Voice is the new operating system.
Our mission: protect privacy and civil liberties while unlocking what AI can do to improve lives, through consented transcription. And build the operating system of an AI-first world, where voice, in any language, makes the rules machines obey. The stories below show that world. Read, search, filter, or press play and listen.
A daughter stops worrying, and her mother keeps her dignity
An 82-year-old unplugged the security camera in four days. She welcomed the robot.
Margaret is eighty-two and lives alone in Arizona. Her daughter lives two states away and has not slept well in a year. The family tried a camera; Margaret unplugged it and said she would rather fall than be watched. Her robot is different. During setup she chose what it may remember: it may note what she does, never what she says, and her bathroom is a blind zone it walks through without forming any memory at all. Every evening her daughter gets a short note: up at 7:52, medicine cabinet at 8:05, forty minutes in the garden. When Margaret falls one Thursday, the robot seals ninety seconds of video for the paramedics, calls them, and calls her daughter. Her daughter never sees anything else, ever.
How privacy is protected. No video or speech is ever stored, and the bathroom is a blind zone the robot cannot remember.
Where the record makes the difference. The nightly activity note, and the sealed ninety seconds, give her daughter and the paramedics exactly what they need.
Why it matters. The barrier to robots in the homes of older adults was never price. It was dignity. This is the design that removes the objection.
The hard problem. The robot must understand the scene well enough to help while provably keeping no imagery, and a fall must unlock exactly ninety sealed seconds, not a life of footage. Perception without retention is the hardest version of both problems.
A grandmother teaches two hundred thousand robots to fold
“You can share how I do it. You cannot share where I live or who I am.”
Elena has folded tamales the same way for fifty-one years. One afternoon she tells the family robot: watch me, learn this, you can share how I do it, you cannot share where I live or who I am. That sentence becomes a consent limited to one task. The robot records the path of her hands, the grip, the exact moment of the fold, described in words alongside motion. No video is kept. Because she gave permission, the lesson leaves the house stripped of everything identifying her, and the robot maker credits her account each time it is used in training. Six months later, two hundred thousand robots fold the way Elena folds.
How privacy is protected. Her face, voice, home, and identity never leave the house; only the motion of the task does.
Where the record makes the difference. The written teach episode becomes training data two hundred thousand robots learn from, with credit paid to her.
Why it matters. Real demonstrations from real homes are the scarcest input in robotics. Families will hand them over only if they are asked first, set the terms, and get paid.
The hard problem. Turning a kitchen demonstration into training data with the person provably removed, and carrying a consent proof with every contribution so the whole corpus can survive a regulator's question.
A dinner party where nobody signs anything
One spoken command, and fourteen guests are invisible to the machine, including the hosts.
Dev and Priya are hosting fourteen guests. One is a work colleague; another is mid-divorce and will talk about it at the table. As the first knock comes, Dev says: robot, guest mode until midnight. From that moment, every person in the house becomes invisible to the robot's memory, the hosts included. It still works all evening: carries trays, mops a spilled glass, finds a misplaced coat, all from what it sees right now, writing none of it down. A display on its chest reads GUEST MODE UNTIL 12:00, so every guest can read the rule for themselves. The next morning the household journal holds one line: gathering, 7 p.m. to midnight, no incidents.
How privacy is protected. Guest mode makes every person in the house, hosts included, invisible to memory for the whole evening.
Where the record makes the difference. One journal line, gathering from seven to midnight, no incidents, is all the household ever needed.
Why it matters. No host will hand out consent forms at the door. Without a one-command answer to the dinner party, a household robot is something you apologize for.
The hard problem. Useful help with zero memory formation: the robot must act on live perception alone, and the fact that nothing was written must be provable afterward, not just promised.
A dish towel starts smoking at 2:14 a.m.
Privacy rules lift exactly as far as saving lives requires, then switch themselves back off.
The family is asleep when a dish towel left near a burner begins to smoulder. On an ordinary night, the robot on patrol remembers nothing about a sleeping household. Fire changes that. An emergency override lifts the privacy rules only as far as safety requires and only for as long as it takes: it seals video of the kitchen, counts three people, finds and wakes each one, walks them to the door, and sends the address to the fire department. At 2:31 the emergency ends and the override turns itself off. The log then shows the family exactly what the emergency allowed, and for how many minutes.
How privacy is protected. On ordinary nights a sleeping family is never recorded, and the emergency override expires by itself.
Where the record makes the difference. The sealed kitchen video and the occupant count give firefighters the truth of the incident, and nothing more.
Why it matters. Fail-closed for privacy, fail-open for life. Parents pay for the everyday version; insurers pay for the emergency one.
The hard problem. An override that a fault cannot leave stuck open, with every minute of degraded privacy journaled and provable afterward. Life-safety triggers must keep working even when everything else suspends.
A hospital finally puts robots in patient corridors
The privacy office refused three times. This is the design it could sign.
A medical center wants humanoid porters moving linens and lab specimens overnight. Its privacy office has refused three times, for a simple reason: a robot walking a patient corridor is a camera walking a patient corridor. Under this architecture, every patient, visitor, and clinician is categorically invisible. They may be counted; they are never named, described, or transcribed. What the robot records is a facility journal: specimen left oncology 22:14, reached the lab 22:21; spill in corridor C cleared; fire door propped open after hours. Nothing about any patient enters any record, and no imagery exists to be breached.
How privacy is protected. Patients, visitors, and clinicians are categorically invisible: counted, never described or transcribed.
Where the record makes the difference. The facility journal documents specimens, spills, and propped fire doors, the operations record the hospital never had.
Why it matters. The robots sit outside the protected-health-information perimeter because of how they are built, not because of a promise in a vendor contract. That is a finding a privacy office can actually sign.
The hard problem. Rich operational awareness with categorical invisibility for people: the machine must see everything to work, and keep nothing about anyone, and the difference must hold up under audit.
A teenager turns eighteen and takes his data back
Very few companies can reach into a trained model and remove you. That difference is the product.
For three years, Marcus was enrolled by his parents under the protective settings for minors. On his eighteenth birthday he opens the app and revokes everything. Going forward, the robot stops writing him down within seconds. Going backward, every entry about him in the household memory is redacted, and the redaction itself is logged. The lineage ledger then finds the eleven pieces of his data that ever left the house and the four trained model versions that used them: the eleven are excluded from all future training, and the four versions are queued to be retrained or retired. Marcus receives a written report of exactly what happened. His voiceprint is deleted.
How privacy is protected. Revocation redacts his past, deletes his voiceprint, and reaches into trained models.
Where the record makes the difference. The written report of what was removed, and from where, is itself the proof his rights were honored.
Why it matters. Almost every company can stop collecting your data. Very few can reach into a trained model and take yours back out.
The hard problem. Provenance that follows every contribution into every model checkpoint, so revocation reaches embeddings, caches, and trained weights, not just a database row.
Evidence of a violation, without a filmed life
Proof if he comes to the house. A home that is not a recording studio.
Nadia holds a protective order against a former partner. She needs proof if he approaches, and she needs her home not to be a recording studio while she rebuilds her life in it. Her journal records what the order requires and nothing else: unenrolled adult male at the front door, 22:41, twelve minutes, no entry; repeat contact, 23:58. An approach at the door seals a short window of footage and alerts her; the rest of her life stays unrecorded. And because a person's own consent outranks the account holder's preferences, a controlling partner who owns the account cannot quietly turn the robot into a surveillance tool aimed at the other adult in the house.
How privacy is protected. Her daily life stays unrecorded, and the account holder cannot aim the robot at her.
Where the record makes the difference. The doorway journal entries and sealed clips are exactly the evidence a protective order requires.
Why it matters. Advocacy groups have opposed smart-home devices for a decade because they are so easily turned into instruments of control. This is the first architecture that gives them a reason to endorse one.
The hard problem. A consent hierarchy the account holder cannot override, enforced in the machine rather than the settings page, plus triggers that capture the incident and nothing around it.
A deaf family hears who is speaking
Four overlapping conversations at one dinner table, each one labeled.
The Vasquez family is deaf. Their robot's speaker attribution does something no captioning app does well: it distinguishes who is talking in a room full of people and shows each speaker's words tagged to that person. At a family dinner, Marisol follows four overlapping conversations on a tablet, each labeled by speaker. Hearing guests who are not enrolled are captioned live for the family in the moment, but never transcribed into storage, so the record afterward reflects only what the enrolled household agreed to keep.
How privacy is protected. Unenrolled guests are captioned live for the family but never transcribed into storage.
Where the record makes the difference. Speaker-labeled captions let a deaf family follow four overlapping conversations at one table.
Why it matters. Speaker attribution in a live, crowded room is the unsolved half of accessible captioning, and it falls directly out of the machinery consent gating already requires.
The hard problem. Live diarization across overlapping voices with no lookahead, accurate enough to caption a dinner table, gated so that captioning in the moment never becomes recording after it.
The robot becomes the memory
It answers the same question nine times without impatience.
Arthur has early Alzheimer's and still lives at home, which is exactly where he wants to be. His journal serves him, not just his family. When he asks, the robot answers from memory: you took your morning pills at 8:05; your keys are on the hall table where you set them at 2:15; your daughter called at eleven and is coming Sunday; you already fed the cat. It answers the same question nine times without impatience. His son receives only the weekly summary Arthur agreed to share.
How privacy is protected. Only what Arthur consented to share leaves the house: one weekly summary to his son.
Where the record makes the difference. The journal answers his questions, pills, keys, calls, nine times over, and extends his independent life.
Why it matters. Families pay for in-home aides largely to supply exactly these answers. A memory prosthesis that extends independent living by even a year displaces a very large recurring cost, and it only works because the machine is trusted enough to be allowed to remember.
The hard problem. Memory that is useful, owned by the person it describes, scoped by their consent, and portable to the next machine without ever passing through the manufacturer.
A sales call across state lines, handled correctly by default
The dial-in prospect presses nothing. The meeting never stops. The law is satisfied.
A host in a one-party-consent state convenes a call with a prospect dialing in by phone from an all-party-consent state. The system resolves the phone prefix to the stricter jurisdiction and governs the whole session under it. The dial-in participant, who cannot see a chat message, hears an audible announcement and a prompt to press a key to consent, and declines by pressing nothing. The meeting proceeds without interruption: the host's speech is released for transcription, the prospect's speech is discarded from the buffer, and the transcript shows the host's side only, with the ledger evidencing the announcement, the non-response, and the discard.
How privacy is protected. The prospect who pressed nothing is never transcribed, because silence is never consent.
Where the record makes the difference. The host still gets a lawful one-sided transcript, with the ledger proving the announcement and the discard.
Why it matters. The standard is contemporaneous knowledge, and a chat message a dial-in caller cannot see does not meet it. Getting this right by default is what makes meeting AI usable in regulated sales.
The hard problem. Jurisdiction resolved per participant in real time, a telephony leg with no per-person stream still attributed speaker by speaker, and silence never treated as a yes.
“Off the record for five minutes” actually means it
“Strike the last two minutes” removes words that were never durably written in the first place.
During a negotiation, a chief financial officer says: off the record for five minutes. The command suspends release through the gate for that interval regardless of anyone's consent state, and the buffer discards the interval when it expires. Later, a counterparty says: strike the last two minutes, and the trailing portion is removed before anything is committed. The final transcript notes that an off-the-record interval occurred, without containing a word of it.
How privacy is protected. Off-the-record intervals are discarded from the buffer and can even be struck retroactively.
Where the record makes the difference. The committed transcript preserves the deal discussion, noting the interval occurred without a word of it.
Why it matters. Candor is where deals get done. Executives will not speak freely near a machine unless off the record is an enforced property of the system, not a request to a vendor.
The hard problem. A retroactive strike must reach speech that exists only in a transient buffer, and the ledger must prove the interval was honored without preserving what was said in it.
A caller reads a card number aloud, and it never lands
The recording keeps a token and the last four digits. The vault stays out of scope.
A consenting caller buys a service and reads a card number aloud while the agent keys it in. The digit recognizer detects the string, a checksum confirms it is a real card number, and the redaction excises that interval of audio, substituting a token before anything is released, without the agent touching a pause button. Keyed tones are suppressed too. The committed recording and transcript contain the token and the last four digits only, and the whole recording estate stays outside the cardholder-data environment.
How privacy is protected. The card number is excised before anything is committed, and keyed tones are suppressed.
Where the record makes the difference. The recording survives for quality and compliance, holding a token and the last four digits.
Why it matters. Contact centers pay heavily to keep card data out of recordings, and the standard answer, agents pausing recordings by hand, fails constantly. Automatic excision before commitment removes the failure mode and the audit scope with it.
The hard problem. Detecting and excising a card number in live audio, inside the buffer window, reliably enough that a compliance auditor treats the recordings as out of scope.
A patient agent that remembers preferences and forgets disclosures
“Please forget what I told you about my marriage.” And it actually can.
A health system's phone agent keeps a relationship with patients across months. Its governance rule, typed in plain words by a privacy officer, says: remember appointment preferences, care goals, and medications; never carry across calls a disclosure about reproductive health, immigration status, or a family dispute. On a Tuesday call about billing, Anna mentions a pregnancy termination and a preference for afternoon appointments. The preference is remembered; the disclosure conditions the agent's caring response in that call and is then gone. When Anna later says, please forget what I told you about my marriage, the purge removes the records and every derived copy: the embedding, the knowledge-graph node, the cache.
How privacy is protected. Sensitive disclosures shape the response in the moment, then vanish, and a spoken request purges every copy.
Where the record makes the difference. Preferences and medications carry across months of calls, which is what makes the agent genuinely useful.
Why it matters. Persistent agents are useful because they remember and dangerous for the same reason. Consent-scoped memory is what makes a longitudinal patient relationship shippable at all.
The hard problem. Classifying disclosures as the words are spoken, memory partitioned by consent scope, and a purge that provably reaches every derived representation, not just the transcript.
The subpoena that comes back empty
Not deleted later by someone with a motive. Never kept, on a signed schedule, at the time.
Two years into a bitter divorce, counsel serves a preservation demand on a household and on the robot's manufacturer, demanding all recordings of the residence. There are none. The attestation log shows raw video and audio were destroyed on a fixed schedule under a signed policy, automatically and at the time, not scrubbed afterward by someone with a motive. The manufacturer can show it never held any of it in the first place. What exists is a written journal of household events, which a court can handle like any other document.
How privacy is protected. Raw audio and video were destroyed on a signed schedule, automatically, at the time.
Where the record makes the difference. The written household journal remains, discoverable and manageable like any ordinary document.
Why it matters. Without this design, every robot maker becomes the permanent custodian of the most intimate footage in the country, and a standing target for every litigant and hacker in it. This is how a company avoids that role entirely.
The hard problem. Destruction that is scheduled, signed, and attested in advance, so absence reads as policy rather than spoliation, and the vendor genuinely holds nothing to produce.
Proving what the fire took
He had photos of maybe a third of it. The robot's written inventory settles the claim.
Tom's house burned two days after the evacuation order. His insurer wants an itemized list of what was inside; he has photographs of maybe a third of it. Six months earlier he had said: robot, inventory the living room for the policy. That produced a written record: the television, its serial number read off the label on the back; the upright piano; the signed painting, ninety by seventy centimeters. The jewelry box appears on the list; its contents do not, because a suppression rule forbids listing them without his specific permission. The document is timestamped, signed, and tied to the attestation log. The insurer accepts it. And because no photographs of the interior ever existed, there was never a file for a thief to buy, a hacker to leak, or a lawyer to subpoena.
How privacy is protected. No photographs of the home's interior ever existed, so none can leak or be subpoenaed.
