What Uber actually built, and got caught building

Start with what's proven, not alleged. In March 2017, the New York Times exposed a program Uber called Greyball, part of a broader internal effort called VTOS ("violation of terms of service"). When Uber pushed into a city where it was banned or being fought by regulators, Greyball identified accounts most likely to belong to undercover officials — people who opened and closed the app suspiciously often near government buildings, or whose credit cards traced back to police or government credit unions — and served those specific accounts a fake version of the app. Ghost cars that never arrived. Rides that mysteriously got canceled. Uber used it in Boston, Portland, Las Vegas, and Paris, and in Australia, China, Italy, and South Korea. The Justice Department opened a criminal investigation about two months after the NYT story broke; Uber's chief security officer said in March 2017 the company would stop using it against law enforcement.

Greyball wasn't the only one. From 2015 into late 2016, Bloomberg reported, citing internal documents and interviews, that a tool nicknamed Ripley let Uber headquarters remotely lock, wipe passwords on, or shut down every laptop and phone in a foreign office the moment police arrived to execute a raid — named by employees after Sigourney Weaver's character in Alien. From 2014 into early 2016, Uber ran a program called Hell: fake rider accounts on Lyft that let Uber silently watch how many Lyft drivers were nearby, their prices, and — critically — cross-reference which of those drivers also drove for Uber, so Uber could pressure them into going exclusive. Fortune reported the FBI was investigating whether Hell amounted to unauthorized access of Lyft's computer systems.

None of this touches the separate 2014 "God View" scandal, where an internal dashboard let any Uber corporate employee track any rider's real-time location. Uber's own former forensic investigator, Ward Spangenberg, later said in a court filing that employees used it to help exes stalk ex-girlfriends and to look up celebrities' trip histories, and that the misuse continued after the tool was renamed "Heaven View." New York's 14-month investigation into God View also turned up a separate 2014 data breach Uber had failed to disclose on time; the state fined Uber $20,000 for that disclosure failure and required Uber to encrypt rider location data and restrict which employees could access it.

Every one of these programs shared the same design principle: decide, internally and without asking, what the people affected get to see.

The instinct didn't go away — it moved into the fine print

Nobody is running Greyball anymore. But the same "we decide what you get to know" logic now sits in an even less accountable place: the privacy policy every rider, driver, and shopper is required to accept, most of which nobody reads.

We pulled the current, live retention sections from all four apps' policies:

Uber's historical secret tools -- Greyball, Hell, Ripley, God View -- laid out as torn case-file tabs next to a clipped comparison of each company's current stated location-retention policy: Uber gives a specific number, Lyft, DoorDash, and Instacart do not. The caption reads "The worst history. The clearest clock."

Uber publishes an actual table — a specific number of years for each data category. Riders: account and device data for the life of the account; location, trip, and communications data for the life of the account or seven years, whichever comes first; government ID for one year; selfies for three years. Drivers get longer retention across the board — several categories run life-of-account plus seven more years on top, and location/trip data is a flat seven years regardless of whether the account is even still open. Uber states a real deletion window too: about 90 days after you request it, with named exceptions for fraud, safety, and open legal matters.

Lyft gives you exactly one number: transactional data (rides, payments) for "at least seven years." Everything else — your location history, your device data, your messages with support — falls under "as necessary to comply with our legal obligations, resolve disputes and enforce our terms and policies." No table. No stated deletion window after you close your account.

Instacart is nearly the same as Lyft — one hard number, and it's not even for you as a customer. Shoppers' biometric face-scan data (used for identity verification) is kept "for up to three years following your last activity as a Shopper." Every other category — location, order history, payment data — gets the same vague catch-all language, with no deletion timeline stated anywhere.

DoorDash gives zero numbers. Its retention section — substantially the same across the consumer and Dasher policies, though not identical word-for-word — lists six factors: "the length of time necessary," "any retention periods prescribed by law," and four more just as vague. Not one figure you could actually hold the company to. Not for location. Not for order history. Not even for the driver background-check data it's required to collect before letting someone deliver your food.

The modern version of "we decide what you're allowed to see"

Three live developments show the same instinct playing out today, just legalized instead of hidden:

Surveillance pricing. Uber, Lyft, and DoorDash all use your personal data — location, device type, order history, even inferred willingness to pay — to set an individual price just for you, instead of one public rate. The Federal Trade Commission (FTC) opened a formal study into the practice in July 2024 and published findings in January 2025. New York passed a law in 2025 — the Algorithmic Pricing Disclosure Act, signed that May and effective that November — forcing companies to display an on-screen warning:

"THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA." (That's the literal wording the law requires on screen — not a paraphrase.)

Algorithmic pay suppression. A California class action, Carranza v. Uber (filed July 2026), and a parallel Amsterdam case both allege Uber's AI pay-setting algorithm uses drivers' own behavioral data against them — pushing pay toward the lowest amount a driver will still accept. European plaintiffs claim losses as high as £26,239 per driver since August 2021.

