In 2014, WhatsApp founder Jan Koum announced that Facebook had acquired WhatsApp for $19 billion. The announcement was accompanied by explicit assurances: WhatsApp’s founding principles wouldn’t change, users’ private messages would stay private, and nothing about how WhatsApp handled data would be different because of the acquisition.
Two years later, WhatsApp updated its privacy policy to allow sharing user data — including phone numbers and usage patterns — with Facebook’s parent company for targeted advertising and account security purposes. Users who had chosen WhatsApp specifically because of its stated independence from ad networks found themselves in a different product than the one they’d selected.
The WhatsApp case is the most prominent example of a pattern that repeats across the technology industry at smaller scale, constantly: a company makes privacy commitments as part of its original value proposition, gets acquired by a company with different incentives, and the commitments change. Understanding how this works — and what protections actually exist — is useful before you invest your personal files and memories in any privacy-first product.
What Acquisition Means for Your Data
When a company is acquired, its assets transfer to the new owner. For most technology companies — especially privacy-focused ones with meaningful user bases — the user data is among the most commercially valuable assets being transferred. A privacy-first app with a few million users has millions of users’ worth of stored files, behavioral data, and profile information that the acquirer is paying for, whether or not that’s stated explicitly.
The legal framework governing what happens to that data is more nuanced than “the acquirer gets everything and can do whatever it wants.” But the protections are weaker than most people assume.
What the FTC Says — And What It Can Actually Enforce
The Federal Trade Commission has taken the position that a company’s privacy policy constitutes an enforceable promise — one that survives acquisition. If a company promises users it will never sell their data to third parties, the acquiring company is bound by that promise under the FTC Act’s prohibition on deceptive trade practices.
This sounds like robust protection. In practice, it has significant limits.
Enforcement is reactive. The FTC can act against documented violations but doesn’t proactively monitor every policy change made by every acquired company. Enforcement follows complaints and documented harm, not continuous surveillance of what acquirers do with inherited data.
Policies can be changed, with notice. Companies regularly update their privacy policies after acquisition — giving users adequate notice and the opportunity to delete their accounts before the new policy takes effect. The FTC generally views this as acceptable. The original promise isn’t permanent; it can be amended through the update process. The key question is whether the notice is meaningful — whether a typical user would understand what’s changing and have a realistic opportunity to act on it.
“Sale” and “sharing” are legally distinct in ways that matter. Many privacy laws prohibit selling user data to third parties while permitting sharing it with affiliated companies for “internal” purposes. After an acquisition, the target company becomes affiliated with the acquirer. Data flows between the two companies often don’t constitute a “sale” under the legal definition, even if they involve the target’s user data being used for purposes the original policy didn’t contemplate.
The 23andMe Case: Bankruptcy as the Extreme Version
The 23andMe bankruptcy in early 2025 illustrated what happens to sensitive personal data when a company becomes unable to honor its original commitments through insolvency rather than acquisition. It’s a different legal scenario, but it demonstrates the same underlying dynamic.
23andMe collected genetic data from millions of customers under privacy commitments that were central to why customers trusted the service. When the company entered bankruptcy proceedings, that genetic data was listed as an asset available to creditors and potential buyers. The resolution wasn’t determined by what 23andMe had promised its customers — it was determined by creditor interests and bankruptcy proceedings.
The acquisition scenario is legally different: the acquiring company is solvent, bound by the target’s contractual commitments, and subject to FTC enforcement. But both cases make the same point visible: the privacy promises attached to your data are only as durable as the entity making them and its incentives to keep them. When those incentives change — through acquisition, through a pivot to a different business model, through financial pressure — the promises can change too.
How Acquisition Typically Unfolds for Users
The pattern is consistent enough to describe in stages.
Stage 1: The announcement. The acquisition is announced alongside explicit assurances about continuity. The privacy-first positioning that made the acquired company valuable to users is preserved in the messaging. This stage often includes direct communication from the founding team.
Stage 2: Integration period. The company operates substantially as before while technical and operational integration occurs. Users typically see no change in their experience during this period, which can last months to years.
Stage 3: Privacy policy update. Users receive an email or in-app notice about updated terms of service and privacy policy. The notice is legally compliant — it gives adequate notice, links to the new policy, and provides a deletion option. The changes can be significant: new data-sharing arrangements, new retention periods, new uses for historical data, integration with the parent company’s systems.
Stage 4: Data integration. Under the new policy, data flows in ways the original policy didn’t permit. Depending on what was collected and what the acquiring company does with it, this can range from cross-service profile matching to outright commercial use of previously private content.
Users who don’t read the policy update, don’t use the opportunity to delete their accounts before the new policy takes effect, or who continue using the product after the policy change have effectively accepted the new terms.
