IP Library Granted Patent US 11,238,169
Granted Patent B2
US 11,238,169 · App. 16/536,020 · Granted Feb 1, 2022

Privacy score

Inventors: Siddharth Daftary (Chicago, IL); Marvin Lu (Chicago, IL); Jessica Schapiro (Chicago, IL); Jacob Stewart (Arlington Heights, IL); Shashin Patel (Chicago, IL); Michael Sharp (Chicago, IL); Jhanani Dhakshnamoorthy (Boothwyn, PA)
G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,238,169
App. No.
16/536,020
Granted
Feb 1, 2022
Kind
B2
Abstract

Methods, computer-readable media, software, and apparatuses may calculate and inform a consumer of company privacy scores corresponding to companies with which the consumer has a corresponding account, or for a company associated with a website that a consumer may visit. A consumer privacy score may also be determined, based on the company privacy scores. The company privacy scores may be based on a calculation including elements of a privacy practice of the corresponding company and elements of a privacy policy of the corresponding company.

Claims (88)

1. A method comprising: executing, by a processor, computer executable instructions stored in a memory connected thereto, the execution causing a computing device of a cyber-privacy system to:

receive, from a user, personally identifying information, wherein the user is a consumer;

electronically collect data from interactions and transactions between the user and device applications and associated remote software including using an email scanning engine to scan a plurality of emails of the user that contain a listing of user account information and including analyzing the user's web browser cache;

discover a plurality of accounts and online subscriptions of the user by using only the received personally identifying information and collected data;

determine a plurality of companies with which the user has a corresponding account, using primarily the discovered primarily of accounts and online subscriptions;

create a respective company specific privacy practice dataset for each company of the plurality of companies each of the respective datasets based on:

a number of data breach events at a given respective company to which the respective dataset corresponds and a timeframe for each data breath event,

whether the given company uses any personally identifying data of the user for target advertising,

whether the given company uses secure data storage to store all of the any personally identifying data,

whether the given company shares any of the personally identifying data with third parties,

an indication of a time duration that the given company retains any of the personally identifying data, and

an indication of a time duration that each of the third patties retains any of the personally identifying data,

determine a plurality of company privacy scores by, for each company, using the respective company specific dataset to determine, for the given company to which the respective dataset corresponds, a corresponding company privacy score indicative of a measure of protection, provided by the given company, of the personally identifying data used, shared, or stored by the given company; and

determine a user privacy score for the user based on each of the plurality of company privacy scores;

determine a relationship between the user privacy score and a risk of loss to an insurance company;

determine an insurance premium price for the user;

increase the insurance premium price when the user privacy score indicates an increase to the risk of loss; and

decrease the insurance premium when the user privacy score indicates a decrease to the risk of loss.

2. The method of claim 1 , wherein the determining the plurality of company privacy scores further comprises: generating each of the corresponding company privacy scores based on a calculation comprising elements of the privacy practice of a corresponding company to which the respective privacy score corresponds and elements of a privacy policy of the corresponding company.

3. The method of claim 1 , further comprising: determining a trend of the user privacy score, based on the user privacy score and a previous privacy score of the user; and outputting, for display, an indication of the trend.

4. The method of claim 1 , further comprising: receiving a weighting for a parameter used in a calculation of the plurality of company privacy scores; generating one or more of the plurality of company privacy scores, based on the weighting; determining an adjusted consumer privacy score, based at least in part on the generated one or more of the plurality of company privacy scores; and outputting, for display, an indication of the adjusted consumer privacy score.

5. The method of claim 1 , further comprising:

receiving, from a browser plug-in and via a network, a request for at least one company privacy score of the plurality of company privacy scores; and

sending the at least one company privacy score.

6. The method of claim 1 , further comprising: determining a value representative of a worth of the personally, identifying data used, shared, or stored by at least one company of the plurality of companies, wherein the personally identifying data used, shared, or stored comprises consumer data collected according to a privacy policy of the at least one company; and

outputting, for display, an indication of the value.

7. An apparatus of a cyber-privacy system, comprising: a processor; a memory unit storing computer-executable instructions, which when executed by the processor, cause the apparatus to:

receive, from a user, personally identifying information, wherein the user is a consumer;

electronically collect data from interactions and transactions between the user and device applications and associated remote software including using an email scanning engine to scan a plurality of emails of the user that contain a listing of user account information and including analyzing the user's web browser cache;

discover a plurality of accounts and online subscriptions of the user by using only the received personally identifying information and collected data;

determine a plurality of companies with which the user has a corresponding account, using primarily the discovered primarily of accounts and online subscriptions;

create a respective company specific privacy practice dataset for each company of the plurality of companies, each of the respective datasets based on:

a number of data breach events at a given respective company to which the respective dataset corresponds and a timeframe for each data breach event,

whether the given company uses any personally identifying data of the user for target advertising,

whether the given company uses secure data storage to store all of the any personally identifying data,

whether the given company shares any of the personally identifying data with third parties,

an indication of a time duration that the given company retains any of the personally identifying data, and

an indication of a time duration that each of the third parties retains any of the personally identifying data;

determine a plurality of company privacy scores by, for each company, using the respective company specific dataset to determine, for the given company to which the respective dataset corresponds, a corresponding company privacy score indicative of a measure of protection, provided by the given company, of the personally identify data used, shared, or stored by the given company;

determine a user privacy score for the user based on each of the plurality of company privacy scores;

determine a relationship between the user privacy score and a risk of loss to an insurance company;

determine an insurance premium price for the user;

increase the insurance premium price when the user privacy score indicates an increase to the risk of loss; and

decrease the insurance premium when the user privacy score indicates a decrease to the risk of loss.

