Privacy Perceptions of Custom GPTs by Users and Creators
Authors
Research Background and Issues
-
Identified Problems or Challenges:
The paper highlights the rapid growth of custom GPT applications built on OpenAI's large language models (LLMs), surpassing three million, but pressing privacy issues remain unresolved. Specific challenges include:- Discrepancies in user and creator awareness of data flows and privacy risks.
- Lack of transparency in how data is collected, processed, and disseminated, especially in scenarios involving third-party services.
- Increased user privacy risks, such as potential sensitive data leaks, opaque data usage, and third-party data collection.
- Creators' concerns about proprietary knowledge being reverse-engineered, coupled with the lack of platform protection mechanisms.
-
Importance of the Problem:
The widespread use of custom GPT applications directly impacts millions of users, yet the associated privacy issues involving sensitive permissions and understanding of user behavior remain underexplored. As the user base and commercialization expand, ensuring security and addressing privacy concerns become increasingly critical. -
Research Motivation and Related Work:
The motivation for this research is to bridge the knowledge gap between user and creator privacy perceptions and practices. Previous studies have primarily focused on technical privacy protections (e.g., differential privacy or federated learning), with limited understanding of users' perspectives and behaviors regarding privacy in LLM-customized applications.
Solutions
-
Proposed Methods or Solutions:
The authors conducted semi-structured interviews with 23 custom GPT users and creators to explore their perceptions of data flows, privacy risks, and privacy practices, as well as their understanding of different roles and responsibilities. -
Innovative Contributions:
- Investigated the impact of dual user-creator roles on privacy perceptions, revealing a phenomenon of "blurred user-creator identities."
- Systematically analyzed users' privacy concerns regarding data collection, processing, and dissemination, along with their coping strategies.
- Provided recommendations for platforms, policymakers, and researchers to improve privacy protection and platform governance.
-
Implementation Steps and Techniques:
- Interview Design: Conducted semi-structured interviews lasting 40-126 minutes, with stratified sampling of users and creators, including general users, amateur creators, and professional creators.
- Data Analysis: Employed thematic analysis using a combined inductive and deductive framework to capture key privacy issues and behaviors expressed by participants.
- Theoretical Perspective: Privacy analysis utilized Solove's taxonomy of privacy (covering data collection, processing, and dissemination stages) and incorporated privacy calculus theory (how users trade off privacy and functionality).
Research Findings
-
Specific Findings:
- Proposed a psychological model of data flow for users and creators across three main GPT usage scenarios (basic GPT, action-based GPT, and login-based GPT), including uncertain trust in OpenAI's data collection, misunderstandings about creator permissions, and distrust of third-party involvement.
- Systematically summarized key privacy concerns of users and creators: lack of transparency in data collection, processing, and dissemination; risks of third-party data misuse; and insufficient platform regulatory policies.
- Identified user strategies to address privacy issues, such as self-censorship (limiting input), evaluating GPT trustworthiness, and reducing usage traces, while creators focused on protecting intellectual property through GPT privacy settings and prompt design adjustments.
-
Comparison with Existing Solutions and Advantages:
- The authors' research adopts a human-centered perspective to fill the gap in current technical privacy protection studies, clearly delineating the responsibilities of users and creators.
- Further explored the platform's shortcomings in supporting creators' intellectual property protection and providing compliance guidance.
-
Experimental or Evaluation Results:
The authors analyzed how privacy concerns manifest differently across user roles, reflecting communication misunderstandings and biases in user perceptions of GPT applications. Key findings include:- General users overestimate the impact of GPT creators on their privacy while neglecting the roles of the platform (OpenAI) and third-party services.
- Creators lack trust in platform regulatory mechanisms, leading to reluctance in sharing knowledge.
-
Limitations and Future Directions:
- Limitations:
- Limited sample size, primarily targeting specific user groups (e.g., users under European GDPR regulations).
- Focused solely on OpenAI's GPT platform, excluding other LLM-customized applications.
- Future Directions:
- Expand the scope of research to include more model providers (e.g., Anthropic, Google's LLM projects).
- Investigate the potential risks of data breaches in GPT collaborations with third-party services.
- Explore the impact of privacy fatigue on long-term user behavior and corresponding countermeasures.
- Limitations:
Through the proposed research framework and detailed exploration of privacy practices, this paper provides foundational guidance for designing secure and transparent GPT application systems. It also contributes to fostering interdisciplinary dialogue among policy, technology, and user experience for collaborative development.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How do users and creators' perceptions of data flows and privacy risks differ in GPT custom applications?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- How do users and creators address privacy challenges such as data collection, processing, and third-party use?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- How can platforms and policies better protect user privacy and support creators' intellectual property?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
Practical Problems
1- Users cannot trust how data is processed and used by third parties in GPT custom applications.Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- 60%
Manipulating and Measuring Model Interpretability
CHI '21· Explainable AI (XAI) +1
- 60%
I don't need an expert! Making URL phishing features human comprehensible
CHI '21· Algorithmic Transparency & Auditability +1
- 60%
Shared Interest: Measuring Human-AI Alignment to Identify Recurring Patterns in Model Behavior
CHI '22· Explainable AI (XAI) +1
- 60%
Debiased-CAM to mitigate image perturbations with faithful visual explanations of machine learning
CHI '22· Explainable AI (XAI) +1
- 60%
Progressive Disclosure: Empirically Motivated Approaches to Designing Effective Transparency
IUI '19· Explainable AI (XAI) +1
- 60%
When People and Algorithms Meet: User-reported Problems in Intelligent Everyday Applications
IUI '19· Explainable AI (XAI) +1
Based on Jaccard similarity of research subtopics & professions (≥60%)