← Transport
C

Uber

Notable issues
Uber · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
Manufacturer: Uber Technologies

⚠️ The bottom line

Uber promises your data is shared only for Uber's services. Then its CTO tells TechCrunch the company is building a commercial data business selling footage of real people — unblurred — to 25 self-driving companies. When you open the Uber app and book a ride, you don't consent to your face ending up in Wayve's training server in London or Baidu Apollo's model in Dubai. The privacy policy doesn't say that. The CTO did. Uber built an internal tool called "God View" that displayed the real-time GPS location of every rider on a live map — and gave broad employee access with no oversight. Executive Josh Mohrer used it to track a BuzzFeed News journalist investigating the company. At a 2014 dinner, another executive, Emil Michael, floated spending $1 million to hire investigators to dig up dirt on critical journalists' personal lives and families. Employees used God View to stalk ex-girlfriends. Uber knew about the abuse and didn't restrict access until reporters exposed it.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
B
Parent company: Uber
$148M breach cover-up
1 structural risks · 2 products →
Spying
2/4 MODERATE
Is someone spying on me?
Data Sharing
1/4 LOW
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Kids at risk
Honesty
4/4 EXTREME
Can I trust what they say?
Kids at risk
REPLACE Extreme risk. Look for alternatives or lock down hard.
8Contradictions
1Critical
5High
2Medium
7Sources
Findings by concern
Spying 2/4 MODERATE 2 findings
⚡ highpolicy claims vs app permissions
Uber said it collected location data "to improve services," but it also used that data to build Greyball — a tool that identified government regulators and law enforcement by analyzing their location patterns, credit cards, and devices, then showed them a completely fake Uber app with ghost cars that could never be hailed. Uber used Greyball in Portland, Philadelphia, Boston, and multiple countries to systematically evade transportation laws. They also tracked riders' locations for 5 minutes after every trip ended, claiming "drop-off accuracy." Uber weaponized surveillance data to put itself above the law.

What they claim: Uber says it collects location data to provide and improve its services.

What we found: In 2016, Uber changed its app to collect rider location data for 5 minutes after trips ended. Uber also deployed Greyball — a tool using location data, credit card info, and device identifiers to identify and evade government regulators. Greyball showed fake versions of the Uber app to suspected regulators with ghost cars and non-functional ride requests. Used in Portland, Philadelphia, Boston, and multiple countries.

⚫ mediumpolicy claims vs app permissions
Uber monitors drivers' every acceleration, brake, phone touch, and GPS coordinate — surveillance more invasive than most employers — while classifying drivers as "independent contractors" with no employment rights. Drivers can be deactivated by algorithm overnight based on opaque scores with no explanation and no appeal. The UK Supreme Court ruled in February 2021 that this level of control made drivers workers, not contractors, entitled to minimum wage and holiday pay. Uber claims the surveillance "improves the driver experience." The drivers had to go to the highest court in the UK to prove they were employees being surveilled like employees.

What they claim: Uber states that driver data is used to improve the driver experience and ensure safety.

What we found: Uber monitors drivers' every acceleration, brake, phone touch, and GPS coordinate while classifying them as independent contractors. Drivers are deactivated by algorithm with no meaningful appeal. The UK Supreme Court ruled in 2021 that Uber drivers are workers, not contractors. Amazon warehouse injury rates parallel: surveillance for extraction, not safety.

Security 3/4 HIGH 3 findings
⚡ highpolicy claims vs regulatory findings
In 2016, hackers stole the personal data of 57 million Uber users and drivers. Instead of reporting it, Chief Security Officer Joe Sullivan paid the hackers $100,000, made them sign NDAs, and told his team "we can't let this get out" — all while the FTC was investigating Uber for a previous breach. CEO Travis Kalanick was informed and did nothing. Sullivan became the first corporate executive in American history criminally convicted for concealing a data breach. Uber paid $148 million to settle with all 50 states. The cover-up lasted over a year — 57 million people had no idea their data was stolen.

What they claim: Uber states it is committed to transparency and promptly reports security incidents as required by law.

What we found: In 2016, hackers stole data of 57 million riders and drivers. CSO Joe Sullivan paid the hackers $100,000 through the bug bounty program and had them sign NDAs to conceal the breach — while Uber was under FTC investigation for a previous breach. CEO Travis Kalanick knew. Sullivan was criminally convicted of obstruction of justice in October 2022 — first corporate executive convicted for concealing a data breach. Uber paid $148 million to settle with all 50 states.

⚡ highpolicy claims vs regulatory findings
In September 2022, an 18-year-old hacker compromised Uber's entire internal network by sending a single text message to an employee pretending to be IT support. The teenager accessed Uber's Slack, AWS cloud, financial dashboards, and its HackerOne database of unfixed security bugs. The hacker posted "I am a hacker and Uber has suffered a data breach" in the company Slack channel. This was Uber's third major breach. The same year, the "Uber Files" — 124,000 leaked documents — revealed CEO Travis Kalanick personally texted Emmanuel Macron to lobby for favorable regulations. Uber treats security as optional and laws as suggestions.

What they claim: Uber states it maintains appropriate security measures.

