Skip to documentation content

H05 — Privacy

Default flow

  1. Record locally
  2. Process locally where practical
  3. Infer sections
  4. Review and correct alignment
  5. Trim or delete
  6. Show exactly what will upload
  7. Give explicit consent
  8. Upload only the selected information; the default is derived-only

After upload, the contributor can delete local raw audio and use the documented withdrawal path.

Defaults

TopicRule
Raw audioStays on device (ADR-004)
UploadDerived features default (ADR-005)
LocationMinimise; section assignment ≠ full GPS trail
SpeechIncidental speech is a risk — prefer features over audio
Free textExtra personal-data risk — treat carefully
Controller / entityNamed controller(s); CLG by launch (ADR-013)
Legal copyCanon in tunes legal pack; sync tunes-web / tunes-ios consumers

Contribution tiers (data sensitivity)

PayloadWhen
Derived-onlyDefault / public path
Short excerptsRare, explicit, higher bar
Full rawResearch-restricted only, if ever
Research-restrictedSeparate access controls

Detail

privacy ethics · UK legal R12 · legal pack · H11 · recorder · tunes-ios client flow · ADR-004 · ADR-005 · ADR-013