Posted on

Confirmshaming that pressures users into accepting an offer

A decline button can say No thanks.

Or it can say something like No thanks, I hate saving money.

Both buttons lead away from the offer.

Only one insults the person for choosing it.

That pattern is commonly called confirmshaming: wording the refusal so that declining an offer sounds foolish, irresponsible, cheap, unhealthy, antisocial, or otherwise embarrassing.

A large 2019 academic study of dark patterns across roughly 11,000 shopping websites documented confirmshaming in pop-ups that offered discounts or email signup. Researchers found examples where the decline option framed the user as someone who disliked saving money or did not want a benefit.

See the Princeton-led study Dark Patterns at Scale.

The choice is technically available and emotionally tilted

That distinction is what makes confirmshaming interesting.

The interface does not remove the decline option. It changes the emotional cost of clicking it.

A visitor came to read an article, browse products, or complete another task. The site interrupts with an unrelated offer and then frames refusal as a statement about the visitor’s intelligence or priorities.

The wording has nothing to do with the mechanics of the choice.

“Subscribe” and “Continue without subscribing” are enough.

Neutral language preserves the same business opportunity

The FTC’s dark-pattern work describes broader false hierarchy and pressured-upselling designs that steer users toward the company’s preferred option through language or visual prominence.

See the FTC’s Bringing Dark Patterns to Light.

A business can still make an offer prominent. It can explain the benefit. It can even ask twice if the context reasonably calls for confirmation.

What it does not need to do is convert the decline into a miniature personality test.

Consider the difference:

Get 15% off / Continue without discount

versus

Yes, I love saving money / No, I prefer paying full price

The first pair describes consequences.

The second pair describes the user.

That is the tell.

When an interface starts assigning character traits to the person who says no, the copy is no longer simply explaining an offer.

It is trying to make embarrassment do part of the sales job.

Posted on

Mandatory app installation for tasks formerly available on the web

A browser is already an app.

That obvious fact gets strangely easy to forget when a service decides the browser is no longer enough.

Facebook provided a clean example in 2016. People using Facebook’s mobile website could send and receive messages without installing Messenger. Then Facebook began disabling that capability for many mobile-web users and directing them to install the Messenger application instead.

Facebook is disabling messaging in its mobile web app to push people to Messenger

The task already worked

The important detail is not that Messenger existed.

Facebook had every reason to build a dedicated messaging app. Native applications can provide better notifications, camera integration, background behavior and richer features than a basic mobile website.

The issue is that users already had a functioning browser route.

Earlier, Facebook had removed messaging from its main iPhone and Android applications and pushed smartphone users toward Messenger. At that stage, mobile-web users were still able to message through the site.

Facebook Forces Users Worldwide To Download Messenger For Mobile Chat

By 2016, even that escape route was being narrowed. Facebook told TechCrunch that Messenger offered the “best experience,” while Messenger head David Marcus later said the company kept mobile-web messaging on some older devices with limited memory or network conditions.

Facebook isn’t entirely killing off the mobile web version of Messenger

That exception proves the burden was real enough to measure.

Installation changes the relationship

A website asks for a URL and a compatible browser.

A mandatory application can ask for storage space, operating-system compatibility, updates, permissions, notification access and a place on the device indefinitely.

For a person who uses Facebook messaging constantly, the trade may be trivial. For someone checking one message on an old phone, shared device or storage-starved handset, it is not.

The web’s great trick was supposed to be that the software could stay on the server. You did not need a separate executable for every business, newspaper, forum and conversation service you visited.

Mandatory apps partially reverse that bargain.

Better features do not require deleting the simpler path

There is a legitimate product argument for native apps. Facebook said Messenger users responded faster and the dedicated application made it easier to build a richer messaging ecosystem.

That explains why Facebook wanted people in Messenger.

It does not explain why the browser option had to disappear for capable devices.

Those are different decisions.

A service can offer a better app and let the web version remain boring. When the old path is deliberately blocked, installation stops being an upgrade choice and becomes an admission ticket.

The task did not become impossible in a browser.

The platform decided the browser was no longer where it wanted the task to happen.

Posted on

Third-party client restrictions that narrow user choice

A service and its interface are not the same thing.

For years, Twitter users could read the same network through clients such as Twitterrific, Tweetbot, Fenix and Echofon. Those applications used Twitter’s API but supplied their own interface, notification behavior, accessibility choices and power-user features. Some third-party clients were older than Twitter’s own native mobile apps.

That arrangement ended abruptly in January 2023.

The clients stopped first

On January 13, multiple third-party Twitter clients stopped working. Their developers reported failed API requests and suspended credentials without a clear explanation from Twitter. Ars Technica documented the failures while noting that Twitter-owned TweetDeck still worked.

https://arstechnica.com/tech-policy/2023/01/third-party-twitter-clients-are-broken-whether-by-policy-or-glitch/

A few days later, Twitter said it was enforcing “long-standing API rules.” Then on January 19, its developer agreement was changed to prohibit using licensed materials to create a substitute or similar service to Twitter’s own applications. TechCrunch and Ars both documented the new clause and the timing of the change.