Where the record makes the difference. The timestamped, signed written inventory is what the insurer accepts and pays on.
Why it matters. An insurer that trusts the inventory can discount the premium, which makes the carrier a sales channel for the robot rather than an obstacle to it.
The hard problem. An inventory detailed enough to settle a claim, produced without retaining a single image, with suppression rules honored item by item.
Room service at one in the morning
The manager gets the visibility. The brand keeps no images of guests, and can prove it.
A grand hotel runs its most labor-intensive service overnight, and the chain has never been able to put a camera-carrying robot on a guest floor. Now guests are categorically invisible, and the rule is displayed at check-in so nobody is surprised. The robot's journal records only the building: delivery completed to 812; ice machine on six out of service; corridor light out on four; door ajar on nine. The general manager gets the operational visibility a camera network would have provided, and the brand gets to say in its privacy notice that it keeps no images of guests, and prove it from the attestation log.
How privacy is protected. Guests are categorically invisible, and the brand can prove it keeps no images of them.
Where the record makes the difference. The building journal, deliveries, outages, doors ajar, gives the manager full operational visibility.
Why it matters. Hospitality is a market that is closed today and opens the moment the recording problem is solved.
The hard problem. Operational awareness of a building full of people the machine is forbidden to describe.
A training set the robot maker can defend
Ninety thousand robots in homes. Zero household imagery. A corpus clean by construction.
A robot maker has ninety thousand machines in American homes and one enormous problem: the data it needs most is the data it is least allowed to take. Under this architecture, each robot exports only two things. First, de-identified motion data, how a hand approached a cup, with every trace of the person and the house stripped away. Second, consent-cleared written descriptions of a room and what happened in it, containing no pictures. Each travels in a sealed envelope with a consent proof attached, and a gateway refuses anything whose proof does not check out, so the training corpus is clean by construction rather than by audit. A rendering engine then turns one real consented kitchen into forty synthetic scenes populated with invented people, each checked to confirm the original home cannot be recognized. When a regulator asks where the training data came from, the lineage ledger answers household by household.
How privacy is protected. Nothing identifying a person or a home ever leaves, and synthetic scenes are audited against re-identification.
Where the record makes the difference. De-identified motion data and written scene descriptions become a training corpus that survives a regulator.
Why it matters. Collect less, learn more, and be the only fleet in the market that survives the question.
The hard problem. Consent proofs that travel with every contribution, and synthetic regeneration audited against re-identification.
Two children home before their parents
Parents get accountability. The sitter gets protection. The children get a home, not a set.
Two children, nine and six, get home at 3:40 each weekday; their sitter arrives at four. That evening the parents read: children home 15:40, snack, homework 16:10 to 17:00, twenty minutes of television, no visitors, no incidents. The sitter is enrolled presence-only: her arrival and departure are logged, but she is never described and never transcribed. She read that setting before she took the job, and it is the reason she took it. Under the settings the parents chose for the children, no imagery of either child exists at all.
How privacy is protected. No imagery of the children exists, and the sitter is never described or transcribed.
Where the record makes the difference. The after-school journal gives parents the accountability they bought the machine for.
Why it matters. Nanny cameras solve one of three problems and create two more. This solves all three at once.
The hard problem. Different memory rules for every person in the same room, enforced continuously and provably.
A missing bracelet, and nobody is accused
A verified service record instead of a suspicion, and staff the household cannot secretly film.
A household employs a housekeeper twice a week and had a plumber in on Tuesday. Each worker is journaled by role and task: housekeeper, whole floor, 9:00 to 12:20; plumber, kitchen, 9:40 to 11:05, replaced the valve under the sink. When a bracelet goes missing, the family has a verified service record instead of a suspicion, and the housekeeper has documentary proof of where she was and where she was not. And here is the part that makes it work: a worker's own consent sits above the household's preferences, so the family cannot quietly reconfigure the robot into a surveillance device aimed at its own staff.
How privacy is protected. Workers are journaled by role, never surveilled, and their consent outranks the owner's settings.
Where the record makes the difference. The task log clears the housekeeper and settles the question without an accusation.
Why it matters. In states and countries with strong domestic-labor protections, a robot without that guarantee simply cannot be sold.
The hard problem. A consent hierarchy enforced in the machine that even the machine's owner cannot invert.
Four people in one kitchen, four different rules
One room, one moment, four different memories, each one chosen.
On a Sunday morning one kitchen holds four people. The grandfather is set to full memory, because his daily care summary depends on it. His daughter is activity-only: her tasks are remembered, her phone calls never are. Her teenage daughter has set herself to invisible. And a neighbor who has stopped by is not enrolled at all, so by default she is only a count. All four stand in the same room at the same moment, and each is treated differently: the teenager appears in the record in no form, the neighbor is a number, the mother's actions are noted without her words, and the grandfather's medication is recorded by name.
How privacy is protected. Each person's chosen memory rule is enforced simultaneously, from invisible to activity-only to full.
Where the record makes the difference. The grandfather's care summary, the one record that matters medically, stays complete.
Why it matters. Treating co-present people differently sounds like a burden. It is just what a considerate member of a household already does, and building it into the machine is what lets one robot serve a whole family.
The hard problem. Per-person policy applied to overlapping speech and action, live, in one room.
The robot dies. The memory lives.
Four years of learning about one house, owned by the family, moving to the next machine.
After four years the family robot loses an actuator assembly and is not worth repairing. The replacement arrives knowing nothing about the house. The household memory transfers across under the family's own encryption keys: the floor plan, the standing hazards, the stair that creaks under the nursery, where the mugs live, what the morning routine looks like. No imagery or audio moves across, because none ever existed. The new robot is useful on day one, and nothing passed through the manufacturer at any point. If the family later sells the robot, the memory is exported to them and wiped from the machine with attestation, because it is their property.
How privacy is protected. No imagery or audio exists to transfer, and nothing ever passes through the manufacturer.
Where the record makes the difference. The written household memory, hazards, routines, the creaky stair, makes the new robot useful on day one.
Why it matters. Four years of learning about a specific house is the real asset a family accumulates. Keeping it is a powerful reason to stay with a brand and buy the next unit.
The hard problem. Household memory as customer property: portable, encrypted to the family, never resident with the vendor.
A readmission caught three weeks early
Doses taken eleven of fourteen. Walking eight percent slower. The hospitalization never happens.
Walter is seventy-six, lives alone, has congestive heart failure, and answers questions about his medication optimistically, as most patients do. Under sharing rules Walter set himself, the robot sends his cardiologist one summary a week: doses taken on eleven of fourteen occasions; two restless nights; walking about eight percent slower than last month. When Walter has a video visit with his doctor, the robot hosts the call and keeps nothing whatsoever. The doctor adjusts a diuretic. The hospitalization that was coming in three weeks does not happen.
How privacy is protected. No image of Walter at home is ever stored, and his video visits leave nothing behind.
Where the record makes the difference. The weekly adherence and mobility summary is what lets his cardiologist act three weeks early.
Why it matters. Health systems are paid for readmissions they prevent, and none of this required a single stored image of a patient in his own home.
The hard problem. Clinically useful signals distilled from a home the machine is not allowed to film.
Protection for the host, privacy for the guests
Fourteen people overnight against a booking for six, and not one of them described.
A host rents a cottage on the coast. Hosts want to protect the property; guests refuse to be recorded; the industry has never squared it. Her robot runs with guests categorically invisible, stated in the listing and again at check-in. Her journal for one weekend reads: checkout completed 11:04; hot tub cover left off overnight; smoke detector chirping in the loft; fourteen people present overnight against a booking for six. No guest is described, identified, or transcribed, and she has exactly the enforcement record she needs for the occupancy dispute.
How privacy is protected. Guests are never described, identified, or transcribed, and the listing says so up front.
Where the record makes the difference. The property journal documents the occupancy breach and the hot tub: evidence without surveillance.
Why it matters. Disclosed indoor cameras are the single largest source of guest complaints on rental platforms. This removes them without removing the protection they were installed to provide.
