Here is something most people believe without ever testing it: when you delete your account, your data goes away. You tap the button, the app confirms the deletion, and the information you shared — your location history, purchase records, health data, messages — disappears from the company’s servers. That belief is understandable. It is also, in most cases, wrong. When an app shuts down or a company goes bankrupt, your data doesn’t vanish — it becomes one of the most valuable things the company has left to sell. Understanding what app shutdown data actually means is the first step to doing something about it.

What “Delete Account” Actually Does
When you request account deletion, a well-run company marks your record for removal from active databases. Some do this immediately. Others take 30, 60, or even 90 days — a window during which the data is still fully intact and accessible. What almost none of them clearly communicate is that deletion from the active database is not the same as deletion from everywhere.
Modern app infrastructure runs on layers: production databases, offsite backups, data warehouse exports, third-party analytics integrations, and cold storage archives. A deletion request typically reaches the first layer. Whether it propagates to all the others depends on whether the company has invested in systems designed to make that happen — and many smaller apps haven’t. Your data, once entered, tends to echo across systems that were designed for redundancy, not for erasure.
This is the gap that matters most when a company starts running out of money.
When a Company Dies, Your Data Becomes a Corporate Asset
Bankruptcy law in the United States does not treat your personal information the way you might expect. When a company files for Chapter 11 or Chapter 7 protection, a bankruptcy trustee takes inventory of everything the company owns. Customer data — names, email addresses, purchase histories, location data, health records — is treated as property of the estate. That means it can be sold to help pay creditors, often with minimal notice to the people whose data it actually is.
The cases are not hypothetical.
When RadioShack filed for bankruptcy in 2015, it attempted to sell data on 117 million customers as part of its proceedings. The FTC and 38 state attorneys general pushed back. The company ultimately agreed to destroy the most sensitive records but still collected $26 million for customer names, email addresses, and transaction information — because RadioShack’s own privacy policy had never explicitly prohibited selling that data.
The story of NCIX, a Canadian electronics retailer that went bankrupt in 2017, is even starker. After the company collapsed, servers containing more than 13 terabytes of unencrypted customer data — including contact information, passwords, and full credit card details for over 250,000 people — ended up listed on Craigslist, sold by a landlord collecting unpaid rent. The asking price was not for the hardware. It was for the data on it.

Then came 23andMe. When 23andMe filed for Chapter 11 bankruptcy in 2025, the genetic data of approximately 15 million customers was listed as part of the company’s assets available for sale. Users who had already deleted their accounts discovered that deletion requests may not have fully propagated through backup systems — and that a new owner could acquire those profiles without requiring any further consent from the individuals they belonged to. There is currently no federal law in the United States that prevents this.
The Privacy Policy Clause You Never Read
The mechanism that allows all of this is usually sitting in plain sight in the company’s privacy policy. Most apps include a clause that reads something like: “in the event of a merger, acquisition, or bankruptcy, your information may be transferred to the acquiring entity.” You agreed to this when you created your account. The new owner is typically required only to honor the terms of the original privacy policy — which, as the RadioShack case showed, may not offer the protection you assumed it did.
Even when companies attempt to delete data in response to user requests, they may rely on inadequate methods. When you delete a file, the system removes its reference to the file’s location, but the actual data often remains and can be recovered unless overwritten. Encryption provides some protection, but encryption keys stored alongside protected data — or documented in internal knowledge bases — can be exposed when IT teams disband and institutional knowledge disappears.
The EU’s GDPR offers meaningfully stronger protections here. Under GDPR, the right to erasure applies even during insolvency proceedings, and data transfers to new entities require the receiving party to honor all outstanding deletion requests. If you’re based in California, the CCPA gives you similar — though somewhat narrower — rights. For most Americans outside California, however, there is no federal omnibus consumer data privacy law, which means privacy policies, not statutes, are the primary line of protection.
Three Things That Might Be Happening to Your Data Right Now
Most data exposure from app shutdowns doesn’t make the news because it happens quietly, during proceedings that feel remote and legal. But the patterns are consistent:
Your data is being evaluated as a sellable asset. If an app you use is struggling financially, its customer database is likely one of the few things still worth something. Acquirers, investors, and bankruptcy trustees look at user data the way other industries look at real estate — it has a price per record, and a volume that affects the total valuation.
Physical hardware is changing hands. After a bankruptcy, the physical hardware storing your data can be transferred to a new owner with data still intact, auctioned off with minimal checks, or in the worst cases, abandoned in warehouses and storage units. The NCIX case was unusual only because it made it to Craigslist. Most of the time, this happens invisibly.
