Any chance of a post-mortem write up on how exactly things went wrong? Including some discussion on how data's going to be protected moving forward? Now that everyone knows this is a type of privacy violation that could occur, it's going to stay back of mind (a "why should we trust you with this sort of data now?" sort of deal). Potentially losing a job or having career plans stunted because a website added a new feature is a lot of power to trust a website with.
We're working on a post-mortem internally right now. The thing I want to do externally is make a more clear/binding commitment to user privacy. The idea is still a bit inchoate, but I want to do something that makes this not just about trusting us.
“I want to do something that makes this not just about trusting us.”.
Is that because deep down inside you know the public would be foolish to trust your company in its current form?