| Literature DB >> 35084348 |
Abstract
BACKGROUND: Pulse oximeter apps became of interest to consumers during the COVID-19 pandemic, particularly when traditional over-the-counter pulse oximeter devices were in short supply. Yet, no study to date has examined or scoped the state of privacy policies and notices for the top-rated and most downloaded pulse oximeter apps during COVID-19.Entities:
Keywords: COVID-19; mHealth; mobile apps; privacy; pulse oximeters
Mesh:
Year: 2022 PMID: 35084348 PMCID: PMC8805452 DOI: 10.2196/30361
Source DB: PubMed Journal: JMIR Mhealth Uhealth ISSN: 2291-5222 Impact factor: 4.773
Summary of pulse oximeter app privacy policy provisions reviewed during August-October 2020.
| Category | Pulse Oximeter-Beat & Oxygen | Oximeter | OxyCare-(Pulse Oximeter) | Oxxiom | EMAY Bluetooth Pulse Oximeter | Kenek Edge |
| Software purpose | General digital health management app that helps users personally check their blood oxygen level and heart rate at any time | General digital health management app that helps users see the percentage of breathable oxygen at their current altitude and check what percentage of oxygen they are breathing | Digital health app that connects to traditional, medical-grade pulse oximeters via Bluetooth or USB | Digital health app that works only with the Oxxiom pulse oximetry system/device | Digital health app that allows users to transfer the pulse oximetry and heart rate data from the EMAY Bluetooth Pulse Oximeter device (Food and Drug Administration–approved) to smartphones | General digital health management app that helps users measure their blood oxygen and heart rate using a hospital-grade finger sensor that can be attached to users’ mobile phones or tablets |
| Developer location (country) | Vietnam | Spain | Not disclosed | United States | China | Canada |
| Free/Paid | Free to install but charges per feature offered within the app | Free to install and use | Free to install and use | Charge to install; pulse oximeter sold separately | Free to install and use | Free to install and use |
| Mobile device access permissions stated on app download site | Storage; Wi-Fi connection information; wearable sensors/activity data; photos, media, and files; receive data from internet; full network access; prevent device from sleeping; view network connections; run at startup; control vibration | Location; photos, media, and files; storage; view network connections; full network access | Location; photos, media, and files; storage; pair with Bluetooth devices; access Bluetooth settings | Users may post, upload, store, share, send, or display photos, images, video, data, text, comments, and other information and content (“Your Content”) to and via the app, which would grant the app a nonexclusive, transferable, sublicensable, worldwide, royalty-free license to use, copy, modify, publicly display, reproduce, translate, and distribute user content | Not disclosed | Location; weblogs; IP address; web browser information; date and time user accessed or left the developer’s website and which pages the user viewed; behavioral data (eg, sleep patterns); user communication records with the developer; personal information (eg, name, age, gender, height, and weight) |
| Ads disclosure on app download site? | Yes | Yes | No | No | No | Yes |
| Scope of personal data collected | “Registration” data (eg, name, email); “transaction” data (eg, purchases, offer responses, downloads); “help” data; app use (eg, heart rate, steps, flights climbed, age, height, weight); other data (eg, mobile device type, unique device ID, IP address, mobile operating system, mobile internet browsers) | “Account” data (eg, username, password, email); “additional” data (eg, biography, location, website, picture, address book); location data (eg, mobile or IP address); “log data” (eg, IP address, browser type, operating system, referring webpage, pages visited, location, mobile carrier, device information, search terms, cookies)a | Location (approximate via network and precise via GPS); USB storage (photos, media, files)a | Date and times of measurements; SpO2b, PRc, and PId measurements; sale information (eg, shipping address, contact information, credit card information) | Deidentified “basic” web server visitor information (eg, IP address, browser details, timestamps, referring pages) | Visit data (eg, location data, weblogs and other communication data, IP address, web browser information, date and time accessed); form data (eg, name, email); sleep data (eg, actions, behaviors, treatments, medication, and general wellness); identifying information (eg, email, device ID, site password); personal information (eg, name, age, gender, height, weight); location information |
