if something I have said changes or I remember a connection with the software.
ph00lt0 commented 2021-08-03 09:36:47 +00:00 (Migrated from github.com)

Self hosting is possible: https://docs.cozy.io/en/tutorials/selfhost-debian/

I am a bit concerned about their privacy page. The link @fgamess included is not the actual privacy policy. The actual privacy policy is listed at the bottom can be found here: https://files.cozycloud.cc/TOS-4.41.1.pdf. This is actually the full TOS, but they are only available in French. Under GDPR it is required to provide a privacy policy in the language of the countries you are active.
The TOS under 4.11.1 mentions that Cozy still shares data to countries in the Privacy Shield scheme. This has abandoned by the EU court of Justice (Schrems II) and may no longer be used. Sharing EU personal data with companies in the US such as Stripe and Mailchimp are still a tricky business. The only options to do so are with a BCR or SCC contract and because the US does not offer the same level of data protection, additional measures are required. (https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32021D0914&from=EN). The fact that they have no mention of this and the TOS is either outdated or against the law should raise a red flag.

Self hosting is possible: https://docs.cozy.io/en/tutorials/selfhost-debian/ I am a bit concerned about their privacy page. The link @fgamess included is not the actual privacy policy. The actual privacy policy is listed at the bottom can be found here: https://files.cozycloud.cc/TOS-4.41.1.pdf. This is actually the full TOS, but they are only available in French. Under GDPR it is required to provide a privacy policy in the language of the countries you are active. The TOS under 4.11.1 mentions that Cozy still shares data to countries in the Privacy Shield scheme. This has abandoned by the EU court of Justice (Schrems II) and may no longer be used. Sharing EU personal data with companies in the US such as Stripe and Mailchimp are still a tricky business. The only options to do so are with a BCR or SCC contract and because the US does not offer the same level of data protection, additional measures are required. (https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32021D0914&from=EN). The fact that they have no mention of this and the TOS is either outdated or against the law should raise a red flag.
fgamess commented 2021-08-03 10:08:00 +00:00 (Migrated from github.com)

These are good points @ph00lt0 I am not so rigorous yet when checking because I just started to be concerned by privacy in fact. Then perhaps cozy isn't a good suggestion

These are good points @ph00lt0 I am not so rigorous yet when checking because I just started to be concerned by privacy in fact. Then perhaps cozy isn't a good suggestion
ph00lt0 commented 2021-08-03 15:46:11 +00:00 (Migrated from github.com)

@fgamess hey no worries. It's good to look into these. I am not saying that they should not be recommended but it would require some changes on their side.

@fgamess hey no worries. It's good to look into these. I am not saying that they should not be recommended but it would require some changes on their side.
lynn-stephenson commented 2021-08-03 23:54:47 +00:00 (Migrated from github.com)

I am taking a look at the source code, but I don't immediately see how this is any more private than other cloud providers. There does not appear to be any E2EE. Besides, I already have a plan to develop a self-hostable file management server (ahem, "cloud storage") with E2EE.

I am taking a look at the source code, but I don't immediately see how this is any more private than other cloud providers. There does not _appear_ to be any E2EE. Besides, I already have a plan to develop a self-hostable file management server (ahem, "cloud storage") with E2EE.
fgamess commented 2021-08-04 06:00:47 +00:00 (Migrated from github.com)

@lynn-stephenson good catch https://help.cozy.io/article/110-does-cozy-encrypt-my-data
They say Cozy encrypts passwords and connections. The data stored in Cozy is not encrypted, as this would negatively affect the overall user experience. We are considering implementing partial encryption of data stored in Cozy.
So I don't know the ETA on this point for today. I will try to contact them to know about the progress.
additional link: https://blog.cozy.io/en/encryption-cozy/

@ph00lt0 about this Under GDPR it is required to provide a privacy policy in the language of the countries you are active.
I will notice them about that once have some free time.

@ph00lt0 @lynn-stephenson we need to see if they are open to suggestion and improvements about security and privacy

@lynn-stephenson good catch https://help.cozy.io/article/110-does-cozy-encrypt-my-data They say _Cozy encrypts passwords and connections. The data stored in Cozy is not encrypted, as this would negatively affect the overall user experience. We are considering implementing partial encryption of data stored in Cozy._ So I don't know the ETA on this point for today. I will try to contact them to know about the progress. additional link: https://blog.cozy.io/en/encryption-cozy/ @ph00lt0 about this _Under GDPR it is required to provide a privacy policy in the language of the countries you are active._ I will notice them about that once have some free time. @ph00lt0 @lynn-stephenson we need to see if they are open to suggestion and improvements about security and privacy
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#2401
No description provided.