Meta’s Download your information

I led design of a unified download flow for Facebook and Instagram that met every regulatory requirement while people consistently rated it easy to use.

My Role:

Design lead and user research

I owned:

End-to-end flow, data structure, and research

Timeline:

5 months

Collaboration:

Content design, product, engineering, legal, policy

Platform:

iOS, Android, Mobile web and desktop

TL:DR

  • Problem: Facebook and Instagram had separate, inconsistent download tools, and the experience had to meet strict privacy regulations.

  • What I did: Led design of one flow to download data across every linked profile, built on a data structure every app team adopted.

  • Result: Full regulatory compliance, a double-digit lift in task completion, and three surfaces consolidated into one.

One unified flow to download your data from every linked Meta profile, from request to file options.

The problem

As Meta moved to a connected app model, people needed one place to download data from all their linked Meta products. Privacy laws like GDPR and CCPA require that access, and some settings were legally required to be centralized.

But the two existing tools pulled in opposite directions. Facebook let people pick individual data types, which regulators demanded. Instagram offered one click, because it had faced less regulatory pressure.

Goal

Give people one place to download all their Meta data, with real transparency and control, while meeting privacy regulations in every market.

Who it's for

People download their data for very different reasons, and many have more than one profile across Facebook, Instagram, and WhatsApp:

  • Curious: wants to see what Facebook and Instagram have stored about them

  • Leaving: wants to deactivate Facebook but keep their memories

  • Locked out: had a profile disabled and wants their data in case it isn't restored

Principles

Quick - Request and retrieve data in minimal steps, without understanding back-end complexity.

Unified - The same structure and terms across every profile, so nothing needs relearning.

Separate - Never imply that data from different profiles is mixing.

Compliant - Always offer the full breadth of data, with the choice of what to download.

Key decisions

Decision 01

Co-locate, don't consolidate

Options: merge every profile's data into one unit, or give profiles one shared entry point while each profile's data stays separate.

Decision: I made the case for co-location. It met the project's needs without a company-wide back-end rewrite or a change to data policy, and research showed people think about their data profile by profile.

Decision 02

One data structure for every app

The problem: an audit showed some apps nested data types under categories, while others simply listed them.

What I did: I led card sorting and testing to find a structure that worked with every app's existing data, scaled, and made sense to people.

The outcome: app teams across the company adopted it, so people never relearn where things live as they move between apps.

Decision 03

Smart defaults, full control

Regulators required access to all data, but most people only wanted their photos and posts. I designed three clear paths:

  • Your media, selected by default, since research showed it matched what people expected

  • All information, for everything at once

  • Select types of information, for granular control per profile

Because choices change the flow's length, I used a line indicator instead of step counts, which people found lighter.

Decision 04

Design for the wait

Files can take a few minutes to a few days to prepare, about an hour on average. That was a technical constraint we couldn't remove, so the flow sets expectations up front and notifies people the moment their file is ready.

The final experience

Request, choose profiles, choose information, set file options. A short line indicator replaces step counts, since the flow length changes with each choice.

Each profile stays separate, so people choose exactly whose data goes into their file.

Outcome

Full

regulatory compliance, with minimal impact on core metrics

Double-digit

lift in task completion, the core metric for regulators

3 → 1

surfaces to maintain, cutting engineering overhead

Major reduction in friction

for people with multiple accounts

Company-wide adoption

of the data structure

High user satisfaction

in post-launch surveys

Reflection

What we missed after launch

The signal: some people requested a download but never came back for it.

The cause: people on shared devices or in internet cafes, especially in emerging markets, often couldn't download or store a file at all. We'd designed around the assumption of a personal device.

What I did: I pushed to integrate an existing transfer tool owned by another org, so people could send their data straight to services like Google Drive. The work was adopted, and the two products later merged.

Result: completion rose significantly.

Treat limited-access conditions as a starting constraint, not an edge case.