Warning Signs to Watch For
Some acquisition trajectories are more predictable than others.
The product is free and the user base is large. A privacy-focused product that’s free to use and has built a large user base without monetizing that base has implicitly built something that could be sold. VC-backed privacy apps that haven’t reached profitability on their stated model are eventually going to need an exit — and the user data often is the exit.
The most recent funding round was large at a high valuation. A large round at a high valuation means investors expect a return proportionate to what they put in. The typical mechanism is an acquisition. The acquirer is usually a larger company with a data strategy.
The product has obvious strategic value to a larger platform. A privacy-preserving photo storage app that a major cloud platform or advertising network would benefit from owning is a more predictable acquisition target than a narrow utility tool with no obvious strategic value to big tech.
The founding team signals an exit in interviews. Founders who talk about “building the privacy layer for [big company category]” or “becoming the default for [user segment]” are often describing an acquisition thesis, not just ambition.
None of these are certainties. But if a service you’re trusting with personal files exhibits these characteristics, it’s worth asking: what happens to my data if this company gets acquired?
Due Diligence: How Acquirers Value Your Data
Understanding the acquirer’s perspective is useful for understanding what happens after the deal closes.
M&A due diligence in technology acquisitions now routinely includes a privacy and data assessment that treats the target’s user data as a core asset to be evaluated. Acquirers assess: how many users, what data types, consent quality for various uses, technical accessibility of the data, and what policy changes would be possible with adequate user notice.
A 2026 Morgan Lewis publication on M&A data privacy described this directly: failures to properly assess a target company’s data landscape can lead to unforeseen liabilities, while properly assessed data is a significant source of deal value. The user data isn’t incidental to the acquisition — it often is the acquisition.
GDPR and CCPA add obligations that don’t disappear in a transaction. Personal data of EU and California residents can’t be transferred to a new controller without maintaining the legal basis under which it was collected. In practice, this means acquirers must honor the consent framework of the acquired company — or obtain fresh consent for new uses — when it comes to covered users. This is a real constraint, but it’s procedural, not absolute: the consent can be updated through the standard policy-update process.
What Structural Commitments Actually Look Like
The most durable protection against acquisition-driven privacy changes is a business model that doesn’t create an acquisition pressure or incentive in the first place.
A subscription-funded company — where the customer is the customer, not the product — has fundamentally different incentives than one whose business model involves data monetization or finding an acquirer for the user base. Subscription models create alignment: the company earns by retaining customers, which means keeping customers happy, which means maintaining the privacy commitments customers chose the service for.
The most transparent version of structural commitment combines:
- A subscription business model with no advertising revenue or data brokerage
- Privacy commitments backed by technical mechanisms (encryption, explicit no-AI-training policy) rather than just policy language
- Clear deletion processes that result in actual, irreversible erasure
daftei is funded by subscriptions — 5 GB free, Pro at $5.99/month, $44.99/year, or $89.99 lifetime — with no advertising, no data brokerage, and no AI training on user content, including third-party AI. Files are encrypted with AES-256 at rest and TLS 1.3 in transit. Account deletion triggers a 30-day grace window, after which deletion is permanent and irreversible. GDPR and CCPA compliance is baseline, not a geographic add-on.
These commitments are reflected in both the technical architecture and the business model — not just in a policy document that a future acquirer could update with adequate notice.
What You Can Do Right Now
Regardless of which services you currently use, there are concrete steps that limit your exposure if a privacy-first service you rely on gets acquired.
Export your data regularly. Most services that comply with GDPR or CCPA provide a data export mechanism. Using it periodically ensures that if terms change after an acquisition, you have a complete copy of your data in a portable format and can leave without starting over. The export is yours — it doesn’t depend on the service continuing to operate under the terms you chose.
Read privacy policy change notices. Policy update notifications that arrive shortly after an acquisition announcement are almost always the mechanism through which data terms change. Read the specific changes, not just the summary. Look for changes to what the company can do with your historical data, not just data going forward.
Use the deletion window. Most policy updates that make significant changes include a transition period during which you can delete your account under the old terms. If the new terms aren’t acceptable, this window is when deletion has the most legal weight.
Prefer subscription models over free privacy services. Where you have a choice between a free privacy service funded by an eventual exit and a paid service funded by subscriptions, the paid service’s incentive structure is more likely to remain aligned with its privacy commitments over time. The payment is, among other things, a signal about what the business model actually is.
The Underlying Question
Privacy promises made by companies are only as reliable as the conditions under which those companies operate. When those conditions change — through acquisition, through financial pressure, through a pivot to a different model — the promises can change too. The structural question isn’t whether a company’s current privacy policy says the right things. It’s whether the business model gives the company a lasting reason to keep those commitments.
That’s the question worth asking before you decide where to store the things that matter most.