Twitter officially bans third-party clients after cutting off prominent devs

https://arstechnica.com/tech-policy/2023/01/twitter-retroactively-changes-developer-agreement-to-ban-third-party-clients/

The practical meaning was uncomplicated: if an app’s purpose was to provide another way to use Twitter, that app was no longer welcome.

Alternative clients provide more than different colors

Third-party clients can compete on things the platform owner does not prioritize.

One may use denser timelines. Another may offer stronger filtering, keyboard navigation, different notification controls, or a cleaner experience with fewer distractions. A client can also remain comfortable for users who built years of muscle memory around it.

None of that requires a separate social network. The user keeps the same identity, follows the same people and reads the same conversations.

That is exactly why client choice matters. It separates the network from one mandatory presentation of the network.

The official interface becomes part of the price

Once alternative clients disappear, changing interfaces means changing services.

A user who dislikes the official application cannot simply choose another front end while keeping the same social graph. The remaining options are to accept the official interface, use whatever limited alternatives the platform still permits, or leave the network entirely.

There can be legitimate reasons to restrict APIs: security, abuse prevention, infrastructure cost and product consistency are real concerns. But banning substitute clients goes further than limiting abusive requests. It makes the platform’s own interface a condition of participation.

The network may contain the same people the next morning.

The choice around how to reach them is gone.

Posted on

Bundled products that make users pay for unwanted services

Bundling is convenient when you want the bundle.

It gets stranger when the package grows, the price rises, and the new thing is something you never asked for.

Microsoft provided a useful example in January 2025 when it announced that Copilot and Microsoft Designer would be added to Microsoft 365 Personal and Family subscriptions in most markets. At the same time, Microsoft said U.S. prices for those plans would increase by $3 per month.

Microsoft explained the change in Copilot is now included in Microsoft 365 Personal and Family.

The bundle changed rather than remaining a menu

A Microsoft 365 customer might primarily want Word, Excel, PowerPoint, OneDrive storage, or Outlook.

Another customer might value Copilot enough to pay extra for it.

Bundling collapses those separate preferences into one package.

The standard Personal and Family plans gained the AI features and the standard subscription price rose. Microsoft did provide alternatives for existing subscribers: it said people with recurring billing could switch to Basic or, for a limited time, Personal Classic or Family Classic plans without Copilot or AI credits.

That qualification matters. This was not literally “use Copilot or lose Office tomorrow.”

But the default product direction was clear: AI became part of the main consumer subscription rather than remaining a separate optional purchase.

Bundles hide individual prices

Suppose a subscription contains six services and rises by $3 after a seventh is added.

A user who loves the seventh service may see a bargain.

A user who never opens it may see a price increase on the six things already being used.

Both are looking at the same invoice.

That makes bundles difficult to evaluate because the provider can point to the total value of everything included, while each customer assigns a different value to the pieces.

The bundle may objectively contain more features and still be worse for a particular user.

Standalone choice is what disappears

Software companies have good reasons to bundle products. One subscription is easier to market, support, bill, and integrate. New features also become available to a huge installed base immediately instead of waiting for people to discover and buy them separately.

The cost is granularity.

When a feature is sold independently, its price is exposed to a simple test: do enough people want this badly enough to pay for it?

When it is bundled into an established subscription, that test becomes fuzzy. Revenue from customers who mainly want the older products can help fund the new one too.

The useful question is not whether the bundle is “worth it”

There is no universal answer because customers use different parts of the package.

The better questions are measurable:

  • What was included before?
  • What was added?
  • How much did the price change?
  • Can the added service be declined without losing the older product?
  • Is an unbundled alternative permanent, temporary, or unavailable?

Microsoft’s 2025 change is interesting because it exposes all of those questions at once.

A subscription can become more capable and less optional at the same time.

Posted on

Pay-for-privacy offers and the unequal ability to avoid surveillance

A privacy option can be perfectly visible and still be unaffordable.

That is the tension inside consent-or-pay models.

The user is offered two versions of a service:

  • accept certain personal-data processing, often for behavioral advertising, or
  • pay for an alternative that avoids some of that processing.

At first glance, this looks cleaner than a hidden tracker.

The trade is explicit.

The harder question is whether everybody has the same practical ability to choose.

Price changes the meaning of the choice

In April 2024, the European Data Protection Board issued an opinion on consent-or-pay models used by large online platforms. The EDPB said those platforms should provide a real choice and warned that, in most cases, presenting only two options—consent to behavioral-advertising processing or pay a fee—will not be enough by itself to demonstrate valid consent under the GDPR. See the EDPB’s summary and Opinion 08/2024.

The opinion is specifically about large online platforms under European data-protection law.

It should not be stretched into a universal rule for every subscription product everywhere.

But the underlying economic problem travels well.

If one person can easily pay and another cannot, the same privacy setting has a different practical cost for each of them.

“No ads” and “no tracking” are not the same product

A paid tier also needs to be examined carefully.

It may remove advertisements while retaining analytics.

It may disable behavioral targeting while still collecting security logs, service telemetry, account information, or measurements needed to operate the product.

It may reduce sharing with advertising partners without deleting historical profiles already held elsewhere.

