Weekly review emails data leak

I’m curious what the real reason for adding such an unwanted feature would be.

I think @lizardfish is right in their post.

My guess is that they expect this feature to drive engagement with the AVOD area of their platform. Plex licenses some content from a big tv/film studio, user gets an email that their friend watched that show, it’s not a show you have on your server so the user watches it via AVOD and Plex makes $$$.

Server owners just aren’t the money makers and since Plex took venture funding, they need growth. This is a very poorly thought out effort at getting users on the more profitable parts of Plex.

5 Likes

The legal ramifications of this action by Plex could be substantial - certainly I would hope that their legal folks double and triple checked that their actions here would be ok, but auto-opting customers into sharing data without their direct consent, on its face, violates a ton of laws, many of which have some fierce teeth. Just a few laws that Plex may have violated…

California Consumer Privacy Act (CCPA)
Colorado Privacy Act (CPA)
Connecticut Data Privacy Act (CTDPA)
Kansas Consumer Protection Act
Utah Consumer Privacy Act (UCPA)
Virginia Consumer Data Protection Act (VCDPA)
Nearly every state has a CPA-equivalent.
Federal Trade Commission Act (FTC Act)
EU General Data Protection Regulation (GDPR)
EU e-Privacy Directive
South Korea’s Personal Information Protection Act (PIPA)
German Data Protection Act (BDSG)
UK Data Protection Act 2018 (DPA 2018)
French Data Protection Act (Loi Informatique et Libertés)
Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP)
Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)
Japan’s Act on the Protection of Personal Information (APPI)

I could go on and on and on. I am not your lawyer; this is not legal advice.

10 Likes

This feature is garbage and should never have been opted in by default to share or receive information like this.

As someone that works for a SAAS company and regularly needs to navigate privacy policies and feature sets, this is truly appalling.

11 Likes

Just want to add my voice as a plex pass lifetime subscriber that I loathe this feature and want plex to walk it back. my friends who use my server also were shocked to start getting emails of what I watched. Nobody wants this. The discover tab in plex isn’t so bad, showing what’s on their "watch list " or shows they want to see, movies they want to see etc. but knowing their actual watch history and having it emailed out is AWFUL.

2 Likes

I briefly skimmed this whole comment section to try to understand more about this, however my conclusion is that it doesn’t matter what was “intended” from this feature, what matters is what actually happened.

What actually happened is that a lot of people including myself had their privacy breached unintentionally and borderline maliciously. It doesn’t matter that a pop up message made you say it was ok, the problem is that the implications of that pop up were so unclear that people did it and didn’t expect the end result. This is extremely shady from Plex and is unacceptable. I will now be going through the painful process of converting all of my family over to a different media server. This sucks.

15 Likes

this is horrifying. wth Plex! This is disturbing in so many ways.

8 Likes

I dont normally post in the Plex forums, but I had to log in JUST to voice my opinion on this new “feature”. Like others here, I opened my email in the last week to find unsolicited emails detailing other users watch history, which is absolutely UNACCEPTABLE. Then, I go in to find all email subscriptions have been enabled, despite disabling them prior. This is a serious breach of privacy and trust and is the sort of thing that can absolutely crater a company’s public perception and user base. I am not sure whether I am more upset about getting these emails or finding out that there is no way to disable it centrally for my server. Now I have to somehow approach each of my users to tell them that their watch data has been breached and made visible to others and now have to somehow walk them through how to turn it all off, or maybe they just dont use it anymore once they find out. NOT ACCEPTABLE!!!

How Plex, its management, its board, and its programmers could implement something like this in this manner without proper safeguards or thought defies all belief. Its like they met up one day and thought “Lets create a massive data breach for profit!”. You guys really need to rethink your direction as right now this data breach is serious enough that I am rethinking my Plex Pass and Plex in general. I’d be very surprised if there arent legal repercussions for what you have done.

Seriously, WTF Plex?

19 Likes

This has been well known by libraries, video rental stores, and so many other media establishments for DECADES, too. I don’t know how they could miss it.

11 Likes

I will be very surprised if this does not result in legal action against Plex of some sort…

5 Likes

What I don’t understand is that I’ve been getting Plex “Week in Review” emails since December 2022. I don’t know if these were just because I was a server admin but it was showing me content that my “friends” watched that definitely isn’t even on my server!

“Another week, another fresh delivery of what your friends on Plex have been watching, rating, and plan to watch next.”

I apparently could stop getting these emails but I wonder if my “friends” even knew they were being sent?!

1 Like

I recognize that plex employees/mods are being intentionally obtuse in calling this “opt-in” because this feature might generate some $$$.

