IP Library Granted Patent US 11,876,837
Granted Patent B2
US 11,876,837 · App. 17/984,559 · Granted Jan 16, 2024

Network privacy policy scoring

Inventors: Brent VanLoo (Forest Grove, OR); Christopher Semke (Portland, OR); Doug Pollack (Portland, OR)
Assignee: IDENTITY THEFT GUARD SOLUTIONS, INC.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,837
App. No.
17/984,559
Granted
Jan 16, 2024
Kind
B2
Abstract

A user of a client device accesses a service provided by a server computer. The server computer gathers data about the user. The data gathered may be kept private by the server computer, shared only with other computers and users owned by the same entity, shared with selected third parties, or made public. The server computer provides a privacy policy document that describes how the data gathered is used. A privacy server analyzes the privacy policy document and, based on the analysis, generates a privacy score. The privacy score or an informational message selected based on the privacy score are provided to the client device. In response, the client device presents the privacy score or the informational message to the user. In this way, the user is informed of privacy risks that result from accessing the server computer.

Claims (37)

1. A system comprising:

a memory that stores instructions; and

one or more processors configured by the instructions to perform operations comprising:

receiving, from a client device, a uniform resource locator (URL) of a web site accessed by the client device;

accessing text describing a privacy policy associated with the URL;

identifying a set of phrases within the text, each phrase of the set of phrases having a corresponding score component;

determining, based on the score components corresponding to the phrases of the set of phrases, a score for the privacy policy, the score components comprising a score component for data ownership; and

based on the score for the privacy policy and a comparison to a predetermined reference, causing an informational message to be presented on a display device associated with the client device.

2. The system of claim 1 , wherein the determining of the score for the privacy policy comprises using a trained machine learning model.

3. The system of claim 1 , wherein the score components comprise a score component for data use.

4. The system of claim 1 , wherein the score components comprise a score component for data disclosure.

5. The system of claim 1 , wherein the score component for data ownership is based on a determination that the privacy policy indicates General Data Protection Regulation (GDPR) compliance.

6. The system of claim 1 , wherein the score component for data ownership is based on the privacy policy indicating that a user is allowed to delete all user data.

7. The system of claim 1 , wherein the score component for data ownership is based on the privacy policy indicating that a user has control over data sharing.

8. A method comprising:

receiving, by a server and from a client device, a uniform resource locator (URL) of a web site accessed by the client device;

accessing, by the server, text describing a privacy policy associated with the URL;

identifying, by the server, a set of phrases within the text, each phrase of the set of phrases having a corresponding score component;

determining, by the server, based on the score components corresponding to the phrases of the set of phrases, a score for the privacy policy, the score components comprising a score component for data ownership; and

based on the score for the privacy policy and a comparison to a predetermined reference, causing an informational message to be presented on a display device associated with the client device.

9. The method of claim 8 , wherein the determining of the score for the privacy policy comprises using a trained machine learning model.

10. The method of claim 8 , wherein the score components comprise a score component for data disclosure.

11. The method of claim 8 , wherein the score components comprise a score component for data sale.

12. The method of claim 8 , wherein the causing of the informational message to be displayed on the display device is further based on one of the score components and a second predetermined reference.

13. The method of claim 8 , wherein the score component for data ownership is based on a determination that the privacy policy indicates General Data Protection Regulation (GDPR) compliance.

14. The method of claim 8 , wherein the score component for data ownership is based on the privacy policy indicating that a user is allowed to delete all user data.

15. The method of claim 8 , wherein the score component for data ownership is based on the privacy policy indicating that a user has control over data sharing.

16. A non-transitory machine-readable medium that stores instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, from a client device, a uniform resource locator (URL) of a web site accessed by the client device;

accessing text describing a privacy policy associated with the URL;

identifying a set of phrases within the text, each phrase of the set of phrases having a corresponding score component;

determining, based on the score components corresponding to the phrases of the set of phrases, a score for the privacy policy, the score components comprising a score component for data ownership; and

based on the score for the privacy policy and a comparison to a predetermined reference, causing an informational message to be presented on a display device associated with the client device.

17. The non-transitory machine-readable medium of claim 16 , wherein the score component for data ownership is based on a determination that the privacy policy indicates General Data Protection Regulation (GDPR) compliance.

18. The non-transitory machine-readable medium of claim 16 , wherein the score component for data ownership is based on the privacy policy indicating that a user is allowed to delete all user data.

19. The non-transitory machine-readable medium of claim 16 , wherein the score component for data ownership is based on the privacy policy indicating that a user has control over data sharing.

20. The non-transitory machine-readable medium of claim 16 , wherein the causing of the informational message to be displayed on the display device is further based on one of the score components and a second predetermined reference.

Assignments (5)
SECURITY INTEREST Recorded Feb 28, 2025
From: IDENTITY THEFT GUARD SOLUTIONS, INC.
To: STELLUS CAPITAL INVESTMENT CORPORATION, AS THE ADMINISTRATIVE AGENT
Reel/Frame 070370/0581 →
PARTIAL RELEASE OF PATENT SECURITY AGREEMENTS (067396/0304) Recorded Nov 25, 2024
From: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
To: IDENTITY THEFT GUARD SOLUTIONS, INC.
Reel/Frame 069439/0662 →
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: IDENTITY THEFT GUARD SOLUTIONS, INC.
Reel/Frame 067429/0849 →
SECURITY INTEREST Recorded May 13, 2024
From: ZEROFOX, INC.; LOOKINGGLASS CYBER SOLUTIONS, LLC; IDENTITY THEFT GUARD SOLUTIONS, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
Reel/Frame 067396/0304 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2022
From: VANLOO, BRENT; SEMKE, CHRISTOPHER; POLLACK, DOUG
To: IDENTITY THEFT GUARD SOLUTIONS, INC.
Reel/Frame 061736/0027 →
Continuity (2)
Continuation 17071313 · Oct 15, 2020
Related Publication 20230067728A1 · Mar 2, 2023