8. The apparatus of claim 7 , wherein the computer-executable instructions, when executed by the processor, further cause the apparatus to determine the plurality of company privacy scores by causing the apparatus to:

generate each of the corresponding company privacy scores based on a calculation comprising elements of the privacy practice of a corresponding company to which the respective privacy score corresponds and elements of a privacy policy of the corresponding company.

9. The apparatus or claim 7 , wherein the computer-executable instructions, when executed by the processor, cause the apparatus to: determine a trend of the user privacy score, based on the user privacy score and a previous privacy score of the user; and output, for display, an indication of the trend.

10. The apparatus of claim 7 , wherein the computer-instructions, when executed by the processor, cause the apparatus to: receive a weighting for a parameter used in a calculation of the plurality or company privacy scores; generate one or more orate plurality of company privacy scores, based on the weighting; determine an adjusted consumer privacy score, based at least in part on the generated one or more of the plurality company privacy scores; and output, for display, an indication of the adjusted consumer privacy score.

11. The apparatus of claim 7 , wherein the computer-executable instructions, when executed by the processor, cause the apparatus to:

receive, from a browser plug-in and via a network, a request for at least one company privacy score of the plurality of company privacy scores; and

send the at least one company privacy score.

12. The apparatus of claim 7 , wherein the computer-executable instructions, when executed by the processor, cause the apparatus to:

determine a value representative of a worth of the personally identifying data used, shared, or stored by at least one company of the plurality of the plurality of companies, wherein the personally identifying data used, shared, or stored comprises consumer data collected according to a privacy policy of the at least one company; and

output, for display, an indication of value.

13. One or more non-transitory computer-readable media of a cyber-privacy system storing instructions that, when executed by a computing device, cause the computing device to:

receive, from a user, personally identifying information, wherein the user is a consumer;

electronically collect data from interactions and transactions between the user and device applications and associated remote software including using an email scanning engine to scan a plurality of emails of the user that contain a listing of user account information and including analyzing the user's web browser cache;

discover a plurality of accounts and online subscriptions of the user by using only the received personally identifying information and collected data;

determine a plurality of companies with which the user has a corresponding account, using primarily the discovered primarily of accounts and online subscriptions;

create a respective company specific privacy practice dataset for each company of the plurality of companies, each of the respective datasets based on:

a number of data breach events at a given respective company to which the respective dataset correspond and a timeframe for each data breach event,

whether the given company uses any personally identifying data of the user for target advertising,

whether the given company uses secure data storage to store all of the any personally identifying data,

whether the given company shares any of the personally identifying data with third parties,

an indication of a time duration that the given company retains any of the personally identifying data, and

an indication of a time duration that each of the third parties retains any of the personally identifying data;

determine a plurality of company privacy scores by, for each company, using the respective company specific dataset to determine, for the given company to which the respective dataset corresponds, a corresponding company privacy score indicative of a measure of protection, provided by the given company, of the personally identifying data used, shared, or stored by the given company;

determine a user privacy score for the user based on each of the plurality of company privacy scores;

determine a relationship between the user privacy score and a risk of loss to an insurance company;

determine an insurance premium price for the user;

increase the insurance premium price when the user privacy score indicates an increase to the risk of loss; and

decrease the insurance premium when the user privacy score indicates a decrease to the risk of loss.

14. The one or more non-transitory computer-readable media of claim 13 , slating further instructions that, when executed by the computing device, cause the computing device to:

generate each of the corresponding company privacy scores based on a calculation comprising elements privacy practice of a corresponding company to which the respective privacy score corresponds and elements of a privacy policy of the corresponding company.

15. The one or more non-transitory computer-readable media of claim 13 , storing further instructions that, when executed by the computing device, cause the computing device to:

determine a trend of the user privacy score, based on the user privacy score and a previous privacy score of the user; and

output, for display, an indication of the trend.

16. The one or more non-transitory computer-readable media of claim 13 , storing further instructions that, when. executed by the computing device, cause the computing device to:

receive a weighting for a parameter used in a calculation of the plurality of company privacy scores;

generate one or more of the plurality of company privacy scores, based on the weighting;

determine an adjusted consumer privacy score, based at least in part on the generated one or more of the plurality of company privacy scores; and

output, for display, an indication of the adjusted consumer privacy score.

17. The one or more non-transitory computer-readable media of claim 13 , storing further instructions that, when executed by the computing device, cause the computing device to:

receive, from a browser plug-in and via a network, a request for at least one company privacy score of the plurality of company privacy scores; and

send the at least one company privacy score.

18. The one or more non-transitory computer-readable media of claim 13 , storing further instructions that, when executed by the computing device, cause the computing device to:

determine a value representative of a worth of the personally identifying data used, shared, or stored by at least one company of the plurality of companies, wherein the personally identifying data used, shared, or stored comprises consumer data collected according to a privacy policy of the at least one company; and

output, for display, an indication of the value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2021
From: DAFTARY, SIDDHARTH; LU, MARVIN; SCHAPIRO, JESSICA; STEWART, JACOB; PATEL, SHASHIN; SHARP, MICHAEL; DHAKSHNAMOORTHY, JHANANI
To: ALLSTATE INSURANCE COMPANY; INFOARMOR, INC.
Reel/Frame 058522/0212 →
Continuity (1)
Related Publication 20210042428A1 · Feb 11, 2021
Cited By (1)
US 12,743,545