Note
Privacy in sensor-rich environments
Systems that perceive physical environments will encounter information about routines, relationships, activity, and objects that people do not necessarily want processed, retained, or transmitted.
Note
Systems that perceive physical environments will encounter information about routines, relationships, activity, and objects that people do not necessarily want processed, retained, or transmitted.
A home, workplace, or shared environment reveals patterns of daily life. Sensing systems entering that environment cross a boundary that ordinary software does not.
Responsible design begins by acknowledging that the sensor environment is not neutral.
Data collection should be scoped to a specific supported feature. It should be described in language a customer can understand.
Uncertainty about what is collected produces uncertainty about what the system is doing. That erodes trust faster than any single feature can restore it.
Not all processing can occur on the device. Where connected services are involved, that should be described clearly rather than implied to be entirely local.
Retention, access, and transmission should each be treated as engineering decisions with defined justification.
People should be able to manage what is retained, what remains active, and how permissions change over time.
The controls must be usable. Controls that exist but are difficult to find do not serve the intent behind them.
Related notes
How permissions, interruption, confirmation, and supervision should shape physical intelligence.
Identity, updates, support, security, documentation, maintenance, and lifecycle management.
Why testing must include uncertainty, recovery, repeated operation, and environmental variation.