But putting that aside, lets actually think about how a user in going to process this series of screens:

  1. User opens Plex with the intention of watching something, they are greeted with the first screen.

Maybe they’re interested, more likely they’re not, they just want to watch their show and so they click through the first screen

  1. Hit with second and third screens, click through them
  2. They arrive at the actually important modal. The options are set to Friends by default.

The most likely thing is that the user clicks through this without reading. However, if they actually do stop and parse the options, it’s even more confusing.

Users are familiar with the concept of Friends. It’s on every social media site. Making someone your friend is also 100% of the time a process that the user initiates, MANUALLY. Only, in this case, Plex has added everyone you share a server with as your Friend, without asking or notifying you! Putting aside the fact that the Friend concept seems pretty new to Plex, especially with how it’s being used here, users are going to have a false expectation that they do not have any Plex friends.

The average user that stops to read this modal is going to assume that with no friends, nothing will be sent or shared with anyone. They’re going to click through, and would be shocked to know that I’m now receiving a copy of their watch history. They wouldn’t even know that we are Friends.

Never mind the fact that even if they knew, they would need to click into 4 separate drop-downs to manually select “private” before watching their show.

What a ridiculous failure of UX. The default option needs to be changed to Private, and a patch applied for every account that defaulted to Friends which changes their settings to Private.

Better yet, delete this useless feature.

EDIT: Also, this is 10000% a GDPR violation. It cannot be informed consent if the user has no concept of what “Friends” are, or who that group is made of.

18 Likes

Plex appear to have taken the approach of waiting for this to blow over. I wrote and asked for their official response before contacting the privacy watchdog here (the Information Commissioner’s Office) and I haven’t even had my request acknowledged, let alone replied to.

Plex’s position on this matter is clear: We don’t care about your privacy.

11 Likes

I’m sure Plex is going to go through some legal stuff related to this - once that hits their doorstep they’re going to have to respond.

3 Likes

What surprises me is that pretty much no one (bar me) is questioning why a profile was even created! Account yes, I signed up all those years ago and have an account but I NEVER agreed to have a plex social profile and everything that comes with that!

I also cannot delete/remove the profile plex created without deleting my account.

12 Likes

This infuriates me so much that after 14 years I am seriously thinking about finally moving to Emby or Jellyfin. I’m worried about what’s next.

You can file a complaint here:

10 Likes

Just hearing about this. I’m a long time Plex user who has not updated recently, meaning I don’t have any of these features visible on my GUI yet, although I’m not clear if that means my viewing is being shared yet or not.

Is there a simple setting I can enable somewhere that will guarantee that no personal information about me (content viewed, in library, ratings, anything at all) is shared at all with anyone for any reason, now or in the future?

Let me add to the chorus that the idea of Plex deciding to automatically begin sharing my viewing habits is awful & terrible & against the privacy policy I thought was in effect.

4 Likes

Wait, I have a Plex social profile?!? wtf. I never asked for that, didn’t know about it, definitely don’t want it. How can I see it?

How has it gone so wrong with this team?

12 Likes

Investors want to make profits. We got sold out.

6 Likes

May be relevant

Plex Chooses unitQ Artificial Intelligence to Gauge Sentiment, Bolster User Experience

Link to Article

  • unitQ captures user feedback in more than 100 languages from dozens of sources — including Amazon, the Apple App Store, Discord, Google Play Store, Reddit, Twitter, TikTok, Facebook, Instagram, YouTube and more.

  • "unitQ combines user feedback into a single source of truth, and enables leading organizations like Plex to gain a complete view of user feedback in real time to bolster brand reputation and drive growth."

  • Advanced AI technology and machine learning from unitQ are empowering Plex to keep a finger on the pulse of their users.

  • unitQ are empowering Plex to keep our finger on the pulse of our users’ needs to power growth and engagement, and to reduce churn and build brand loyalty."

It appears to me that some half-baked, AI social media bot has decided it knows more about what customers want, than the customers do

If you were looking to improve your reputation and build loyalty, I’m going to say this was a massive failure

I can’t speak for anybody else but I’m not a Facebook, Instagram social media type of person and I think you have miscalculated the kind of customers you serve

This is a “know your audience” kind of situation. It’s like somebody back in the day scheduling Richard Pryor to do a stand-up show in a Church, in front of Nuns and children

If you didn’t anticipate this kind of reaction, I’m embarrassed for you

If you did anticipate this reaction and just don’t care, I’m embarrassed for myself for supporting you and recommending this product to my friends and family

I was going to buy both my aunt, and my sister a lifetime Plex pass for Christmas

NOPE!!!

16 Likes

Right – account is https://app.plex.tv/desktop/#!/settings/account and your profile is https://app.plex.tv/desktop/#!/profile. Two very different things and the second is not something I want or agreed to have created!

10 Likes