Mark Zuckerberg has a new privacy promise, but it’s Mark Zuckerberg, so he is almost certainly lying, or at least guilty of telling the truth too precisely.
According to Meta’s Human Boy, the firm’s AI products will now offer something called “Incognito Chat,” a mode supposedly private enough that “no one can read your conversations, even Meta or WhatsApp.” For most companies, this would qualify as a product update. From Meta, it arrives more like an invitation to revisit old trauma.
The announcement was posted earlier today on Threads with the buoyant confidence of a man who would never doubt his own reflection if he actually had one. He claims Meta AI will process conversations inside a Trusted Execution Environment and that those chats are inaccessible even to Meta itself. Conversations disappear from the device when the session ends. The implication is clear: speak freely, citizen. The machine has promised not to gossip.
And perhaps, technically speaking, it has.
But one learns, with Meta, to read the sentence twice. Preferably with a lawyer nearby, and to hold close the company’s long history of lying about everything all the time.
The crucial phrase is not “private.” Technology companies use “private” the way estate agents use “cosy.” The crucial phrase is: “no log of your conversations stored on servers.” That is impressively precise, and and precision, in Silicon Valley, is usually where the bodies are buried.
Because a “conversation” is not necessarily the same thing as the surrounding behavioural exhaust that global digital giants like Meta have mined for two decades while they built the most extraordinary global surveillance system in history.
Human Boy’s statement does not explain what metadata is retained, what telemetry survives, what abuse signals are preserved, what aggregate patterns remain visible, or whether Meta can still infer useful things from the mere fact that a user arrived anxious, lonely, horny, indebted, politically curious, or awake at 2am asking an AI whether their boss secretly hates them.
Which is to say: the company may not be reading your diary but it is still studying your fingerprints on the cover.
This distinction matters because WhatsApp has always existed in the peculiar territory where content and context perform an elegant little dance around privacy law. End-to-end encryption protects messages themselves, certainly. But the modern surveillance economy has never depended solely on reading your love letters. It thrives perfectly well knowing who sent them, when, how often, from where, on what device, after searching for divorce lawyers and before ordering melatonin gummies.
Zuckerberg also compares this new system to end-to-end encryption, which is excellent marketing and somewhat less excellent philosophy. Encryption works because the provider cannot read the message without the key. AI systems, by contrast, must process prompts in readable form somewhere in order to respond. Meta says that processing happens inside secure infrastructure – a Trusted Execution Environment – which may indeed be a robust technical safeguard.
But architecture is not absolution.
A Trusted Execution Environment sounds less like a piece of computing than something a bishop might wave incense around. One expects candles. Perhaps a small choir.
But the questions are not theological. They are drearily practical, which is always where the trouble begins.
Who owns the box? Who changes the code when no one is looking? What little notes are still being kept outside the holy chamber? And what happens when regulators, litigators, internal safety teams, or some future quarterly earnings panic develop an intense and inconvenient curiosity about what users have been whispering into these allegedly sealed confessionals of silicon and sin?
Technology companies are forever building cathedrals to privacy just prior to discovering a pressing commercial need for a side door.
Zuckerberg’s post answers none of these concerns. It simply gestures toward privacy with the serene confidence of a maître d’ assuring diners the kitchen is spotless moments before the health inspector arrives.
Then there is the disappearing-chat claim, that beloved modern lullaby. Conversations vanish from the phone once the session ends, Meta says. Lovely, so does smoke. The issue is whether traces survive elsewhere in the system – in analytics pipelines, safety review mechanisms, telemetry streams, abuse detection tools, or the vast and mysterious bureaucratic underworld where “temporary” data goes to become permanent after a compliance meeting.
Consumers have encountered this genre before. “Incognito,” “private,” “ephemeral,” and “disappearing” are among the most abused words in technology, ranking just below “community” and just above “reimagining.” In product language, they often mean something technically narrow while sounding emotionally sweeping.
And that emotional sweep is the point.
Because AI assistants are not ordinary software products. They are engines of confession. People do not merely ask them for weather updates. They ask about illness, debt, loneliness, infidelity, medication, sex, work panic, political fears, pregnancy scares, and whether it is normal to feel dead inside during quarterly planning meetings.
A search engine reveals curiosity but an AI assistant reveals vulnerability. That makes Zuckerberg’s framing especially delicate. He argues that privacy is essential for what he calls “personal superintelligence,” a phrase that sounds faintly as though a management consultant attempted to write science fiction after three espressos. But the underlying commercial question is serious: is Meta truly sealing itself off from one of the richest behavioural datasets in human history, or merely promising not to store the narrowest category of raw chat text while everything adjacent remains commercially illuminating?
Those are very different things.
None of this proves deception. The fairer criticism is subtler, and therefore more dangerous. Meta has become extraordinarily skilled at defining privacy in ways that are technically defensible, rhetorically expansive, and commercially survivable. The company speaks fluent reassurance with such confidence that one almost admires the craftsmanship in the same way a rat might admire a hungry rattlesnake
To be fair, the thing may even be good. There is always that danger.
It may keep secrets better than its rivals. It may tuck the chats away in some shining little vault where even Meta cannot put its nose against the glass. The auditors may arrive, grave and fragrant with independence, and pronounce the whole contraption virtuous. Miracles do occur, usually in footnotes.
But trust in technology is not made of adjectives. It is made of disclosures, of particulars, of saying the ugly parts first, before reporters find them and regulators arrive with subpoenas and comfortable shoes.
Meta has long treated transparency as something regrettable, postponable, and best attempted only after the screaming starts.
So when Zuckerberg says “no one can read your conversations,” the sensible response is the one that you ask a magician: Yes, lovely trick. Now show us the other hand.

Leave a Reply