Skip to content

Privacy · the five-minute version

Privacy in five minutes

Nothing here is a summary written after the fact. These are the problem, mechanism, and move of each article, in the reading order, joined by its own connective lines. Any one of them opens into the full argument.

Begin where every privacy claim begins, at the moment someone is offered a private version and told it costs nothing, because what it costs is the first thing an honest claim has to say.

Privacy is a different product

Problem
Products present a private mode as a switch inside one product, which implies everything else survives the switch, and everything else does not survive it wherever the intelligence runs on a server.
Mechanism
Encryption removes the readable text that server-side intelligence consumes, so the private version and the capable version are two products rather than two settings of one, and the control between them is a boundary.
Move
Price the fork inside the interface, naming which capability degrades, by roughly how much, and on whose measurement rather than on nobody's.

Now follow the words after they leave you. A system that reads your text makes things out of it, and the question of what those things are turns out to have a measured answer.

A vector of your words

Problem
Embeddings are handled across the industry as anonymized metadata, a safe numerical shadow of content that can be persisted, synced, and shared under looser rules than the content itself.
Mechanism
An embedding preserves enough of its source to be reconstructed rather than destroying it, which makes the vector a second copy of the words instead of an abstraction of them, and a second copy inherits every restriction the first one carried.
Move
Treat a derived vector as the content it came from, and refuse to create any derivative your deletion path cannot reach.

Move from your own material to material several people share, where somebody has to hold the room and the question is what else that job quietly comes with.

Custody is not visibility

Problem
Systems express organizational responsibility for a shared container by giving the responsible party ownership of it, which hands them read access as a side effect nobody decided to grant.
Mechanism
Custody answers who owes duties when a container has to be concluded and visibility answers who may read inside it, so a schema that derives reading from responsibility has collapsed two independent questions into one column and can no longer answer either separately.
Move
Model custody and visibility as separate axes, and forbid any read policy from naming the custodian at all, so the separation is a property of the schema rather than a habit of the people writing queries.

Then ask what happens when you take it back. Every answer that sounds instant is describing a server, and the copies are somewhere else.

The revocation window

Problem
Revoking access reads to a person as an event that has already happened everywhere, while the product knows it is a request that may not arrive, may not succeed, and will not report back when it fails.
Mechanism
Revocation is an instruction that has to travel to each device already holding a copy, so the material stays readable for exactly as long as the instruction takes to arrive, and nothing bounds that duration on a device that never reconnects.
Move
State the window in the interface where the revoking happens, with its ordinary duration and its unbounded case, and offer the one setting that closes it by keeping the material off devices entirely.

Widen once more, from where the data sits to who is holding the whole database, and find that the most trustworthy-sounding arrangement moves the risk onto whoever was not in the room.

Sovereignty relocates trust

Problem
Letting an institution hold its own database is presented as strictly more private, but the threat models these systems ship with are built out of outside adversaries and never name the institution itself.
Mechanism
Moving the database under the controller's own administration adds no adversary and removes none, but it converts the constraint on the party most able to read everything from a technical control into a legal obligation, and legal obligations bind after the query rather than during it.
Move
Disclose the tier to the people whose material is held under it, before onboarding rather than in the terms, and tell them plainly which of their rights the platform can still enforce.

Finish with the discipline all five rooms were arguments for, drawing the edge of your own claim before a reader has to go looking for it.

What your claim excludes

Problem
A protection claim with no stated edge invites the reader to extend it as far as the words will stretch, and the words always stretch further than the engineering does.
Mechanism
An exclusion published by the claimant bounds what a reader is entitled to infer, and an exclusion discovered by the reader retroactively converts every unbounded claim beside it into something that looks deliberate.
Move
Write the list of things your product may not be called, hand it to the people whose job is to make it sound good, and publish the boundary in your own documentation rather than waiting for someone else's.

You have walked The honest privacy claim end to end: the fork, the derivative, the two powers, the window, the relocated boundary, and the published edge. Six rooms, one habit. A privacy claim is only worth what it says about its own limits, and every limit in here was easier to name than to hide.