743 x:
- Addresses that are wrong
- Passwords stored (probably insecurely)
- Other personal data that can be stolen
If they "need it", they can be granted access to it (or a personally encrypted copy of it unique to them). Of course they can (and likely will) mis-manage even this data; Zero-Knowledge Proofs and Homomorphic Encryption should be used instead, where possible.
Remember, Public data written by an Agent are written to the DHT and are persistenly available, so "upload and decrypt" isn't really usually a thing in Holochain hApps.
So, if they want to make some non-repudiable claim under the auspices of "my account" (ie. claim agency on my behalf over some change of state, such as a "post" under my name, ...), then they can bloody well get me to sign such a state change with my private key. And, make all such data publicly available so that I (by my sole decision) can cease to use their service and take my data elsewhere.
Remember -- these are "randos on the internet" holding your data. Hundreds, or possibly even thousands of them including all the partners they sell your harvested data to, who are evidently incompetent in managing/securing it, and certainly don't care a whit about you and the sanctity of your data.