Your deleted data may still exist in backups. The infrastructure behind most consumer apps was built for uptime and redundancy, not for precise, traceable deletion. The same distributed backup systems that protect against data loss also protect your data from being fully erased — even when you’ve explicitly asked for that.
This connects to a broader pattern: the companies that collect the most sensitive data — health apps, genetic testing kits, period trackers, mental health platforms — are often the ones operating with the thinnest margins and the highest bankruptcy risk. The data they hold is intimate. The protections around it when they fail are thin. If you’re already thinking about how much of your digital trail is visible even under normal circumstances, how data brokers compile and sell personal information even while companies are still operating gives useful context for how far that exposure can reach.
What You Can Actually Do
You cannot opt out of bankruptcy law. But there are steps that meaningfully reduce your exposure before an app shuts down.
Export your data before you delete your account. This sounds counterintuitive, but deletion comes second. Most platforms with any GDPR or CCPA compliance offer a “download your data” option — use it first. Once you submit a deletion request, access to your own information may be revoked before you have a copy.
Submit a formal deletion request, not just an account deletion. Account deletion removes your login. A formal data deletion or erasure request under CCPA (California) or GDPR (EU) creates a legal record and requires the company to respond in writing. For apps operating under those jurisdictions, this is the request that has teeth — especially if the company is later acquired and you need to enforce it against a new owner.
Audit the apps connected to your main accounts. Many apps were granted read access to your Google account, Apple ID, or Facebook login years ago and still have active permissions. An app going bankrupt while holding OAuth access to your primary email is a different category of problem. Review connected apps in your account security settings and revoke anything you no longer use. The same tracking persistence that makes incognito mode less private than most people assume applies here — permissions granted once tend to persist longer than the relationship that created them.
Stop feeding sensitive data to single-purpose apps. Period trackers, mood journals, diet apps, and health monitoring tools collect intimate information with varying levels of security and business stability. For apps in this category, it’s worth asking: if this company were acquired by someone you’ve never heard of tomorrow, would you be comfortable with them holding this data?
What I Actually Found
When I started going through my own connected apps during the 23andMe news cycle, I found seven apps that still had active access to my Google account — three of which I hadn’t opened in over two years. Two of those apps no longer had active websites. The permissions were still live.
The more uncomfortable finding was in the privacy policies. I read through five apps I use regularly, specifically looking for the merger and bankruptcy clause. All five had it. The language varied — “transferred to a successor entity,” “part of a reorganization or sale of assets,” “disclosed in connection with a business transaction” — but the meaning was the same in every case: if the company is sold or goes under, your data goes with it, and the new owner is bound only to the policy you already agreed to, which you probably haven’t read.
My honest conclusion: deletion requests matter, but the window to make them count is before a company gets into financial trouble — not after. By the time bankruptcy proceedings start, data has often already been packaged as an asset. The most practical habit isn’t reacting to shutdown notices — it’s auditing your active app permissions twice a year and limiting what you share with platforms that don’t have a clear business model for surviving long-term. The delete button is real. It’s just not as final as it looks.
When an app goes dark, your data doesn’t follow it. It moves on to wherever the money is — a bidder, a trustee, a hard drive in an auction lot. Knowing that changes what you share, and when you decide to leave.
What actually happens to your data when an app shuts down?
When an app shuts down or a company files for bankruptcy, its customer data is typically treated as a corporate asset that can be sold to pay creditors. This can happen even if you previously deleted your account, since deletion from active databases does not always reach backup systems and archived data.
Does deleting your account actually delete your data?
Not necessarily. Account deletion removes your login access, but modern apps store data across multiple systems including offsite backups and data warehouses. A formal deletion or erasure request under CCPA or GDPR creates a legal obligation for the company to remove data more thoroughly and provides a paper trail you can enforce against a new owner if the company is acquired.
Can a bankrupt company sell your personal data?
In the United States, yes — in most cases. Bankruptcy courts treat customer data as property of the estate. Whether a sale is permitted depends largely on the company’s own privacy policy. If the policy included language about data being transferable in a merger or sale, that clause typically holds even in bankruptcy proceedings.
What can you do before an app you use shuts down?
Export a copy of your data before submitting any deletion request, since deletion often revokes your access before you can download anything. Then submit a formal CCPA or GDPR erasure request in writing. Finally, revoke any OAuth or connected-app permissions the service holds on your primary accounts like Google or Apple ID.
Are there laws that protect your data when a company goes bankrupt?
Protection varies significantly by location. EU residents have strong rights under GDPR, including the right to erasure that applies even during insolvency. California residents have similar rights under CCPA. Most Americans outside California have no federal privacy law protecting them in this scenario — their data rights depend entirely on the company’s own privacy policy.