A surveillance vendor trying to conscript the fleet without telling anyone. In August 2025, the license-plate-tracking company Flock Safety pitched Georgia's Attorney General on a plan to turn 350,000 Uber, Lyft, and delivery drivers' existing dashcams — made by a company called Nexar, already strapped to hundreds of thousands of gig workers' windshields — into a passive license-plate-reader network feeding Flock's police surveillance system. Every red light, every drop-off, logging the plates of every nearby car. It surfaced publicly in August 2026 through leaked documents. Flock says the deal was never activated. What's still unclear: whether Uber, Lyft, or a single driver would ever have been told their personal car was doing this.

What this piece is not saying

Lyft, DoorDash, and Instacart have never been caught running anything like Greyball. No scandal on record for any of the three. That's not the same as saying they've never done something similar — nobody knows either way, and this piece isn't claiming to.

Here's the real point: Uber has the worst history of the four companies and Uber tells you the most. Past behavior and current honesty aren't the same thing. This is proof of that.

None of this means Lyft, DoorDash, or Instacart are breaking any law. There's no federal requirement to publish a specific retention number — the vague language in their policies is legal. It means three of the four companies chose not to tell you a number. Not that they're hiding something illegal.

Congress tried twice to fix this, and stopped both times

There's no federal number because there's no federal law. Congress has come close twice. The American Data Privacy and Protection Act (ADPPA) passed the House Energy and Commerce Committee in 2022 on a bipartisan 53-2 vote — the furthest a comprehensive federal privacy bill has ever gotten — then died without a floor vote when the term ended. The two "no" votes on that committee tally were themselves California Democrats, Reps. Anna Eshoo and Nanette Barragán, both objecting that it would let a federal law override the state's own tougher law; Speaker Nancy Pelosi later declined to bring it to the floor over the same concern. Its successor, the American Privacy Rights Act (APRA), cleared subcommittee in May 2024 — but the full committee markup, its required next step, was abruptly canceled that June and never rescheduled before the bill expired with the term. House GOP leadership pointed to a different sticking point this time: whether ordinary people should be allowed to sue companies directly instead of only regulators. The fight over whether a federal law should override state laws was still unresolved underneath it.

Either bill would have set a national floor most privacy lawyers expect includes real data-minimization and retention limits — something closer to what Uber already publishes voluntarily. Until one passes, "how long do you keep my data" stays a question every company gets to answer for itself, or not answer at all.

The one real lever right now: California

If you live in California, you're not actually stuck with whatever a company's policy says. The CCPA, as amended by the California Privacy Rights Act (CPRA), gives you a legal right to request that a business delete the personal information it holds on you — a right the vague "as necessary" language in Lyft's, DoorDash's, and Instacart's policies doesn't get to override. A business has 45 calendar days to respond after it receives your request (extendable once, by another 45 days, for complex or high-volume cases), and it must confirm receipt within 10 business days and explain how it will verify you're really you.

It's not unconditional — companies can still refuse to delete data they need for fraud and security purposes or to comply with a legal obligation (Cal. Civ. Code § 1798.105(d)), the same carve-outs all four companies already claim in their policies. But it's an actual, enforceable deadline, which is more than any of these policies promise on their own. If you're outside California, several other states — Virginia, Colorado, Connecticut, and others — now have similar deletion rights — check whether yours is one of them before assuming you have none.

What can I do

If you're in California: file a deletion request directly — it's a legal right, not a favor. Uber lets you do this from Settings → Privacy → "Manage Data." Instacart: an in-app request for Shoppers, or shopperprivacy@instacart.com. DoorDash: privacy@doordash.com. Lyft doesn't publish a request email in its main policy — use its privacy team contact form and put "CCPA deletion request" in the subject line so it can't be routed as generic support. Whoever you ask, you're owed a response within 45 days.

If you're outside California: first check whether your state has passed its own version (Virginia's Consumer Data Protection Act (VCDPA), Colorado's Privacy Act (CPA), Connecticut's Data Privacy Act (CTDPA), and others all include a right to delete). If it has, use it the same way. If it hasn't, your only lever left is asking directly and treating a non-answer as the answer: request, in writing, exactly how long the company keeps your location and trip/order history. Uber already tells you in its policy — you're just confirming it. Lyft, DoorDash, and Instacart don't say — if they can't give you a number when you ask directly, that silence is itself the finding.

Either way: don't accept "we retain data as necessary for business purposes" as a real answer. Ask for the number. If nobody will give you one, that's this story's whole point, applied to your own account.

Why we're covering this

This isn't a story about whether to use Uber, Lyft, DoorDash, or Instacart — it's about what "trust us" is actually worth from a company, measured against what it's already proven willing to do when nobody's watching. The company with the documented history of secretly working around regulators, competitors, and its own customers is also the one telling you the most, in writing, right now. That's not an argument for trusting Uber more. It's proof that reputation and honesty aren't the same measurement, and that a privacy policy's vagueness is a choice a company makes, not a rule it's forced into.

The Receipts

Full sourcing detail, including every fix Fact Desk and Leo required across two review passes, is in newsroom/draft-rideshare-delivery-app-surveillance-retention.md.