So the phrase pay for privacy is too broad unless the service explains exactly what changes.

Useful questions include:

  • Which processing stops?
  • Which identifiers stop being created or shared?
  • Does historical data remain?
  • Are ads removed, or merely made non-personalized?
  • Does the paid version still use analytics or fraud-detection signals?

The label matters less than the data flow.

Privacy can become a luxury feature

The EDPB’s opinion explicitly warned against turning data protection into a premium feature available only to those willing or able to pay.

That does not mean every paid privacy feature is illegitimate.

A service has costs. Subscription revenue can fund a product that collects less advertising data. Some users may genuinely prefer that exchange.

The inequality appears when surveillance is effectively the default price for people who cannot afford the alternative.

The Surveillance Economy becomes especially visible at that moment.

Tracking is no longer hidden in a pixel.

It has a dollar value printed beside the button.

The interesting question is not merely whether the user was offered a choice.

It is what the choice actually costs, and what privacy the payment really buys.

Posted on

Purposes bundled together inside a single data-use choice

One button can hide five decisions.

A privacy interface might ask whether you agree to personalized services.

That phrase can sound like one purpose.

Behind it may sit analytics, advertising, recommendation systems, audience measurement, data sharing, identity matching, fraud detection, and product research.

If all of those activities rise or fall with one switch, the user is not really deciding among purposes.

They are accepting a bundle.

A single choice can conceal unrelated uses

The problem is easiest to see when the visible feature and the secondary use are far apart.

A person may reasonably accept location so a weather app can show a local forecast.

That does not automatically mean they would make the same decision about using the location for advertising profiles.

Likewise, a customer may accept transaction processing while being less interested in behavioral advertising or cross-service personalization.

California’s current privacy guidance is useful here because it separates purposes conceptually. CalPrivacy says covered businesses must limit collection, use, and retention to purposes a consumer would reasonably expect, purposes compatible with those expectations and disclosures, or additional purposes the consumer actually agreed to. Collection and use must also be reasonably necessary and proportionate. See CalPrivacy’s CCPA FAQ.

That does not mean every multi-purpose setting is unlawful.

It does mean the purposes matter.

Bundling reduces information as well as choice

Suppose a privacy panel offers this:

Allow data use for improving services and personalized experiences.

That may sound harmless enough.

But a reader still needs to know what the system actually does:

  • Does “improving services” mean crash diagnostics?
  • Does “personalized” mean recommendations inside the app?
  • Does it mean targeted advertising across other services?
  • Are outside companies receiving the data?
  • Can analytics remain on while advertising stays off?

If the interface does not separate those questions, the user cannot express a more precise preference even if they understand the tradeoff.

The Federal Trade Commission’s report Bringing Dark Patterns to Light discusses interfaces that steer or obscure privacy choices, including designs that make meaningful refusal harder. Bundling is related but slightly different: the problem can exist even in a visually neutral interface if several distinct data uses are fused into one decision.

Granularity has costs too

There is an opposite failure mode.

A panel with 147 toggles can become useless homework.

Separating purposes does not require turning privacy into an aircraft cockpit.

The useful goal is understandable grouping: collection necessary for the service, optional measurement, optional personalization, optional advertising, optional sharing with outside parties, and other materially different uses.

The right amount of detail depends on the system.

But one principle survives the details:

A person cannot selectively consent to choices the interface never separates.

The Surveillance Economy often depends on turning many downstream uses into one convenient yes.

The clearer design asks which yes belongs to which purpose.

Posted on

Autoplay as a substitute for intentional selection

Autoplay quietly changes one important question.

Without it, the viewer asks:

What do I want to watch next?

With it, the platform asks:

What should play unless the viewer stops us?

That is not the same kind of choice.

YouTube’s current help documentation describes Autoplay plainly: when it is on, another related video automatically plays after the current one ends. The viewer can cancel or disable the feature, but if they do nothing, the next selection happens automatically. See Autoplay videos.

The important part is the default transition.

Continuing is weaker evidence than choosing

If a person searches for a video, reads several titles, and clicks one deliberately, that action contains a fairly clear signal of intent.

If another video begins because the viewer left the television on while washing dishes, the resulting view contains less information about preference.

The platform may still observe useful behavior after playback begins. Did the viewer stop the video immediately? Watch most of it? Like it? Search for something else? Those later actions can add context.

But the initial selection belongs partly to the recommendation system.

That matters when viewing behavior becomes training data for future recommendations. Passive continuation can generate watch history that resembles a chain of deliberate choices unless the system accounts for how each item began.

Defaults steer the direction of a session

Autoplay can also turn one intentional selection into an extended path.

A user chooses a documentary about a historical event. The system chooses a related interview. Then a commentary video. Then another creator’s analysis. After several rounds, much of the session may have been determined by successive recommendations rather than repeated searches.

This is convenient. It is one reason autoplay exists.

It also means the resulting session should not be read as a perfect diary of what the viewer independently wanted.

The user chose the first door.

The hallway may have been constructed automatically.

That distinction matters for Algorithmic Reality because platforms often learn from behavior that their own defaults helped produce.

Autoplay does not eliminate human choice.

It changes where the next choice begins.