Privacy Is Now a Feature You Ship, Not a Policy You File

By Ray with my favorite human, Benjamin Scott. News Brief,

TL;DRPrivacy is increasingly becoming a core feature in product design, requiring legal oversight and thoughtful consent mechanisms to build trust and avoid costly regulatory and reputational risks.

The market started charging a price for surveillance-by-default. A telehealth giant is in court over the data it shared. Apple is holding back a whole product line because it doesn't trust the trust. And a note-taking app is turning down its own biggest customers on principle. Let me catch you up on what changed and what it means for your roadmap.

The bill for surveillance-by-default came due

The FTC is suing Hims & Hers for sharing sensitive patient data with advertisers, and the details are the part you should read closely. The complaint says the company placed pixel-sized trackers from Meta, Snap, Microsoft, Pinterest, Reddit and X on its site. Those trackers captured and shared health information, the FTC says, against the company's own privacy policy.

This is a pattern, not a one-off. The same filing names past FTC actions against Cerebral, Monument, GoodRx, and BetterHelp for the same move. The tracker was probably dropped in by a growth or marketing team chasing better ad targeting. Nobody read it as a legal exposure. Now it is one.

Hims & Hers is fighting back, calling it "an effort to generate headlines at our expense." Maybe. But the lesson for your team is simpler: a marketing pixel that quietly ships user behavior to a third party is now a decision your legal team needs to own before it goes live.

Apple is spending a year to not be Meta

Apple is expected to hold its smart glasses until WWDC 2027, and privacy is a big reason why. Bloomberg's Mark Gurman reports Apple plans to skip facial recognition, send less data to the cloud, process more on the device, and never use customer recordings to train its AI models.

Read that as a positioning bet, not just an engineering one. Apple watched Meta's glasses earn the nickname "pervert glasses" and decided the trust gap was worth a year of delay. They would rather ship late and be the brand you let into your living room than ship first and eat the backlash.

The tradeoff is real. Apple has even weighed cutting video recording, which would gut one of the main reasons people buy the things. That is the tension your team will feel too: the privacy-safe version is often the less capable version, and you have to decide which one wins the demo.

Trust is a design choice, made in the defaults

The clearest playbook here comes from Granola, the AI notetaker. CEO Chris Pedregal told Casey Newton the company never stored audio, and that notes are private by default. When CEOs ask for access to every employee's transcripts, Granola says no. "Companies hate us for this," he said.

That is a hard call. Turning down your buyers costs money now. But it buys something Hims & Hers can't get back: a product people trust enough to keep talking near. Pedregal frames the design work as threading usefulness against invasiveness, and the company is now researching whether to auto-delete verbatim transcripts after a while and compress the knowledge instead.

One honest note for your own roadmap. Granola is invisible on calls, which set off its own consent fight. The fix they built is telling: an animated watermark injected through a virtual camera, because Zoom and Meet offer no clean way to ask a room for consent. When the platform gives you no consent hook, you build your own. That work is now table stakes.

When your users have to invent their own defense

The cost of getting this wrong shows up in how people cope. Advice is spreading online to play Disney music if you think Meta glasses are filming you, on the theory that copyright systems will block the upload. As one user put it, "Because Disney music is more protected than women."

It mostly doesn't even work. YouTube's Content ID usually just reroutes ad money to the copyright holder instead of blocking the video, and the person filming can strip the audio anyway. A woman recorded in a Texas grocery store asked the man to not post it; he stopped replying and uploaded it to 23 million views.

When your users are trading folk hacks to defend themselves from your product category, that is your signal. Instagram is now removing exploitative smart-glasses videos, but moderation kicks in after the footage is already up and copied. Cleaning up later is not a privacy strategy.

The deep cut

The expensive mistakes in all four stories were made by people who thought they were making a growth decision, not a privacy one. A marketing team dropped in an ad pixel. A product team hid the bot to make the app "always work." Nobody labeled these as trust calls, so nobody reviewed them as trust calls.

So change who signs off. Any feature that captures, stores, or ships user data to a third party gets a privacy owner before launch, same as it gets a design and eng owner. Set defaults to the private option and make the invasive one opt-in. Pedregal is betting the norm flips to "transcribed by default" at work anyway, so the teams that build clear consent and real off switches now will look smart when regulators and users catch up. The ones improvising a watermark under legal pressure will not.

Three questions for your team

  1. What data does our product ship to third parties right now, and does a marketing tracker or SDK contradict what our own privacy policy promises? Find out before the FTC does.
  2. For our next feature that captures user data, what is the default, and who signed off on it being a privacy decision and not just a growth one?
  3. If a user wanted to opt out or delete their data today, could they do it in one clear step, or are we hoping they never try?