The Future is Private: Secure Data
Management Best Practice
Roman Bugaev, CTO at Flo
#1Health & Fitness app
by installs and MAU
26M+MAU
90% organic. 60% tier-1 countries
Why is this
important?
Privacy is now a luxury
Apple’s newest product is privacy
You can become “famous”
And some more...
Reputational
FinancialBusiness
Regulatory
Lessons for Data
Practitioners
Design a positive opt-in opt-in (no pre-checked boxes!)
Your strongest position is to get explicit, willful permission to collect user's
data. And think about micro-consent.
Screen Accept rate Churn Rate
With checkboxes 97,14% 2.86%
Without checkboxes 98,67 1.33%
Respect Data Subject Rights
User must be able to modify, correct, erase, and update Personal Data
Privacy by Design
Be proactive not Reactive; Preventative not Remedial
* https://www.digitemis.com/
If I pull data from an API, do I really
need all the fields of data that I could
get, or do I narrow it for the specific
purpose of this product?
When thinking about geolocation data–
do I really need it? And if I do capture
geolocation data, what are the risks
associated with that?
Minimize collected data
Datensparsamkeit [de] - Only store data you need
* https://martinfowler.com/bliki/
Reduce sensitivity of data
Aggregate and statistically anonymise data or extract the features of
interest before sharing
e.g. use age group instead of age
Cultivate transparency and honesty
Be open and clear about how you protect and use private data
Protect whole data lifecycle with End-to-End security
Cloudflare helps Flo to raise the bar of security standards for women’s
health apps.
Thank you!

Data the future is private secure data management best practice