H05 — Privacy
Default flow
- Record locally
- Process locally where practical
- Infer sections
- Review and correct alignment
- Trim or delete
- Show exactly what will upload
- Give explicit consent
- Upload only the selected information; the default is derived-only
After upload, the contributor can delete local raw audio and use the documented withdrawal path.
Defaults
| Topic | Rule |
|---|---|
| Raw audio | Stays on device (ADR-004) |
| Upload | Derived features default (ADR-005) |
| Location | Minimise; section assignment ≠ full GPS trail |
| Speech | Incidental speech is a risk — prefer features over audio |
| Free text | Extra personal-data risk — treat carefully |
| Controller / entity | Named controller(s); CLG by launch (ADR-013) |
| Legal copy | Canon in tunes legal pack; sync tunes-web / tunes-ios consumers |
Contribution tiers (data sensitivity)
| Payload | When |
|---|---|
| Derived-only | Default / public path |
| Short excerpts | Rare, explicit, higher bar |
| Full raw | Research-restricted only, if ever |
| Research-restricted | Separate access controls |
Detail
privacy ethics · UK legal R12 · legal pack · H11 · recorder · tunes-ios client flow · ADR-004 · ADR-005 · ADR-013