Inside the Metamorphosis: The Collapse of Social Media Privacy and Security

0
Image by Dima Solomin under the Unsplash license.

On a Reddit forum dedicated to privacy, a user recently recounted an experience in which they and their girlfriend got into an argument over Instagram direct messages (DMs), causing accusations of infidelity to fly about. That same user reported that when they opened Instagram Reels minutes later, their feed had shifted from cars and technology to a barrage of  “‘she’s cheating on you’ type videos.”

Others affirmed the experience. Responding to the initial Reddit post, one user wrote, “You’re on Instagram. There’s no priva[cy].” Another added, “Dude it’s Meta, did you really think they weren’t going to do this?” 

Despite such reports, Meta does not list the content of private messages as a signal–like watch time, shares, and comments–that informs its algorithms for your feed. Feed recommendations determine the posts and videos that appear on your Facebook or Instagram page Additionally, as Meta has expanded the incorporation of AI across its platforms, it’s stated that it does not use the content of private messages to train AI unless somebody directly shares their messages with AI. Yet, Meta is in the midst of a historic rollback of privacy and security features, putting the platform’s safety and credibility at risk. Users have every reason to be concerned. 

Your Feed: What Meta is Changing 

As of May 8, 2026, when it ended its end-to-end encryption program that allowed users to opt-in to another layer of privacy, Meta can read anyone’s Instagram DMs. End-to-end encryption is a security system that locks data into a secret code, ensuring that only the sender and the receiver can read it. In an interview with the HPR, Kyle Crichton, a research fellow at the Center for Security and Emerging Technology, said end-to-end encryption “provided the gold standard for privacy.” 

The HPR asked Meta spokesperson Emil Vazquez what led to the decision to discontinue the feature. He stated that “very few people were opting in to end-to-end encrypted messaging in DMs, so we’re removing this option from Instagram in the coming months.”

However, it may be Meta’s own fault that the feature was underutilized. As an opt-in feature, users had to go out of their way to search for end-to-end encryption before it could be enabled. Evidently, Meta is applying circular reasoning to justify their removal of the feature: Although they claimed not enough people were using it, the low usage stemmed from the fact that Meta didn’t publicize the existence of the feature in the first place. 

End-to-end encryption is not the only significant privacy feature that Meta has recently struck through. In July, Meta shelved off-platform disconnect, an opt-in feature that allowed users to sever the link between their Meta profile and their off-site browsing and purchasing history. Now, any activity on platforms that sell or otherwise transmit data to Meta can and will likely do so with your personal information attached. 

Meta has also changed the ways in which off-site data will be used on their platforms. Previously, off-site data was only used to inform ad targeting. Feed recommendations — the posts and videos that appear on your Facebook or Instagram page will now also be informed  by off-site data. Practically, whatever Meta users search for on the internet — including shopping for certain products, researching a political ideology, or investigating a personal health issue — will now be reflected in the videos and posts they see on Meta platforms. 

Meta’s abandonment of privacy and security also stretches beyond its social media platforms. Meta’s AI-powered glasses, which can covertly take photos and videos of anything in their vicinity, have recently been the subject of extensive controversy. Meta is currently facing a class action lawsuit over allegations that company employees can review footage collected on Meta AI glasses, including scenes of nudity, sex, or bathroom use. With this, consumers are beginning to acknowledge that Meta has breached a threshold when it comes to user privacy. As one man speaking with the Guardian put it, “I’ve been onboard with technological advancement all my life, but with … Meta glasses, I’m drawing the line.”

Advertisement

The Erosion of Privacy in the Name of Safety 

For all the privacy risks that come with Meta’s recent policy changes, there may be genuine, safety-oriented reasons to support some of them. Child safety advocates have long warned that end-to-end encryption can worsen the plight of abuse victims because the feature obscures the government’s access to dangerous messages. Crichton noted that thanks to the end of end-to-end encryption, “Meta now has access to view that data if they want it, and by extension … law enforcement also now has access to any of those messages.” 

