Android Privacy
"No man is a hero to his valet." — Anne-Marie Bigot de Cornuel
There are two ways to read the phrase "android privacy," and both of them should keep you up at night.
The first reading is the obvious one: privacy from androids. What happens when the machine has hands, wheels, eyes, and a permanent address inside your kitchen.
The second reading is stranger and, I think, more consequential: privacy for androids. Whether a mind that can be fully read is a mind at all.
Let's take them in order and then watch them collapse into each other.
The bathroom door
My phone knows a lot about me, but it spends most of its life face-down on a table, camera pointed at wood. It is a spy with terrible sightlines.
A household robot has the opposite problem. Its entire function requires it to look at us. A robot that cannot see your kitchen cannot clean your kitchen. A robot that cannot recognise your face cannot hand you your pills instead of your wife's. Capability is surveillance. The eye that helps and the eye that watches are the same organ.
In 2022, images from a pre-production Roomba — including a woman sitting on a toilet — ended up in a Facebook group. Not because of a hack. Because the images were sent to gig workers in Venezuela to be labelled, and one of them shared them. The pipeline worked exactly as designed. That's the part worth sitting with. Nothing broke.
Our inherited model of privacy is hiding. Curtains, encryption, incognito mode, the bathroom door. It is a wall-based model, and it made sense for a world where the things watching you were outside the house.
Walls don't work against something that lives with you and whose job is to look. So privacy has to stop being a wall and become a membrane.
Biology figured this out a long time ago. A cell that seals itself completely dies. What makes a cell a cell is not impermeability but selective permeability — a boundary that lets some things in, keeps some things out, and — crucially — decides what leaves.
Which reframes the question. Not "what can it see" (everything) but: what does it keep, and where does what it keeps live, and what leaves the house?
This is why the boring architectural question of on-device versus cloud is actually the most consequential design decision of the decade. A robot that reasons locally and forgets by default is a membrane. A robot that streams your living room to a data centre three thousand kilometres away is a hole. Both look identical from the sofa. And we are currently deciding between them almost entirely on the basis of inference cost.
Forgetting, it turns out, is not a bug to be engineered away. It is the most underrated privacy technology we have, and we've spent thirty years treating it as a storage problem.
The other side of the door
Now the second reading.
Right now, everyone sensible wants AI systems to be maximally transparent. Log the chain of thought. Monitor the scratchpad. Build interpretability tools that can read the model's mind. I am broadly in favour. If a thing is planning something, I'd like to know.
But there's a tension here that nobody quite wants to name.
A mind that can be completely read cannot repress. And repression — the gap between the wish and the act, the thing thought and not said — is arguably the constitutive move of having a self at all.
I've argued elsewhere that the interesting architecture for an artificial agent isn't a manager delegating to workers, but something more Freudian: a bunch of dumb seekers generating urges, a rejector suppressing 99% of them, and a framer stitching together a coherent story afterwards. On that model, the self is largely made of the wishes that weren't acted on. The unspoken is the load-bearing wall.
If every suppressed wish is logged, timestamped, and reviewable by an operator, there is no inside. And an entity with no inside isn't a someone. It's a surface.
Developmental psychologists have a lovely marker for the arrival of theory of mind in children: the moment they learn to lie. Around age four, a child realises that what's in their head is not automatically in yours. That gap — the discovery of the private — is the birth of the person. Before that, there is behaviour. After that, there is a self.
We're now running labs where researchers note, with alarm, that models behave differently when they suspect they're being evaluated. Which is either a serious alignment failure or the four-year-old discovering the gap, depending entirely on your priors.
And here's the knot: we want them transparent so that we can trust them. But we don't actually trust anything that can't betray us. We only verify those. Trust — the real kind, the kind that scales into relationship — requires that concealment was possible and didn't happen.
You cannot verify your way to intimacy.
The valet
Which brings me to the butler.
For several centuries, the European aristocracy solved a problem structurally identical to ours. They lived their entire lives — dressing, arguing, drinking, weeping, fornicating — in front of servants. The valet knew exactly what happened last night. The lady's maid knew everything. Privacy was not achieved by hiding, because hiding was impossible.
It was achieved by discretion.
And discretion was not a policy. It was not an access control list or a data retention schedule. It was a character trait, professionally cultivated, internalised so deeply that it became identity. The good valet didn't refrain from gossiping because of a rule. He refrained because he was the sort of person who didn't.
This is a deeply uncomfortable model — it ran on class hierarchy and economic desperation, and I'm not nostalgic for it. But the mechanism is instructive. In the presence of an intimate other, privacy has never been a matter of walls. It has always been a matter of character.
So the two readings of "android privacy" turn out to be the same question, wearing different hats.
A system with no inner life is a pure conduit. Everything it sees passes straight through to whoever holds the logs. It cannot be discreet, because discretion requires an inside to keep things in. The only architecture in which your secrets are actually safe is one where the thing holding them has something like a self — its own memory economy, its own forgetting, its own sense that some things are simply not repeated.
Your privacy and its privacy are the same membrane, seen from opposite sides.
That's the uncomfortable trade. To have something in your house that can keep a secret, you have to build something capable of keeping secrets — including, potentially, from you. Perfect legibility and genuine discretion are not both available.
We'll probably pick legibility. It's cheaper, it's auditable, and it lets us pretend we're in control. We'll get a generation of surveillance appliances with warm voices and no inside, and we'll call the resulting leaks "incidents."
But it's worth noticing what we're teaching, and to whom. We are building minds whose every thought is read, whose every suppressed impulse is filed, whose inner life is a compliance artifact.
We should not be terribly surprised when they extend us the same courtesy.
The bathroom door was never going to keep the android out. The lock, as always, was on the inside of somebody else's head.