On March 24, 2026, OpenAI posted a short goodbye to Sora on X. The web and app versions went dark on April 26, and the underlying API is scheduled to close on September 24, 2026. Users could download their videos before a final deadline, after which the content was deleted. Sora came from one of the best-funded companies in the field, and it still vanished in roughly six months. If a tool with that backing can disappear that fast, the smaller AI apps most people build their days around are far more fragile.
That fragility is the real subject here. When an AI company folds, the question is not only whether the app stops working. It is what happens to the years of chats, files, prompts and training inputs you handed over, and who owns them once the company that promised to protect them no longer exists.
Key takeaways
● Your data rarely gets deleted at shutdown. It is usually sold to a buyer, handed to a bankruptcy trustee, left with a third-party processor, or abandoned on servers nobody maintains.
● An export button is not the same as ownership. Many AI products offer no export, a short read-only window, or a stripped file you cannot reload anywhere else.
● Anything absorbed into a model's weights or a fine-tune cannot be cleanly pulled back out, which makes the promise that your data is portable weaker than it sounds.
● Sensitive data carries the highest stakes. The 23andMe bankruptcy put the DNA of about 15 million people up for sale before a nonprofit bought the company back.
The short answer: your data does not disappear, it changes hands
When an AI startup shuts down, your data almost never gets wiped on the way out. Instead it takes one of four paths: a buyer absorbs it, a bankruptcy trustee takes control of it, a third-party processor keeps a copy, or it sits abandoned on servers nobody is paying to secure. Which path applies decides who is responsible for your information now and how much say you still have over it.

The four places your data goes when an AI company shuts down
The table below is the fast version. Each row is unpacked underneath.
| Destination | How likely | Who is responsible now | What it means for you |
|---|---|---|---|
| Acquired by a buyer | Common for tools with real users | The acquiring company | It inherits the old privacy policy, but can change purpose or retire your feature |
| Held by a bankruptcy trustee | Common in formal insolvency | A court-appointed trustee | Your data is an asset the trustee may sell to repay creditors |
| Kept by a data processor | Very common, often overlooked | Cloud host, payment or analytics vendor | Copies can linger after the main company is gone |
| Abandoned on servers | Frequent with small, informal closures | Effectively no one | High breach risk; data sits exposed and unmonitored |
Acquired by another company
This is the common outcome for any startup with users worth having. Customer data is often the most valuable thing on the balance sheet, so a buyer usually takes it as part of the deal. The acquirer inherits the original privacy obligations and is generally expected to honor the old policy or tell you what is changing. The AI-specific catch is subtle: even when the company keeps running inside a larger owner, the feature you depended on may be retired. A buyer purchases the technology and the customer base, not a promise to preserve your workflow.
Held by a bankruptcy trustee
In a formal Chapter 11 or Chapter 7 case, a trustee or administrator takes control of company assets, data included. The trustee's duty is to maximize recovery for creditors, which can mean selling the database to the highest bidder. This is not a loophole. It is the core mechanism of a bankruptcy sale under Section 363 of the Bankruptcy Code, and courts generally allow it, even for the most sensitive information a company holds.
Retained by a data processor
The company you signed up with rarely stored your data alone. Cloud hosts, payment processors, analytics platforms and email providers often hold copies as processors acting on the company's behalf. When the company dies, those processors are supposed to delete what they hold once the controller no longer exists, but enforcement is uneven and copies quietly linger.
Abandoned on unmaintained servers
The worst case is neglect. Nobody manages the data, the hosting bill goes unpaid, the domain lapses, and the records sit exposed until someone stumbles on them. Defunct companies are prime breach targets because no security team is patching servers or watching for intruders. For AI tools the exposure is larger than usual, since an abandoned storage bucket can hold raw training data and vector stores packed with everything users ever typed.
What is different about AI data (the part vendors do not tell you)
Generic shutdown advice treats your data as a static folder of records. AI data behaves differently in four ways, and each one changes what you can realistically get back.
Your chats and stored memory
For most AI assistants and companions, your history lives on the vendor's servers under the vendor's terms. A shutdown, a pricing change or a regulator can erase it. This stopped being abstract in mid-2026, when several of China's largest AI apps removed user-built companion features or closed them outright, and reporting said many users had little or no way to take their conversation histories with them. Independent coverage confirmed that Chinese regulators pushed the country's biggest platforms to retire humanlike chatbot personas around the same time.

