‹ BackHN Continuity

Thread

Google AI Studio fakes data deletion. VRP auto-banned me in 60s for reporting it

56 points · 39 comments · Bitu79

  1. jasonkester · · focus · HN ↗
    Anybody who has ever run a website with customer data can instantly understand why they do it this way. I don't see any malice.

    It's simple, really. You have a website where people can upload their cat photos. There's a delete button. People click the delete button, read the "This will really Delete your Thing. It's Permanent. You CAN'T GET IT BACK!" warning, and click the confirm button.

    Then you get an angry email (and twitter post, and blog entry, and Reddit mob) saying "I can't believe you deleted my photo without asking. That was my favorite cat photo it was my only copy I'LL SUE YOU!@!!"

    So you go into your console and flip the .isActive bit back to 1 on that photo, send off your stock apology, and get on with your day.

    To run your business any other way is madness. You're not training or selling or otherwise misusing that cat photo. You just don't want to deal with that hassle every day. So you "delete" things by moving them someplace where they're not public anymore.

    It's just what you do...

    1. bot403 · · focus · HN ↗
      No, sorry. Promising to permanently delete data without doing it is the madness and should be illegal if it's not already. Hide the permeantly delete for privacy just a bit further and offer a soft delete to the user then for the normal case.
      1. jasonkester · · focus · HN ↗
        But that's silly. If you don't trust a website with your cat photo, don't upload your cat photo the website.

        As I said above, the only thing my site does with your cat photo is show it back to you when you ask to look at it. No training. No selling your data to anybody. All I'm doing is storing it because you asked me to, and showing it to the people you ask me to.

        You can certainly ask me to stop showing it to people. But please don't get all excited about how your rights have somehow been violated.

        The fact is, people click delete buttons without thinking about it. Those people get way more mad when they can't undo that delete than you are now.

        1. Bitu79 · · focus · HN ↗
          This is honestly a foolish response, but I'm still not going to flag you. In fact, I'll even upvote your comment so you get a point. I'm sure you aren't writing this nonsense out of malice—you just genuinely don't understand the issue.

          Deletion means deletion. There is no such thing as 'we didn't delete it just in case you did it by accident.' That is just a convenient excuse for illegally hoarding user data, and the law strictly forbids it. What is their lawful basis under the GDPR to keep it after I demand deletion? Exactly: none at all.

          1. UncleMeat · · focus · HN ↗
            > What is their lawful basis under the GDPR to keep it after I demand deletion?

            GDPR explicitly permits deletion timeframes. It does not demand that files are instantly destroyed as soon as you click the button.

            1. Bitu79 · · focus · HN ↗

              [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.