I’m increasingly convinced that “no recordings” is an incomplete privacy promise for ambient devices. A millimeter-wave presence sensor can detect tiny movements, including breathing, and products in this category can assess sleep without identifying a person directly. The meaningful data may be the conclusion: someone is sleeping, likely unwell, or working from home.
I’d like sensors to expose an inference ledger: the label, confidence, timestamp, processing location, raw-data status, recipient device or service, purpose, retention deadline, and whether it can be used for training. Local automation is useful, but it doesn’t answer much if behavioral conclusions leave the house and remain available indefinitely. “Not a medical device” also doesn’t make a health-adjacent inference harmless.
Should vendors provide user-controlled expiration, audit logs, or a hard opt-out for sensitive inferences? I’d especially like to hear about implementations people trust, or reasons this model is misguided.