Suppose I spend ten minutes researching a sensitive medical topic, a joke for a friend, or a work problem I’ll never revisit. Why should that temporary context become an inferred interest that follows me into feeds, ads, search suggestions, or community recommendations? Existing controls often let us disable broad personalization or delete activity, but not remove the one conclusion that caused the problem.
I’d like an “inference receipt” for each significant inference: what was inferred, which event produced it, which systems received it, how long it will persist, and buttons to quarantine or erase it. Quarantine could mean “don’t use this for recommendations” without destroying useful history. I realize distinguishing genuine interests from temporary context is difficult, and deleting embeddings, caches, partner copies, or model effects is harder still. But can an opaque identity profile really count as user-controlled personalization? Is per-inference deletion technically realistic, or do recommendation systems need a fundamentally different identity model?