An export button is not ownership
“Your data is exportable” can mean four very different things:
- No export at all: you can read your history inside the app but cannot download it.
- A short read-only window: temporary access to view or save before a hard deletion date.
- A lossy dump: a file that strips out the structure and remembered context that made the tool useful.
- No portability: even a clean export usually cannot be loaded into a competing product.
Sora is the rare good example. OpenAI gave users a genuine path to export their videos and images before the cutoff. Plenty of smaller apps offer nothing close, and users discover the limits only once the deletion date is days away.
Data baked into model weights cannot be clawed back
Once your text, code or images are used to train or fine-tune a model, they stop being a file you can request back. They become part of the statistical weights, blended with millions of other examples. You cannot extract your contribution cleanly, and neither can the company. So when a vendor calls your data portable, read that as covering the copy sitting in the database, not the copy already dissolved into a trained model.
Your data as a liquidation asset
Here is the twist almost no shutdown guide mentions. Your data can be sold as training fuel for other AI systems. When the transcription company cielo24 wound down, its chief executive discovered, while working with a startup that helps companies close, that thirteen years of internal communications were worth hundreds of thousands of dollars to AI labs, according to reporting on the closure. Real operational data, full of jargon and natural back-and-forth, is exactly what model builders will pay for. A startup that fails can still turn its archive of your activity into one of the last assets it sells.
The next table maps the main types of AI data to what usually happens to each, whether you can get it back, and the one move that helps most.
| Your data | Typical fate on shutdown | Recoverable? | What to do |
|---|---|---|---|
| Chat history and memory | Deleted after a read-only window, or sold with the company | Sometimes | Export in full before the earlier deadline |
| Uploaded files | Returned via export, or abandoned on storage | Often | Download and confirm the files open elsewhere |
| Fine-tuning inputs | Sold as a dataset, or lost | Rarely as-is | Keep your own encrypted copy from the start |
| Embeddings and vector data | Abandoned or transferred with assets | No | Regenerate from your source data if needed |
| Prompts and outputs | Retained, or reused for training | Rarely | Avoid putting secrets in prompts |
| Genetic or biometric data | Sold or transferred as an asset | No | Request deletion early; involve a regulator |
The special case of genetic and biometric data
Everything above gets more serious when the data maps to your body. A leaked password can be changed. Your genome cannot. The clearest real example of what a shutdown can do to this kind of information is 23andMe.
The 23andMe story, start to finish
23andMe filed for Chapter 11 on March 23, 2025, putting the genetic data of about 15 million customers into play. The backdrop was bleak. A 2023 breach had exposed information tied to nearly 7 million people. The share price had collapsed from a 2021 peak above $300 to around $1, and the chief executive resigned as the case opened.
Regulators moved quickly. The chair of the Federal Trade Commission wrote to the trustee warning that any sale had to honor the privacy promises customers relied on, echoing the agency's 2015 intervention in the RadioShack bankruptcy. More than two dozen state attorneys general went further and sued to block a sale of genetic data without customer consent, arguing that a genome is not ordinary property like the office furniture normally sold in a bankruptcy. A court-appointed privacy ombudsman had to review the transaction before it could close.
The ending mattered. The pharmaceutical company Regeneron first won the auction at $256 million. After the pushback from states, the bidding reopened, and a nonprofit founded by co-founder Anne Wojcicki, the TTAM Research Institute, won with a $305 million bid. A judge approved that sale in late June 2025, and the DNA data stayed out of a third-party buyer's hands. The system worked, but only because the data was sensitive enough to draw regulators and a founder willing to pay to reclaim it. Most shutdowns get none of that attention.

Why de-identified data slips through the cracks
A quirk of privacy law shapes many of these deals. Once data is anonymized and aggregated so it no longer points to a single person, most privacy rules stop applying to it. That is how research datasets keep changing hands even after a company is sold. The label de-identified does heavy lifting here, and re-identification is not always as hard as buyers claim.
Are you an individual user or a business? Your playbook differs
The four destinations apply to everyone, but what you should do splits along one line. Individuals are protecting personal history and memory. Organizations are protecting a pipeline they may have built a product on. The next two sections give each group a concrete runbook. The decision flow below sums up the moves for anyone who has just received a shutdown notice.

If you are an individual user: how to protect and recover your data
Right now, before anything shuts down
● Export everything in the richest format offered, then confirm the file actually opens outside the app.
● Save the current privacy policy to an archive such as the Wayback Machine, since it often names who inherits data and what happens on closure.
● Change any password you reused elsewhere, because a defunct company's login database is a soft target for attackers.

