Table of Contents
Fetching ...

Natural Language but Omitted? On the Ineffectiveness of Large Language Models' privacy policy from End-users' Perspective

Shuning Zhang, Haobin Xing, Xin Yi, Hewu Li

TL;DR

The first user study to let participants read the privacy policy and user agreement with two different styles (a cursory and detailed style) is conducted, which found users lack important information upon cursory reading and even detailed reading.

Abstract

LLMs driven products were increasingly prevalent in our daily lives, With a natural language based interaction style, people may potentially leak their personal private information. Thus, privacy policy and user agreement played an important role in regulating and alerting people. However, there lacked the work examining the reading of LLM's privacy policy. Thus, we conducted the first user study to let participants read the privacy policy and user agreement with two different styles (a cursory and detailed style). We found users lack important information upon cursory reading and even detailed reading. Besides, their privacy concerns was not solved even upon detailed reading. We provided four design implications based on the findings.

Natural Language but Omitted? On the Ineffectiveness of Large Language Models' privacy policy from End-users' Perspective

TL;DR

The first user study to let participants read the privacy policy and user agreement with two different styles (a cursory and detailed style) is conducted, which found users lack important information upon cursory reading and even detailed reading.

Abstract

LLMs driven products were increasingly prevalent in our daily lives, With a natural language based interaction style, people may potentially leak their personal private information. Thus, privacy policy and user agreement played an important role in regulating and alerting people. However, there lacked the work examining the reading of LLM's privacy policy. Thus, we conducted the first user study to let participants read the privacy policy and user agreement with two different styles (a cursory and detailed style). We found users lack important information upon cursory reading and even detailed reading. Besides, their privacy concerns was not solved even upon detailed reading. We provided four design implications based on the findings.

Paper Structure

This paper contains 37 sections, 7 figures, 6 tables.

Figures (7)

  • Figure 1: Typical privacy policy for AI products. (a) ChatGPT. (b) Wen Xin Yi Yan. (c) PI (d) Zi Dong Tai Chu.
  • Figure 2: The problem definition and research framework of this paper.
  • Figure 3: The keywords and utterance of users for cursory reading and detailed reading. The x axis denoted the frequency of participants. (a), (b), (c) were extracted from the important information, memorized information, important information with reference during cursory reading of user agreement. Similarly, (d), (e), (f) were extracted from the important information, memorized information, important information with reference during detailed reading of user agreement. (g), (h), (i) were extracted from the important information, memorized information, important information with reference during cursory reading of privacy policy. (j), (k), (l) were extracted from the important information, memorized information, important information with reference during detailed reading of privacy policy.
  • Figure 4: Users' frequency to read the usage term and privacy policy.
  • Figure 5: The characters of participants' utterance in each condition and each question. Errorbar showed one standard deviation.
  • ...and 2 more figures