39 comments

pixel_popping11 days ago
I doubt much people using Google think that their data would just magically disappear the moment they click a button, to the contrary, I believe most qualified users would know that their data is forever stored, maybe "anonymized" sure (but can still be correlated back).

If some users think this, have they question the Why would they do it? Why would Google lose money that way? ToS is irrelevant when it comes to what's running on their own private infra.

stackghost11 days ago
Kudos to the author for not being so bitter and jaded, like me, and reporting this thinking some change might come.

I have mostly resigned myself to watching in unsurprised disgust as tech companies (aided by oodles of HN users who work there!) ruin everything they touch with legal impunity.

Bitu7911 days ago
thx
oefrha11 days ago
I want to take this seriously, but eight (slop?) rehash of the story on the blog isn’t helping with credibility. Pro tip: don’t do that, however triggered you are, it definitely doesn’t help.

I don’t use Google AI Studio so can’t verify, good luck.

Bitu7911 days ago
thx!!!!!
jasonkester11 days ago
Anybody who has ever run a website with customer data can instantly understand why they do it this way. I don't see any malice.

It's simple, really. You have a website where people can upload their cat photos. There's a delete button. People click the delete button, read the "This will really Delete your Thing. It's Permanent. You CAN'T GET IT BACK!" warning, and click the confirm button.

Then you get an angry email (and twitter post, and blog entry, and Reddit mob) saying "I can't believe you deleted my photo without asking. That was my favorite cat photo it was my only copy I'LL SUE YOU!@!!"

So you go into your console and flip the .isActive bit back to 1 on that photo, send off your stock apology, and get on with your day.

To run your business any other way is madness. You're not training or selling or otherwise misusing that cat photo. You just don't want to deal with that hassle every day. So you "delete" things by moving them someplace where they're not public anymore.

It's just what you do...

bot40311 days ago
No, sorry. Promising to permanently delete data without doing it is the madness and should be illegal if it's not already. Hide the permeantly delete for privacy just a bit further and offer a soft delete to the user then for the normal case.
UncleMeat11 days ago
It is permanently deleted. It just takes a little while.
Rygian10 days ago
It's already illegal in Europe, as long as the data falls into the PII category.
jasonkester11 days ago
But that's silly. If you don't trust a website with your cat photo, don't upload your cat photo the website.

As I said above, the only thing my site does with your cat photo is show it back to you when you ask to look at it. No training. No selling your data to anybody. All I'm doing is storing it because you asked me to, and showing it to the people you ask me to.

You can certainly ask me to stop showing it to people. But please don't get all excited about how your rights have somehow been violated.

The fact is, people click delete buttons without thinking about it. Those people get way more mad when they can't undo that delete than you are now.

Bitu7911 days ago
Exactly! This is my problem too, because they are lying. Promising to permanently delete data without actually doing it is insane, and it should be illegal if it isn't already. Hide the permanent deletion a bit more for privacy reasons, and normally offer a soft delete to the user. But they are just lying!
Tzk11 days ago
Well, no. Correct behavior would be to state „your data will be deleted and may be recovered for X days“. Claiming full and permanent deletion and then not deleting it is malicious behavior and should be against the law (at least inside the EU).

So forwarding it to NYOB is a good choice.

Bitu7911 days ago
Exactly! But unfortunately, the reality is incredibly frustrating. I actually wrote to a woman at NOYB. She replied at first, but now they have gone completely silent! I honestly wonder if they just don't understand the technical side of the problem. It’s the exact same story with the Irish DPC. But with them, I think they are actively protecting Google. There’s a reason people call the DPC 'Google’s shield.' They even gave me a hard time once because I use AI to write my emails... xD But what the hell am I supposed to do if I don't speak fluent English and need to explain a complex architectural fraud? I’m doing my best, but the system is deaf.
mrd3v011 days ago
Oh yeah, poor corporations, getting sued(!!) for deleting data after being asked by the user to delete it.

Beautifully crafted ragebait :D

Bitu7911 days ago
They are not a 'poor large corporation'—the problem is that they don't delete anything. They just lie and say they do, while in reality, nothing is deleted. I proved it against them with the JSON restore
sapphicsnail11 days ago
You could just not put a delete button in the first place
Bitu7911 days ago
This cannot be an excuse. The data is clearly used for AI training. If that were actually the case, they would state the truth on the UI buttons instead of lying, and they wouldn't have banned me from VRP either. They lie constantly and they do not comply with the law. I have been writing to them for almost a year, and not a single human has ever replied to me—even their DPO is just an automated script!

Read the full thread on Hacker News →

Related stories