Meta has long faced difficulties with harassment and abuse on its platforms. Survey data suggests that teenagers face higher rates of harassment on Facebook and Instagram than on any other platform, with 61% and 38% of all teens who have experienced online harassment in 2024 reporting harassment on each respective platform. Additionally, Meta faced legal filings alleging that in 2021, the company estimated that as many as 100,000 children face sexual harassment on Meta platforms every single day. 

Accordingly, some celebrated when Instagram eliminated the feature, believing that facilitating law enforcement access to social media DMs would protect teenagers and children from harassment. This process isn’t instantaneous though; Meta lays out extensive legal burdens that law enforcement must meet in order to obtain private information. Additionally, mounting privacy risks and a lack of conclusive data linking weaker encryption to lower exploitation or harassment rates have led others to warn that Meta is simply using the facade of child safety to veil further encroachments on consumer privacy.

Jessica Ji, a senior research analyst at Georgetown’s Center for Security and Emerging Technology, told the HPR that there are reasons to be sympathetic to both sides of the debate regarding privacy rollbacks in the name of safety. On the one hand, she says, “people use Instagram DMs out of fear of surveillance,” suggesting that end-to-end encryption could be important for those whose safety could be jeopardized by law enforcement or others gaining access to their communications. Conversely, Ji noted that unencrypting Instagram messages could be vital for presenting evidence in harassment or predation cases. 

Additionally, new child safety measures have given Meta license to collect sensitive identification information. In moves designed to keep underage users off Meta platforms, Meta has implemented age verification processes where users upload documents like birth certificates or scan their facial features to be analyzed by AI. With a massive repository of individuals’ information, including physical appearance, name, address, and date of birth, such databases could become targets for cybercriminals and vulnerable to scams, phishing, and identity theft. Meta claims to delete these IDs within 30 days, but maintains that in certain cases they may hold them for up to a year, such as if they suspect “fraud or abuse.” The ambiguity of what could qualify as potential “fraud” or “abuse” increases the risk of malpractice. 

Archive: It Was Not Always This Way 

While users in 2026 question Meta’s consumer privacy protections, the company once built its identity around privacy. At its founding in 2004, Facebook was remarkably private: Only those with valid college credentials could join “The Facebook,” and the company did not collect any off-platform data. That created a sense that outsiders with perverse incentives would never even make it onto the platform. 

As soon as Facebook became publicly accessible in 2006, privacy took a slide. By 2007, Facebook had begun off-platform data collection with a program called Facebook Beacon. This erosion of privacy on Facebook escalated in 2010 when CEO Mark Zuckerberg argued that, as people become more comfortable sharing a wide range of information in public forums, privacy is no longer a social norm.  At the time, many Facebook privacy protections were being suppressed, with Facebook making key identifying information such as name, profile photo, and bio available to all users — a practice that continues on Meta platforms to this day. 

That privacy-agnostic cultural shift at Facebook circa 2010 inaugurated a decade of scandal. In 2011, the company settled with the Federal Trade Commission over allegations that it had not honored promises to keep user data private by sharing personal data with advertisers and third parties. In 2018, it was revealed that Facebook had known about the massive theft of user data on its platforms and had done nothing about it. Eventually, the discontent with the string of scandals bubbled over, with growing online discourse about Meta’s missteps. 

Thus, in a 2019 move that harkened back to the early days of Facebook, Zuckerberg changed tune. In a nine-page Facebook post, he announced that Facebook was going to prioritize serving as a “privacy focused messaging and social networking platform.” Zuckerberg committed to developing a platform built around secure, encrypted, and safe interactions by taking steps like reducing the time for which messages and posts are visible and increasing collaboration with privacy experts. 

Since 2025, though, when Meta changed its privacy policy to allow more user data feed into Meta AI and drive targeted advertising, new privacy concerns just keep surfacing. 

Why Now? 

