Or they could just store the data locally on the user’s device and not transmit it back to a central server, such that the company never even has possession of the data nor any way to retrieve it? Like I get it would require a major rewrite if they weren’t already doing this, but at least they’d be keeping their users safe while also having no way for authorities to gain any data.
Be careful with that, it could make you a target for a visit