A founder asked me this after quietly fixing a real access-control gap in his app, one that had genuinely been live for a while before he caught it: does he need to bring this up with new customers, or is it reasonable to just move forward now that it's fixed and say nothing?
What actually depends on the specifics
Whether you're under a specific legal obligation to notify anyone depends heavily on where your users are, what kind of data was actually exposed or at risk, and whether real evidence exists that anyone's data was actually accessed versus just theoretically reachable. That's a genuinely specific legal question, worth an actual conversation with someone qualified to answer it for your situation, not a blanket rule from a blog post.
The part that isn't really a legal question
Separate from any legal requirement, there's a trust question: if a new customer later found out, through a scan, a researcher, or simple bad luck, that this had happened and hadn't been mentioned, that discovery reads very differently than an incident being disclosed upfront in a calm, factual, already-fixed way. Silence discovered later reads as concealment, even when the original incident itself was a completely ordinary, common mistake. The same incident, disclosed proactively with a clear account of what happened and what changed, reads as exactly the kind of accountability that actually builds trust rather than eroding it.
What a good disclosure actually looks like
It doesn't need to be dramatic or defensive. Something plain and factual holds up well: what the gap was, roughly when it existed, what's been verified about whether it was actually accessed by anyone, and what specifically changed to close it and prevent a repeat. That's a very different message than either silence or a panicked overcorrection, and it's usually the version that actually reassures a careful customer more than it alarms them.
Why the instinct to stay quiet usually backfires over a longer timeline
The apps that end up in headlines for the worst version of this story aren't usually the ones that had a mistake, since every app eventually has one somewhere. They're the ones where a quiet report or a fix got buried and later surfaced looking like it had been hidden on purpose. A researcher's public writeup describing a company that stayed silent lands very differently than one describing a company that had already disclosed and fixed the same issue on its own initiative.
The honest answer isn't a single universal rule. It's that disclosure, handled calmly and factually, is very rarely the thing that actually damages trust. Silence that gets discovered later almost always is, and that asymmetry is worth weighing seriously before deciding silence is the safer choice.