In 2013, Facebook bought a small Israeli VPN company called Onavo. Onavo’s pitch was simple: encrypt your traffic, protect your data, save bandwidth. It was, on paper, a privacy first app. Facebook used it to watch which apps were gaining traction on other people’s phones, including a messaging app called WhatsApp, which it then acquired for $19 billion. Onavo shut down in 2019 after Apple booted it from the App Store for violating data collection rules. The privacy tool became a competitive intelligence tool, and nobody who installed it in 2014 signed up for that outcome.

That’s the part of the “privacy first apps” conversation that doesn’t get enough attention. Everyone talks about which apps are private today. Almost nobody talks about what happens to a privacy first app once it needs a Series B, an exit, or just a way to pay its engineers next quarter.

the acquisition problem

A privacy first app that succeeds has a structural problem: privacy is expensive to maintain and hard to monetize directly. Most apps make money through ads, data licensing, or acquisition. Two of those three are incompatible with the pitch that got users in the door.

So the pattern repeats. A small team builds something genuinely private, often because they’re annoyed at the alternatives. It gets traction. A larger company notices the user base, not the architecture, and buys it. The acquiring company rarely dismantles the privacy features overnight because that would trigger backlash. Instead the policy changes arrive in increments: a new “service improvement” clause in an update eighteen months later, a data sharing partnership announced in a press release nobody reads, a rebrand that quietly drops the encryption claim from the app description.

WhatsApp is the textbook version. End to end encryption shipped in 2016, the same year Facebook started linking WhatsApp account data to Facebook profiles for ad targeting. Both things were true simultaneously. Users who chose WhatsApp specifically for the encryption were still folded into Facebook’s ad graph through metadata the encryption never touched.

what privacy first actually costs to build

Building genuine privacy into an app isn’t a checkbox, it’s an ongoing cost center. No third party analytics SDKs means building your own crash reporting and usage metrics from scratch, which most five-person teams can’t afford to prioritize. No ad network means no revenue from the single largest, most liquid monetization channel in mobile. Local-only data storage means no cloud backup convenience, which increases support tickets when people lose their phones. Every privacy first decision is also a cost decision, and costs eventually meet a balance sheet.

This is why so many privacy first apps either stay tiny (a few hundred thousand users, run by a team of three, funded by donations) or get bought and quietly repositioned. There isn’t a large stable middle where a privacy first app scales to tens of millions of users while keeping the original business model intact. Signal is the closest counterexample, and it only works because it’s a nonprofit funded by a one-time $50 million loan from WhatsApp’s own co-founder, structured specifically to avoid the acquisition or ad-pivot trap. That’s not a repeatable business model. That’s a very specific, very rare act of philanthropy.

the nonprofit exception, and why it’s an exception

Nonprofits and foundations solve the monetization problem by removing the requirement to monetize at all. Signal, the Tor Project, and a handful of smaller tools (Delta Chat, some F-Droid projects) run this way. But nonprofit status isn’t automatically a privacy guarantee either. It just removes one specific pressure: the pressure to sell user data or accept acquisition to satisfy investors. It doesn’t guarantee good security engineering, doesn’t guarantee the org won’t fold when funding dries up, and doesn’t guarantee the same team stays in charge five years from now.

signals that separate marketing from architecture

When you’re deciding whether a “privacy first” label on an Android app means anything, a few things are worth checking before you trust it:

Who owns the company, and has ownership changed in the last three years. A privacy app that was acquired by a larger ad-tech or data company in the last 24 months deserves a second look at its current privacy policy, not its launch-day marketing.

Where the revenue comes from. If an app has no ads, no subscription, no enterprise tier, and no visible funding source, ask how it pays its server bills. “Free forever” with no business model is usually a business model you haven’t found yet.

Whether the claims are backed by something checkable: open source code, a published audit, a bug bounty program. A marketing page that says “we don’t track you” is a sentence. A public GitHub repo that proves it is evidence.

Whether the privacy policy has changed recently, and what changed. Most app listings show version history for the app itself but not for the policy. Sites like ToS;DR track policy diffs for popular apps and are worth checking before you commit.

the actual takeaway

“Privacy first” is a snapshot of a company’s incentives at one point in time, not a permanent property of the app. The incentives that make an app private today (small team, no ad revenue, mission-driven founders) are frequently the same incentives that make it a takeover target tomorrow. Trusting an app because of what it was two years ago is how millions of WhatsApp and Onavo users ended up somewhere they didn’t sign up for. Check who owns it, check how it survives financially, and recheck both every year or so. The label doesn’t age well on its own.