A House of Woes: Lack of Privacy in Clubhouse App

Clubhouse is an audio-only social networking app that launched in March 2020 and grew in popularity while the world struggled to navigate life in the pandemic. What started as an exclusive app for Silicon Valley’s rich and famous exploded into an ultra-popular social media platform. It has become a space for individuals to connect with celebrities, for Black creatives to thrive, and people to engage in conversations with like-minded individuals, all in a conference call styled room.1 In order to participate, an existing Clubhouse user must provide one with an invite to the app and a year after its release invites continued to remain a hot commodity. The app boasts over ten million weekly active users2 and users gather to talk, learn, laugh, be entertained, meet and connect.3 This exchange of fascinating dialogue does come at a price­–users’ privacy.

One of Clubhouse’s privacy issues stem from its handling of users’ contacts. Clubhouse users are initially given two invites and can send an invite to anyone, provided the user has their phone number. Prior to March 14, 2021, during the signup process Clubhouse requested access to a new user’s contact list. While access was not required, the design of the request page made granting access the more tempting option. A finger icon pointed to the “OK” button, which is in a bolder font and is more enticing than the adjacent “Don’t Allow” option.4 Importantly, users were required to upload their entire contact list, with no option to select individual contacts, in order to send invitations.5 Once a user agreed to share access to their contact list, Clubhouse used that information to recommend people to follow that were already on the app.6 Although these individuals are not Clubhouse users, Clubhouse uses their phone number to check how many times they appear in the contacts of other Clubhouse members, and provides a list of contacts for the user to invite to join, listed in order of the number of friends they already have on Clubhouse.7

On March 14th during its Town Hall, Clubhouse announced access to a user’s contact list was no longer necessary to send invites, as users can now add phone numbers directly.8 Users also have the option to ask Clubhouse to delete any contacts that have already been uploaded and Clubhouse plans to create a tool that will allow users to do this on their own.9 But is this too little too late? The app has millions of users and presumably a large portion of these users granted access to likely hundreds of their contacts. It is unclear how many users have used this option, let alone how many are aware the option exists. There is no incentive for a user to contact the company and request their contact list be deleted and there is no guidance on how long the process takes. Individuals who have purposefully stayed away from this app, have no way to have their information deleted. Even if one user goes through the deletion process, that one contact is likely still in hundreds of other users’ phones that gave Clubhouse access. This is not real solution. An individual’s phone contact list exposes potentially sensitive personal information like therapists, doctors’ offices, rehab facilities, places of worship, and drug dealers, among others.10 Access to this information puts certain groups’ physical safety and livelihoods at risk. Historically vulnerable populations, like sex workers, often work to keep strong boundaries between their personal and professional lives, in order to prevent harassment, loss of employment, and societal disapproval.11 In the year since Clubhouse launched, it has accumulated information about individuals who never joined the app or consented to Clubhouse’s policies surrounding its collection and use of their personal information.12

Beyond access to users’ contact lists, the creators of this app failed to consider users’ privacy along the way. Clubhouse requests that users connect their Twitter and Instagram accounts to Clubhouse to find connections. It states it will be able to see users’ Tweets (including protected Tweets), profile information and account settings, and the accounts that users follow, block, and mute on Twitter.13

Clubhouse will likely soon have to answer for its privacy failures. Clubhouse’s policies violate a number of European Union’s General Data Protection Regulation (GDPR) principles and regulators have begun to take notice. On March 17, the French Data Protection Agency, Commission Nationale de l’Informatique et des Libertés (known as the CNIL), opened an investigation to determine whether or not Clubhouse complies with the GDPR, and if it does not, the CNIL will decide if enforcement action is necessary under its own powers against the app’s company, Alpha Exploration Co.14 French citizens signed a petition with over 15,000 signatures and called for regulatory intervention.15 The French DPA has a history of issuing fines against companies that violate its Data Protection Act. For example, in 2020 it fined Google $120 million and Amazon $42 million for dropping tracking cookies without consent.16 In the United Kingdom there is a similar petition with over 25,000 signatures, also calling for the UK privacy watchdog, Information Commissioner’s Office, to step in.17 Additionally, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) announced in early February that it had requested information from Clubhouse to review its compliance with European data protection law.18 This occurred after Germany’s largest consumer protection organization, Federation of German Consumer Organizations, filed a complaint against Clubhouse for GDPR violations.19 Clubhouse will have to make a number of changes in order to avoid facing large fines by European regulators and agencies in the U.S. as well.

Clubhouse founders noted their desire to slowly expand access to the app to ensure its features can handle a large user base.20 However, every step along the way, Clubhouse has shown how essential it is for privacy to be a proactive measure embedded into the design of technology systems and business practices, throughout the entire lifecycle of data use.21 While it remains to be seen what actions regulators will take against Clubhouse, one thing is clear– there is room for improvement.

Kai Koppoe

Kai Koppoe is a third-year J.D. candidate at Fordham University School of Law and a staff member of the Intellectual Property, Media & Entertainment Law Journal. She holds a B.A. in International Studies and History from the University of Richmond.