Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Dropbox Paper exposed the names and emails of everyone who viewed a public doc

September 2019

HighStatus: DisputedProduct: Dropbox PaperYear: 2019

Anyone viewing a publicly shared Dropbox Paper document could see the full names and email addresses of every signed-in Dropbox user who had ever opened it — turning a collaboration feature into a personal-data harvesting tool.

What happened

Dropbox Paper, the company's collaborative document product, displayed viewer information to support real-time collaboration. In September 2019, security engineer Koen Rouwhorst publicized that when a Paper document was shared publicly, any logged-in viewer could see the full names and email addresses of all other Dropbox users who had accessed it — and that this information persisted.

Reporting by The Register ('Dropbox Paper: Handy for collaborating... oh and harvesting email addresses, too') and others noted the design was reasonable for a known team but dangerous for public links: because Paper docs were shared via long 'magic' URLs that people routinely posted on social media, an attacker could crawl for public Paper URLs and harvest the personal details of large numbers of Dropbox users who had merely clicked a link. A warning that a viewer's identity would be shown was presented only in faint type, and a signed-in user could not hide their identity from the document owner.

Impact

The flaw illustrated how 'viewer info' and read-receipt-style features can surface private behavior — who looked at what, and when — and leak it to strangers. For users it meant that simply opening a shared Paper link while logged in could expose their real name and email to anyone else with the link, a vector useful to spammers, doxxers, and phishers.

Dropbox's Response / Official Position

Dropbox defended the behavior, saying 'privacy considerations are built into how we design our features' and that 'displaying this information is needed to enable collaboration and security features for our users,' rather than treating it as a bug to be fixed.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)
Read documentation

Through 2025 Dropbox pushed Dash to general availability with self-serve sign-up and no IT required, marketing it as an AI assistant that indexes content across all of a user's connected apps — a model that, by design, reaches far beyond the files stored in Dropbox.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dash connects to Google Workspace, Microsoft 365, Slack, Notion and more, and routes queries through large language models — leaving users to trust Dropbox's contractual assurances that connected and indexed data is not used to train third-party AI models.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Developer, API & Platform
Read documentation