| How personal data are collected | Via individuals (account creation or contacting the app); automatic app collection (eg, device, IP address); and third-party tracking technology (eg, cookies) | Via “various websites, email notifications, apps, buttons, widgets, ads, and commerce services”a | Not disclosed | Self-reported and self-uploaded | Tracking via cookies | Via individuals (account creation, contacting the app/site); automatic collection (eg, device, IP address); and third-party tracking technology (eg, cookies) |
| Who can access personal data | Authorized employees and contractors, service providers, app partners, advertisers, advertising networks. Users can opt-out from third-party use of data by uninstalling the app | If the user decides to publish the information, it will be public: service providers, third-party apps, and websites when the user links accounts, sellers of goods and services, law enforcementa | Not disclosed | Third-party payment service providers and authorized third-party e-commerce websites | Advertising partners and other third parties who use cookies | Access via business transfers, law enforcement, and via consent to third parties. Customer PIIe is not available to third-party advertisers; however, these third parties may automatically collect other information via cookies |
| Why personal data are used | To contact individuals, advertise relevant products and services, to use the app | To provide the app services while improving them over time and to provide relevant advertisinga | Not disclosed | To provide app services | For routine administration and maintenance purposes | To contact individuals, advertise via third parties, perform the app’s services, and comply with the law |
| Where the data are stored | Internal memory of the user’s cellular device. Data processing takes place in the United States | Internal memory of the user’s device(s). Data processing takes place in the United States and any country where the app operatesa | Not disclosed | Internal memory of the user’s iOS device | Not disclosed | Internal memory of the user’s devices; otherwise, not disclosed |
| How long the data are stored | Data for advertising purposes are stored as long as the app is installed on the mobile phone | If the user permanently deletes the account, then the data are deleted. Log data are deleted after a few monthsa | Not disclosed | Credit card information is not stored | Not disclosed | Not disclosed |
| Proportionality, fundamental rights, and data protection and privacy issues | Only aggregated, anonymous data are “periodically” transmitted to third parties. Advertisers will only have access to “Automatically Collected Information,” which is the device’s unique ID, IP address, mobile operating system, type of mobile browsers, and app use information | Nonprivate, aggregated, or “otherwise nonpersonal information” will be shared or discloseda | Not disclosed | Not disclosed | User’s personal information cannot be used to identify specific visitors | Individuals can visit the app/website without revealing any personal information |
| Privacy safeguards | The app is opt-in. Physical, electronic, and procedural safeguards of data (eg, authorization process) | The app is opt-ina | Not disclosed | The app is opt-in | The app recommends disabling cookies | The app is opt-in. The developer has a “commercially suitable physical, electronic, and managerial procedure” to safeguard and secure collected information |
| Privacy policy accessible via app store? [ | Yes [ | No (same app developer’s Privacy Policy: RamLabs) [ | No | No [ | Yes, although specific to the company website versus the app [ | Yes [ |
aInformation taken from the app developers’ general privacy policies; the policy could apply to the pulse oximeter app reviewed or a different app made by the developer.
bSpO2: oxygen saturation.
cPR: pulse rate.
dPI: perfusion index.
ePII: personal identifiable information.
Comparison of present findings against comparable and prior privacy policy research focused on mobile health (mHealth) apps.
| Study | mHealth app category surveyed | Apps meeting inclusion criteria, N | mHealth apps surveyed with an accessible mHealth app privacy policy, n (%) |
| This study | Pulse oximeter apps during COVID-19 | 6 | 2 (33) |
| FPF Mobile Apps Study [ | Health and fitness, period tracking, sleep aid | 25 | 19 (76) |
| Flors-Sidro et al [ | Diabetes | 497 | 139 (28.0) |
| O’Loughlin et al [ | Depression | 116 | 57 (49.1) |
| Grindrod et al [ | Medication use and management | 185 | 63 (34.1) |
| Rosenfeld et al [ | Dementia | 72 | 33 (46) |
| Huckvale et al [ | Mental health (depression and smoking cessation) | 36 | 25 (69) |
| Bachiri et al [ | Pregnancy monitoring | 38 | 18 (47) |