Yes-this is a mess, and this article isn't an accurate report. Basically-this was a private company that set itself up as a developer-same as, say, Candy Crush makers or those quiz things about your friends on FB. As a developer, it got access to API (see
here
http://readwrite.com/2013/09/19/api-defined/ for definition) that allowed it to build programs into FB. This allowed it to write programs targeting publicly available information on FB platform.
That means-no private chats, no private groups, no data that users haven't made publicly available. The point of APIs in this context is SUPPOSED to be so advertisers (from small business to nonprofits to Andela, etc.) can send ads to targeted users. This
group completely violated our policies and used their API access to target publicly available info to send to police. FB has kicked them off our platform. As you can imagine, there are many conversations now about this. But key to know that FB did NOT and
does not sell user data; that this was a completely unauthorized use of our developer platform, that we rectified this as soon as we were notified, that the access was not to user data, but essentially a program that allowed them to target public info on
Facebook. It's still unacceptable, and something we are taking extremely seriously.