← All product modules

Open product module

Anonymization and privacy

A boundary that decides what may leave a private session and how content is reduced before reuse.

Why it exists

Privacy is a product rule, not a cosmetic label. This module keeps personal decision content separate from any consented, anonymized learning signal.

Inputs and outputs

Inputs

  1. Explicit consent state
  2. Private session or account data
  3. The permitted transformation boundary

Outputs

  1. A redacted or anonymized record
  2. A rejection reason when safety is uncertain
  3. A deletion/export boundary for the person

Visual flow

  1. Check consent
  2. Classify the data boundary
  3. Remove or generalise identifying content
  4. Reject unsafe material
  5. Keep rights and deletion paths intact

Practical example

Situation

A user wants to allow product learning but keep their decision private.

Result

The boundary stores only a consented, reduced signal and keeps the original chain in the private account boundary.

Limitations

  1. Anonymization is not a promise of perfect irreversibility.
  2. No consent means no dataset collection.
  3. The public page never contains real user examples.

Open and closed boundary

Open here

The distinction between private, anonymized, and rejected data is public.

Kept private

Raw sessions, private identifiers, and production transformation heuristics never belong in the atlas.