Meta’s path towards and away from privacy has been a circuitous one, raising the question of why, in this particular moment, Meta is looping back to its 2010 posture where privacy was an afterthought. 

In large part, it seems that shift can be traced back to the technological development that has been dominating the zeitgeist recently: AI. Since its inception, Meta has been a consumer-oriented company; however, it is entering a new era that prioritizes building AI tools for other businesses. Meta is even in talks to rent out its AI infrastructure to industry giant Anthropic.  

Like all other major AI builders, however, Meta faces the growing challenge of determining how to advance its models as it depletes reservoirs of publicly available training data. “These companies have already scraped the internet essentially multiple times,” said Crichton, referring to the fact that AI companies are running out of training data for their models. Although Meta said that it does not use messaging data to train AI, Crichton suggested that “these [privacy] rollbacks tie into this broader picture of … where do companies that are developing AI technologies turn for data sources.” 

While it may not be using information from DMs, Meta’s built-in AI chatbot Meta AI now permission to use off-platform data to inform its responses to users. According to Crichton, this is the most worrying source for off-platform data because “it might contribute more to the echo chamber effect and give you similar recommendations” based on off-site activities. Many AI models are highly sycophantic and notorious for tailoring the information they give directly to their specific user. Thus, personalized chats with Meta AI could more dramatically reinforce users’ beliefs than prior social media features, contributing to online echo chamber effects that cultivate extremism and vitriol. Allowing off-site, in addition to social media activity, to inform what these chatbots say only expands the scope of beliefs and biases they could reinforce. 

In all of its AI-centric efforts, Meta has vital backing from the federal government under President Donald Trump. His administration has been staunchly in favor of minimizing regulatory burdens in the interest of AI development, with Trump signing an executive order in December 2025 promoting minimal national regulations of the technology rather than state by state ones. The administration’s push to limit states from regulating AI development, in an effort to catalyze innovation, has created an environment conducive to swift, drastic, and often dangerous swings to privacy and security policy. This process has been somewhat slowed down in recent months, however, with Trump signing  an executive order in June that required companies to give the government early access to new AI models before releasing them to the public.

Meta has been known to change policy paradigms to curry favor with whomever sits in the White House. For example, Meta replaced professional fact checkers with crowdsourced community notes in advance of Trump’s second term in a move that many thought was designed to appease a president known for encountering issues with social media fact-checking. Its current abandonment of privacy protections in the interest of accelerating AI development may be yet another example of the company pandering to the president.

Indeed, recent optics point towards a political shift at Meta. Zuckerberg, who advocated in 2015 for punishing Trump for offensive posts on his platforms, has recently cultivated a relationship with the president. Since the 2024 election, Zuckerberg has met with Trump at Mar-a-Lago and greenlit the company’s $1 million donation to Trump’s inauguration fund. 

Jonathan Bellack of Harvard’s Berkman Klein Center for Internet told the HPR that Meta’s motives may lie beyond the purely political. In Bellack’s perception, the company “is not deeply concerned with anything that a political scientist or political philosopher would recognize at this time,” specifying that “they are motivated by resisting government regulations that would constrain their freedom of action.” Instead, Bellack thinks “they’re concerned about protecting profits.” 

Scrolling Forward: What Comes Next 

Given its backing from the current administration and the acceleration of the AI race, there is nothing to suggest that Meta will divert from its antiprivacy course anytime soon. 

Some consumers, however, are beginning to defect from Facebook and Instagram. With the end of off-platform disconnect, however, Crichton implored consumers to use caution in all parts of their online lives and argued that tools like privacy protecting web browsers are becoming “more important as this data is cross-pollinating.” 

Now, more than ever, users must relentlessly protect their own privacy — through discretion about what they post and seeking out privacy protecting tools — while being attentive and reactive to Meta policy changes. With Meta currently posting record profits, it shows little signs of slowing down in its push to embrace a new, liberalized, AI-powered era. As it stands, it seems the Metamorphosis is only beginning.

Advertisement