I'm extremely confused by Mixpanel announcement, according to their blog post if you received an email from them it implies you were affected, yet I closed my account with them few months ago and I still received their email, which I can't understand if my account was impacted or no

> As a valued customer, we wanted to inform you about a recent security incident that affected a limited number of Mixpanel user accounts. We have proactively communicated with all impacted customers. If we did not previously contact you, your Mixpanel accounts were not impacted. We continue to prioritize security as a core tenant of our company, products and services. We are committed to supporting our customers and communicating transparently about this incident.

Closing your account doesn't automatically mean they wiped all your data. If you got the email, your data was impacted.

If that is true, then the data impacted was likely account data, as we also got the email and yet we are only just starting the integration work, and we dont have events in there yet.

It doesn't seem that confusing. The blog post says that they "proactively communicated with all impacted customers" not that they've only emailed impacted customers. Recieving an email doesn't imply you were affected, just that the lack of all email saying "you were affected" means you were not impacted by this event.

In the event you had closed your account a year ago they may have deleted your information from their systems. No way for you to be impacted, but also no way to tell you that, so the lack of the email is the message in that case.

The fact an email was sent from their system implies they kept at least the email. from there one could assume they may have kept more data than the email, I would also be confused, especially if I only was emailed after the incident

> In the event you had closed your account a year ago they may have deleted your information from their systems.

Given what I know about data life cycle implementations there is a very good chance that that data was still there unless the GP explicitly requested it be deleted.

Companies tend to hang on to all kinds of data that they shouldn't have.

The fact that they received an email is a first indication that it wasn't deleted.

If you are EU based (or other equivalent country with decent data protection laws) there may be a GDPR complaint with them not deleting your data after closing your account under the right to be forgotten

Really only if you ask for your data to be deleted too

[dead]