Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The documentation asserts that profile data never leaves the device, yet the described flow sends user-derived labels, demographics, and an OpenID to an external L1 service. Even if direct identifiers are omitted, the combination of pseudonymous identifier plus demographic/personality attributes can enable tracking, linkage, or re-identification and misleads users about actual data disclosure.
