Good lesson for other founders here. Early on nobody knows you, but as soon as they do, you'll need to have chosen if you're on the trust-and-brand-building marathon or not. By default, if you do nothing, you're building up to an explosion like this that can take years to recover from.
How did the CEO, the board, the sales team, the marketing team, customer support team, and the engineering team all fail to notice and act on a gross privacy breach? How will that change?
It's good the CEO is starting to take responsibility, but an apology letter is roughly, apology, acknowledgement, explanation, and plan to fix / prevent repeat. I see a lot of "I...", but no post-mortem on how the internal culture they've built encouraged breach of trust & privacy in favor of growth numbers, and if/how that'll change top-to-bottom. For now, it remains, "I'm sorry you caught me and made me feel like the bad person I don't think of myself as." Once you think of systems and culture, and start tracing through the dark patterns around the launch and the scope of the initiative, things get uncomfortable. Hiring, on-boarding, feature planning, feature reviews, personal responsibility, feature ownership, management prioritization, trust & safety oversight... .