I had a look into the apps side of FB a couple of months ago. Looks like it's pretty easy to get information not just about one person (after they grant explicit access permission to the app), but also basic information about their friends (without any permission)
The ToS says you're not supposed to retain any profile data for more than 24 hours, but how would FB ever know about this?
|