Unroll.me Settles With FTC for Rifling Through Its Users' Email Inboxes to Find Receipts

Image: Unroll.Me, via Facebook
Image: Unroll.Me, via Facebook

Email cleanup service Unroll.me has settled with the Federal Trade Commission and must delete information it gathered from some consumers after it was revealed the firm was mining and selling data from users’ inboxes, the agency announced on Tuesday.


In 2017, the New York Times revealed that once Unroll.me—which was supposed to help users unsubscribe from spam—gained access to inboxes, it scanned them for receipts and sent that data to its parent company, Slice Intelligence. Slice then used those receipts in analytics reports it sold to companies like Uber. Disclosures that the company might engage in this kind of practice were buried deep in the terms of service, and it certainly didn’t help things that CEO Jojo Hedaya’s response to user anger was to issue a non-apology (he wrote it was “heartbreaking” “to see that some of our users were upset to learn about how we monetize our free service”). One of Unroll.me’s co-founders who was no longer with the company, Perri Chase, wrote in a Medium post that those angry about the situation “have clearly been living under a rock.”

The FTC took a somewhat more limited view of how much of this was actually actionable. This settlement announced on Wednesday targets Unroll.me for those instances in which some people declined to give the company permission to access their inboxes or contacted customer support with privacy concerns, and the firm made false statements in an effort to lure them back.

The FTC’s complaint alleged Unroll.me sent marketing pitches to people who declined to give access to their inboxes that it “won’t touch your personal stuff,” and repeatedly assured those who contacted its customer support lines that it was not reading personal email, only “subscription emails.” The settlement bars Unroll.me from misrepresenting the extent to which it collects, uses, stores, or shares information it collects from consumers,” according to the FTC, as well as notify impacted users and delete all electronic receipts it had collected via their accounts. The agreement will be posted to the Federal Register “soon” and subject to a 30-day public comment period before it goes into effect.

“What companies say about privacy matters to consumers,” FTC Bureau of Consumer Protection director Andrew Smith said in the announcement. “It is unacceptable for companies to make false statements about whether they collect information from personal emails.”

"... An upperclassman who had been researching terrorist groups online." - Washington Post



Maybe I’m just out of it today, but I could not for the life of me understand what you meant by receipts. Might have been helpful to describe that in the article.

From the FTC announcement:

E-receipts are emails sent to consumers following a completed transaction and can include, among other things, the user’s name, billing and shipping addresses, and information about products or services purchased by the consumer. Slice uses anonymous purchase information from Unrollme users’ e-receipts in the market research analytics products it sells.