Meta’s Download your information
I led design of a unified download flow for Facebook and Instagram that met every regulatory requirement while people consistently rated it easy to use.
My Role:
Design lead and user research
I owned:
End-to-end flow, data structure, and research
Timeline:
5 months
Collaboration:
Content design, product, engineering, legal, policy
Platform:
iOS, Android, Mobile web and desktop
TL:DR
Problem: Facebook and Instagram had separate, inconsistent download tools, and the experience had to meet strict privacy regulations.
What I did: Led design of one flow to download data across every linked profile, built on a data structure every app team adopted.
Result: Full regulatory compliance, a double-digit lift in task completion, and three surfaces consolidated into one.
One unified flow to download your data from every linked Meta profile, from request to file options.
The problem
As Meta moved to a connected app model, people needed one place to download data from all their linked Meta products. Privacy laws like GDPR and CCPA require that access, and some settings were legally required to be centralized.
But the two existing tools pulled in opposite directions. Facebook let people pick individual data types, which regulators demanded. Instagram offered one click, because it had faced less regulatory pressure.
Goal
Give people one place to download all their Meta data, with real transparency and control, while meeting privacy regulations in every market.
Who it's for
People download their data for very different reasons, and many have more than one profile across Facebook, Instagram, and WhatsApp:
Curious: wants to see what Facebook and Instagram have stored about them
Leaving: wants to deactivate Facebook but keep their memories
Locked out: had a profile disabled and wants their data in case it isn't restored
Principles
Quick - Request and retrieve data in minimal steps, without understanding back-end complexity.
Unified - The same structure and terms across every profile, so nothing needs relearning.
Separate - Never imply that data from different profiles is mixing.
Compliant - Always offer the full breadth of data, with the choice of what to download.
Key decisions
Decision 01
Co-locate, don't consolidate
Options: merge every profile's data into one unit, or give profiles one shared entry point while each profile's data stays separate.
Decision: I made the case for co-location. It met the project's needs without a company-wide back-end rewrite or a change to data policy, and research showed people think about their data profile by profile.
Decision 02
One data structure for every app
The problem: an audit showed some apps nested data types under categories, while others simply listed them.
What I did: I led card sorting and testing to find a structure that worked with every app's existing data, scaled, and made sense to people.
The outcome: app teams across the company adopted it, so people never relearn where things live as they move between apps.
Decision 03
Smart defaults, full control
Regulators required access to all data, but most people only wanted their photos and posts. I designed three clear paths:
Your media, selected by default, since research showed it matched what people expected
All information, for everything at once
Select types of information, for granular control per profile
Because choices change the flow's length, I used a line indicator instead of step counts, which people found lighter.
Decision 04
Design for the wait
Files can take a few minutes to a few days to prepare, about an hour on average. That was a technical constraint we couldn't remove, so the flow sets expectations up front and notifies people the moment their file is ready.
The final experience
Request, choose profiles, choose information, set file options. A short line indicator replaces step counts, since the flow length changes with each choice.
Each profile stays separate, so people choose exactly whose data goes into their file.
Outcome
Full
regulatory compliance, with minimal impact on core metrics
Double-digit
lift in task completion, the core metric for regulators
3 → 1
surfaces to maintain, cutting engineering overhead
Major reduction in friction
for people with multiple accounts
Company-wide adoption
of the data structure
High user satisfaction
in post-launch surveys
Reflection
What we missed after launch
The signal: some people requested a download but never came back for it.
The cause: people on shared devices or in internet cafes, especially in emerging markets, often couldn't download or store a file at all. We'd designed around the assumption of a personal device.
What I did: I pushed to integrate an existing transfer tool owned by another org, so people could send their data straight to services like Google Drive. The work was adopted, and the two products later merged.
Result: completion rose significantly.
Treat limited-access conditions as a starting constraint, not an edge case.