What we found: In September 2022, an 18-year-old hacker breached Uber through social engineering — texting an employee pretending to be IT support. The hacker gained access to Slack, AWS, financial dashboards, and the HackerOne vulnerability database. The attacker posted in Uber's Slack announcing the breach. This was Uber's third major breach. The Uber Files leak of 124,000 documents revealed CEO Kalanick personally texted Emmanuel Macron to lobby for favorable regulations.

⚫ mediumpolicy claims vs app permissions
Uber claims pricing is "transparent" and based on "time and distance," but its algorithm charged riders 4x fares during the 2014 Sydney hostage crisis while people fled a terrorist attack. During Hurricane Sandy, a $27 ride surged to $175. Uber also quietly tested "route-based pricing" that charged different passengers different amounts for identical trips based on what the algorithm predicted they'd tolerate — a rider going to a wealthy neighborhood might pay more for the same distance. When caught, Uber called it "improving the rider experience." The algorithm exploits fear and desperation by design.

What they claim: Uber states its pricing is transparent and based on time and distance.

What we found: Uber's surge pricing charged riders 4x normal fares during the 2014 Sydney hostage crisis. During Hurricane Sandy, $27 rides surged to $175. Uber also tested route-based pricing — charging different riders different amounts for the same trip based on what the algorithm predicted they were willing to pay rather than actual time and distance.

Honesty 4/4 EXTREME 3 findings
⚠️ criticalpolicy claim vs third party research
Uber promises your data is shared only for Uber's services. Then its CTO tells TechCrunch the company is building a commercial data business selling footage of real people — unblurred — to 25 self-driving companies. When you open the Uber app and book a ride, you don't consent to your face ending up in Wayve's training server in London or Baidu Apollo's model in Dubai. The privacy policy doesn't say that. The CTO did.

What they claim: Uber's privacy policy states it shares personal data only to provide and improve services, and limits data sharing to authorised business purposes.

What we found: Uber's CTO publicly described AV Labs as selling labelled sensor data — including unblurred footage of real people — to 25+ AV partners as a commercial product. Riders and bystanders captured by Uber's fleet-mounted sensors have no meaningful consent mechanism and no disclosure that their images are being commercially licensed. Uber's 10-Q flags third-party data risk as material but does not disclose which partners receive what data.

⚡ highpolicy claims vs app permissions
Uber built an internal tool called "God View" that displayed the real-time GPS location of every rider on a live map — and gave broad employee access with no oversight. Executive Josh Mohrer used it to track a BuzzFeed News journalist investigating the company. At a 2014 dinner, another executive, Emil Michael, floated spending $1 million to hire investigators to dig up dirt on critical journalists' personal lives and families. Employees used God View to stalk ex-girlfriends. Uber knew about the abuse and didn't restrict access until reporters exposed it.

What they claim: Uber's privacy policy states access to personal data is limited to authorized personnel with a business need.

What we found: Uber employees used an internal tool called God View to track real-time locations of riders without authorization. Executive Josh Mohrer used it to track a BuzzFeed News journalist. At a 2014 dinner, executive Emil Michael suggested spending $1 million to investigate critical journalists' personal lives. Multiple employees used God View to stalk ex-girlfriends.

⚡ highpolicy claims vs regulatory findings
Uber's privacy policy claims it transfers data "in compliance with applicable laws." The Dutch Data Protection Authority found that for over two years Uber transferred European drivers' location data, identity documents, criminal records, and medical information to US servers with zero legal basis. No Standard Contractual Clauses. No adequacy decision. Nothing. The Dutch authority issued a EUR290 million fine — one of the largest GDPR penalties in history. Uber had already been fined EUR10 million the year before for not even telling drivers what it did with their data.

What they claim: Uber's privacy policy states it transfers data internationally in compliance with applicable data protection laws.

What we found: The Dutch DPA fined Uber EUR290 million in 2024 for transferring European drivers' personal data — location, identity documents, criminal records, medical data — to US servers without any legal transfer mechanism for over two years (August 2021 to November 2023). One of the largest GDPR fines ever. A prior EUR10 million fine was issued in 2023 for failing to inform drivers about data practices.

Latest Risks & Threats
New developments that compound existing privacy concerns. 2 emerging risks.
RISK Uber AV Labs turns driver fleet into mass data collection network for AV companies ⚠️ Data Sharing Announced 2026-05-01
Uber's January 2026 AV Labs division and its May 2026 sensor-grid expansion plan would equip millions of Uber driver vehicles with lidar, radar, and cameras to collect real-world data on behalf of 25+ AV partners. The data — including footage of pedestrians and other drivers, without consent — is shared with partners after processing. Riders booking a trip unknowingly become part of a commercially sold training dataset.
Sources
RISK Uber's $10B robotaxi expansion creates uncharted rider data-sharing between Uber, Rivian, Nuro, and Lucid ⚠️ Autonomous Vehicles Announced 2026-05-15
Uber's $10B+ investment in robotaxi fleets with Rivian, Nuro, and Lucid creates a three- and four-party data architecture — Uber holds booking/payment/app data; Nuro holds autonomy sensor data; Lucid holds vehicle telemetry; Rivian holds fleet data — with no public joint data governance framework. When Uber says your data is used to improve services, riders have no way to know which of four companies holds what, how long, or with what consent rights.
Sources
Sources