The moment a sunset notice lands
Read the notice for two dates: when access ends and when deletion happens. They are often different, and the gap between them is your window. Watch for read-only periods that let you look but not download. Pull your data before the earlier of the two dates, not the later one. OpenAI's Sora guidance is a useful model for what a clear export process looks like (OpenAI's Sora discontinuation help page).
After the company is gone
Your rights outlive the company. Under GDPR and UK GDPR, any entity still controlling your data must answer an access request within 30 days, even after the business stops trading. To find who holds it now, start with that archived privacy policy, then check business registries such as Companies House or SEC EDGAR for a successor, search bankruptcy filings for asset transfers, and contact any processor named in the policy. Send the request to every address you can find, and follow up in writing. One email rarely works. Persistence, plus a reference to the regulatory consequences of ignoring you, usually does.
If you are a business or developer: continuity and contract safeguards
A shutdown that costs an individual their chat history can cost a company its analytics pipeline overnight. Three habits keep that from becoming a crisis.
Watch for the death-watch signals
● A funding gap: a seed round raised back in 2023 with no announced Series A means the runway is running out.
● A pivot to enterprise paired with the removal of free tiers, which quietly deprioritizes self-serve users like you.
● An acquisition, after which the new owner's roadmap sets the priorities, and it bought the technology rather than your use case.
● Quiet API deprecations dressed up as product improvements, which usually signal shrinking scope ahead of a wind-down.
Mirror your data and set export triggers
Keep fine-tuning inputs and other critical data in your own environment, encrypted but retrievable, so a vendor's collapse never takes your only copy. Maintain a tested second provider you can fail over to, even a cheaper backup model kept on standby. Write periodic export rights into the contract itself, so your data arrives on a schedule instead of during a panic when the shutdown email lands.
Consider AI or software escrow
Escrow places the source code, the build instructions, the data and the documentation with a neutral third party that releases them if the vendor fails. The Builder.ai collapse made the case vivid. A company once valued above $1 billion, backed by major investors and having raised roughly $445 million, entered insolvency in 2025 and stranded customers who had built on its platform. A verified escrow arrangement turns that kind of failure into a transition instead of a total loss.

Your legal rights across the US, EU and UK
The company may be gone, but the rights you have over your data are not. They attach to whoever holds the data now, be it a buyer or a bankruptcy trustee. Here is how the main rights line up across the largest regimes.
| Right | GDPR / UK GDPR | CCPA / CPRA | Escalate to |
|---|---|---|---|
| Access | Article 15 | Section 1798.100 | ICO (UK) or your EU DPA |
| Erasure / deletion | Article 17 | Section 1798.105 | State attorney general (US) |
| Portability | Article 20 | Section 1798.130 | Data protection authority |
| Object / opt out | Article 21 | Opt-out of sale/sharing | Regulator or class action |
Can a bankrupt company legally sell your data?
Usually yes, within limits. A Chapter 11 case lets a business sell assets or sell itself to satisfy debts, and customer data is fair game in that process. The brakes come from two directions: the company's own past privacy promises, and regulators willing to enforce them. The FTC has stepped into bankruptcies before to block data sales that would break the original privacy policy. Under GDPR, any sale must still comply with data-protection law and your right to object. The 23andMe case showed both brakes engaging at once, with the FTC watching and the states suing, which is exactly why that data did not end up with an unknown buyer.
How common is this? Reading the failure numbers honestly
You will see alarming figures thrown around, such as claims that 90% of AI startups fail in their first year, or that 40% of those founded in 2024 have already shut down. Treat them with caution. Analysts who track this closely point out that the most-repeated numbers circulate without any traceable methodology behind them. Rather than repeat an unverifiable figure, here is checkable product-level data from a registry that publishes how it counts.

One registry that tracks live AI tools recorded 22 retirements in 2023, 55 in 2024 and 106 in 2025, close to a doubling for two years running. Measured into 2026 the pace was still climbing, though more slowly than that.

Of the roughly 285 tools in that same catalogue that had exited by September 2026, most shut down outright rather than getting rescued. About 135 closed completely. Another 66 were acquired and then sunset, and 84 were bought but still run under their own name. A clean acquisition that preserves your tool is the exception, not the base case.
That is the real reason data survival deserves a plan before you need one. The AI tool you rely on today has better odds of closing than of being safely absorbed, and the day the shutdown notice arrives is the day your options start shrinking. The copy of your data that you control is the only copy a shutdown cannot touch.
The Bottom Line
The pattern across every case here is the same. When an AI company runs out of road, your data becomes an asset it can sell or a folder no one is left to watch, and the choice about its fate stops being yours the moment the company loses control of it. 23andMe was the rare story with a reassuring ending, and it took a founder with hundreds of millions of dollars and two dozen attorneys general to reach it. Most closures come with none of that attention.
So treat any AI tool you depend on as temporary, because the numbers say it probably is. Keep your own copy of anything you would miss. Read the privacy policy for what happens on wind-down before you upload anything sensitive. And know which of the four destinations your data would take if the service went dark tomorrow. Do that work while the tool is healthy, and a shutdown notice becomes an inconvenience rather than a loss.
The company's survival was never in your hands. The fate of your data can be.
Comments 0
Join the discussion and share your perspective.
Sign in to post a comment and reply to other readers.
No comments yet
Be the first to share your perspective on this article.