This is exactly why privacy by architecture matters more than privacy by policy. The Netherlands trusted a policy ("Solvinity can't access the data") but the architecture allowed it anyway. The only real solution is cryptographic sovereignty systems where even the vendor mathematically cannot access user data, regardless of what US law says. Not we promise we won't look but we literally cannot look. Building something small in this direction a mesh network where identity is a BIP-39 seed phrase and messages are E2E encrypted at the protocol level,not the application level. The goal is that even I as the developer cannot read user messages. It's still early, but this problem you're describing is exactly why it needs to exist.