Maybe they aren't that, but why should anybody without personal knowledge of the situation trust that they aren't? This is the sort of scenario where 'better safe than sorry' overrules giving the benifit of the doubt.
Verification and transparency are more important than trust.
I realize your question is most likely rhetorical, but I felt the need to articulate my concerns.
You can't be sure. In the Lavabit case, Lavabit argued giving up the key protecting all their users... compromising them to the FBI... would cost them customers due to damaged reputation and privacy. The FBI argued they could do it without telling them. Then, Lavabit would still look private with no financial harm. The judge agreed.
That proposal and the judge agreeing changed how I looked at a lot of companies' claims about law enforcement. I already assumed this would happen with Patriot Act requests by FBI/NSA partnership given they'd be hit with secrecy orders. I didn't see a judge straight up telling a privacy company to defraud all of its customers. I figured the order would be more narrow than that. Now, I have a blanket recommendation to avoid U.S. for privacy tech over both secret government (Patriot Act stuff) and regular, court system.
https://www.privateinternetaccess.com/blog/2019/11/bellum-om...
I didn't lose trust in PIA because of Kape, I lost it because your blog post was poorly written and inadequately communicated some very important news. You bury mentions of a merger in the 7th paragraph, wtf?
I can't trust PIA if you can't be trusted to clearly communicate such important information.
For context: Facebook told the EU Commission they wouldn't link Facebook and WhatsApp accounts. Then they did it anyway. Sure, they got fined for it, but it's hard to believe that the fine was not factored in from the beginning.
So if they break that part of the agreement with PIA, then what? Is the merger canceled?
> 3. Zero Data – sanctity of personal data – we believe each individual owns his own data therefore we will never store or attempt to sell what does not belong to us.
Which is vague in the extreme. It does not clarify what 'personal data' means. Is my internet activity when using PIA/Kape's network still my own? Or does Kape now make a claim on this data?
If there is really a 'never log' guarantee, why is this not prominently displayed in the discussion of the merger?