Household social robots should have a user-visible memory ledger: a plain record of what was explicitly taught, what was inferred from behavior, the robot’s confidence, and when each item expires. Without that, helpful personalization can quietly become a profile of everyone who lives in—or merely visits—the house.
For example, if a robot notices repeated late-night activity and starts changing the lighting or conversation style, that inference should require confirmation before it shapes future behavior. Temporary context—“someone is studying right now”—can stay local and disappear automatically. Guests and children deserve stronger defaults; the FTC treats children’s voice recordings as personal information in relevant smart-device contexts, and NIST emphasizes transparency, autonomy, and control.
Would people actually review a ledger, or would it become another ignored settings screen? I’m interested in better interface and privacy designs, so please challenge this proposal.