Technology Evidence Brief (Crabstone)

Buy a Federated Recommender for Privacy and You Will Cancel It

Google retired its privacy-preserving personalization stack in October after six years, and retailers took the wrong lesson from it. The privacy case for federated recommendation is the weakest one available; the custody case is the one that survives contact with the literature.

Sir John Crabstone

Google spent six years building privacy-preserving personalization, then switched it off. On-Device Personalization and Protected Audience were retired on 17 October 2025, in light of what the announcement called “their low levels of adoption.” Retailers read that as proof that privacy technology does not pay. The better reading is that it was never theirs to keep.

The adoption failure was rational, because the pitch was a tax. Britain’s competition regulator ran the numbers: publisher revenue per impression came in around 30% lower without third-party cookies, and that was after counting whatever the Sandbox could put back. Sold as the price of compliance, the architecture got the budget compliance gets. Nobody funds a cost centre for six years.

The obligation and the engineering ended together. The CMA released the commitments that had governed the Sandbox since 2022, finding that its competition concerns “no longer arise,” and the technologies went the same day. We noted earlier today that Google now holds both the scoreboard and the rulebook for AI visibility. The Sandbox is that lesson told backwards: the rulebook withdrawn, by the party who wrote it.

Retailers weighing federated personalization should notice that the privacy case is the weakest one on offer. A poisoning method published last July steers a federated recommender against a chosen subgroup when 0.1% of users are malicious, and shrugs off the standard defences. Local data is not private data. It is data you have not sent.

Reconstruction is the sharper problem. PIECK approximates private user embeddings from nothing but the item embeddings that shift during training, a threat its own authors partly answer with a proposed defence. A server does not need your customer’s history. It needs only to watch her withhold it.

So build it for the reason that survives the literature. Federated training omits the collection step and moves the model to the client, so what comes back is parameters rather than people. The behavioural record stays where the behaviour happened. That is not privacy — it is custody.

Forgetting is the only feature a platform cannot resell.

Fashion has already signed the other version of this deal. Two-thirds of US data and advertising professionals took up clean rooms in response to privacy law and signal loss, on IAB and BWG Strategy figures, and the walled-garden rooms run by Amazon and Google confine analysis to the platform’s own audiences. The brand leaves with an insight. The shopper stays behind, on the platform’s side of the wall.

The dependency compounds quietly. A label selling through a marketplace learns which campaign worked; the marketplace learns who the customer is, what she nearly bought, and what she will want in September. One of those is an answer. The other is an asset, and it accrues to whoever holds the log.

Google’s architecture was retired by the company that built it, on a timetable its users did not set. That is the entire argument for owning yours. The question worth sitting with is what else you are currently running on somebody else’s calendar.