← all articles

Getting your data out of a company that is closing

You get the email: “We’re sad to announce that [Service] will be shutting down on [date].” Somewhere below the goodbye message is a line about exporting your data, usually vague, usually with a deadline that’s shorter than it sounds once you factor in how long exports take to generate. This is a good moment to stop skimming and start acting, because once the shutdown date passes, your leverage disappears along with the service.

This isn’t about mistrust of any particular company. It’s about understanding what a shutdown actually does to your data, mechanically, so you can get out what matters before it’s gone.

What “shutting down” means for your data

A company closing doesn’t mean your data evaporates on day one. What happens depends on what kind of closure it is, and the differences matter.

If the company is winding down cleanly, the typical sequence is: stop taking new signups, give existing users a window to export or migrate, then decommission the infrastructure. Decommissioning usually means deleting production databases and storage buckets, and eventually letting backups age out per whatever retention schedule they were on. That backup tail is important: even after the app stops working, your data can sit in a backup snapshot for weeks or months before it’s actually gone. That’s not a loophole you can use to get your data later, it’s just a reason the risk window doesn’t close the instant the login page dies.

If the company is being acquired, the calculus flips. Your data is often the asset being bought. It gets migrated to the new owner’s systems, sometimes under a new privacy policy that’s less favorable than the one you agreed to. The shutdown notice for the old brand can arrive after the data has already moved.

If the company is going through bankruptcy or a distressed sale, user data can be sold off as part of the liquidation. This has happened with defunct retailers and apps before: a customer database is treated as a company asset like inventory or office furniture, and it gets sold to whoever bids on it, sometimes explicitly against what the original privacy policy promised. You generally can’t stop this once it’s in motion, which is exactly why getting your own copy out early, and closing the account if you don’t want to be part of that dataset, matters more than any after the fact objection would.

None of these paths guarantee your data is gone forever, and none of them guarantee it’s compromised either. The point is that you don’t control the timeline once the shutdown starts, so the only window you fully control is the one before it does.

Use the export tool, then check what it actually gave you

Most services with any scale have a self serve export function, often called something like “download my data” or “request archive.” Mechanically, this usually triggers a background job that queries your records across their internal databases and bundles them into a file, commonly JSON or CSV, sometimes a zip with media files included. Because it’s a batch job, it can take anywhere from minutes to a couple of days depending on how much data you have and how backed up their export queue is. Request it as soon as you see the shutdown notice, not the week the servers go dark.

Once you have the file, actually open it before you assume it’s complete. Exports are built from whatever the engineering team decided was “your data” for the purposes of that feature, and that decision is often narrower than what the company actually holds on you. A messaging app’s export might include your sent messages but not the metadata about who you talked to and when. A shopping site’s export might include order history but not the browsing and click data used for ad targeting. If something you care about is missing (a specific conversation thread, an old profile version, transaction details), that’s worth flagging to support directly while the company still has staff to answer, rather than assuming it’s simply not there.

Encrypted data and why the company can still hand it over

Some services advertise end to end encryption for certain data (a lot of messaging apps, some password managers, some backup tools). If that’s genuinely how the system is built, meaning the company’s servers only ever see ciphertext and don’t hold the decryption key, then a shutdown export from their side literally cannot include your plaintext content, because they never had it either. In that case, your own local copy or your own client side export is often the only place that data exists in readable form, which makes it more urgent to pull from the device or app itself before you lose access, not less.

But a lot of “your data is encrypted” language refers to encryption at rest on their servers, where the company holds the keys. That protects your data from someone who steals a hard drive, not from the company itself. For that kind of data, the export the company gives you is the same data they can read internally, and a shutdown doesn’t change what they were able to see all along.

When there’s no export button

Smaller services, side projects, and apps built by a team that didn’t expect to need this often skip a self serve export entirely. If that’s what you’re dealing with, email support directly and ask for your data in a portable format before the shutdown date. Many services operating in the EU are subject to data portability requirements like those in the GDPR, which generally call for providing personal data in a structured, commonly used, machine readable format on request. Similar rules exist in some US states, like the CCPA in California. These are general legal frameworks, not a guarantee of what applies to your specific situation or how a given company will respond, so if the stakes are high (financial records, health data, anything you’d need for a dispute later), it’s worth getting actual legal advice rather than treating this article as it.

Practically, asking early works better than asking late. A company in its last week of operation often has a skeleton crew, and support tickets that used to get same day replies can sit for a week. If you wait until the deadline to ask, you may be asking a mailbox nobody’s checking anymore.

Verify before you delete anything

Once you have an export you’re satisfied with, resist the urge to immediately close the account. Open the files. Check that photos actually opened and weren’t corrupted in transit. Check that a CSV of transactions has the row count you’d expect. If you’re moving to a replacement service, do a test import if one’s available, since export formats and import parsers don’t always agree with each other even when they’re both trying to follow a standard.

Only after that verification step does it make sense to close out the account, if closing is even an option before the whole platform shuts off. Closing early removes your data from the live systems while the company is still around to actually action a deletion request, rather than leaving it to whatever the shutdown wind down process does with abandoned accounts.

What to watch for after the fact

A closing company is, for a little while, a less carefully watched company. Security teams get laid off before the servers do. This doesn’t mean a breach is coming, but it’s a reasonable moment to be a bit more alert: keep an eye on accounts that shared a password with the shut down service (and change it if you haven’t already stopped reusing passwords), and treat any post shutdown email claiming to be from the company, especially one asking you to “log in to retrieve your data,” with real suspicion. Legitimate export flows happen through the app or website you already know, not through a surprise email link.

Getting your data out of a closing service is mostly a logistics problem: request early, read what you got, verify it works, then decide what to do with the account. There’s no single step that makes this bulletproof, but doing it in order, and doing it before the deadline instead of on it, is what actually determines whether you walk away with your data or without it.

If you want more explainers like this on how your data actually moves through the services you use, you can find the rest of them on The Privacy Wire.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →