One idea from
@TheARCTERMINAL's recent research really stuck with me.
A company privacy policy isn't always the final word.
Under certain legal circumstances, data that users believe has been deleted may still need to be retained.
That's an important distinction.
Privacy enforced by policy can change.
Privacy enforced by architecture is much harder to override.
The strongest privacy systems don't rely on promises or trust.
They minimize what can be collected, protect what must exist, and make security a property of the system itself.
That's the direction privacy infrastructure should be moving.