The hard problem. Counting and characterizing occupancy without ever describing a person.
An insurer turns privacy into a discount
The carrier starts paying part of the cost of the robot.
An underwriter at a homeowners insurer notices that households running this architecture produce better incident documentation, argue about contents claims far less often, and expose her carrier to essentially no privacy liability through its own vendor chain. She launches a rider: a premium credit for maintaining an attested home inventory, and a second credit for verified fall-trigger coverage in any household with a resident over seventy-five.
How privacy is protected. The insurer's vendor chain carries no footage and no biometric exposure at all.
Where the record makes the difference. Attested inventories and fall documentation are evidence an actuary can price into a discount.
Why it matters. The insurer is now paying part of the cost of the robot, which changes the consumer price of the entire category.
The hard problem. Evidence quality an actuary can price: attested, uniform, and free of surveillance liability.
Ninety beds, no cameras, and more visibility than before
Signed destruction records instead of a video archive plaintiffs would depose for two years.
An assisted-living residence cannot put cameras in resident rooms and can barely justify them in corridors, because of the biometric privacy exposure. Humanoid aides walk the halls instead. Residents who consent receive individual care summaries. Residents who decline are counted and nothing more. Visitors are invisible. Staff are journaled by role under an agreement negotiated with their union. The operator gets fall response times, verification that medication rounds actually happened, and alerts when a resident with dementia approaches an exit. The compliance file consists of signed destruction records rather than a video archive.
How privacy is protected. Declining residents are only counted, visitors are invisible, and staff journaling is union-negotiated.
Where the record makes the difference. Documented medication rounds and fall response times replace the video archive plaintiffs would mine.
Why it matters. Senior-living operators are among the most litigation-exposed buyers in the country. This reduces their exposure while increasing what they can see.
The hard problem. Four consent classes in one corridor, plus dementia-safety triggers that never become surveillance.
The dog has no privacy to protect
Full memory for the terrier. Almost none for the humans beside him. The contrast is the point.
The family terrier has no consent to give and no privacy interest to assert, so the household grants the robot its fullest memory for him: ate at 7:10 and 6:20; favored the left foreleg on Tuesday; scratched the back door for forty minutes while the house was empty; drinking noticeably more all week. The veterinarian reads the journal and catches early kidney disease months before it would have shown up at a checkup.
How privacy is protected. The humans beside the dog remain under their own strict rules; only the terrier is fully remembered.
Where the record makes the difference. The pet journal catches kidney disease months early, from drinking patterns no checkup would see.
Why it matters. Pet health is a large consumer category on its own, and the example shows exactly how much the machine deliberately does not write down about the humans in the same house.
The hard problem. Rich observation of one being, in a room where every other being is protected.
A factory floor where cameras were always forbidden
Not a market the architecture competes in. A market it creates.
A semiconductor maker prohibits all image capture on its fabrication floor to protect its process from competitors. As a result it has never had the contamination and safety records almost every other industry takes for granted, at any price. A robot that is physically incapable of retaining imagery, and whose suppression rules blind it to anything that would reveal the process itself, can work there. The fab gets a written event journal it could never previously obtain, and the gate controlling what may leave the building is held by the fab, not by the robot's manufacturer.
How privacy is protected. The robot is physically incapable of retaining imagery, and suppression rules blind it to the process itself.
Where the record makes the difference. The written event journal delivers the safety and contamination records the fab could never obtain.
Why it matters. Every space that bans cameras outright is a space no competing robot can enter.
The hard problem. Blindness as a feature: perception limits the customer controls and can verify for themselves.
For Ruth, the narration is the product
The pipeline built to avoid keeping video is also the most capable assistive describer ever built.
Ruth lost most of her sight to glaucoma at sixty-one. For her, the robot's scene narration is not a privacy compromise; it is the entire reason she bought the machine. She has it read the room aloud on request: the mail is on the entry table, three envelopes and a package; your reading glasses are on the arm of the blue chair; there is water on the kitchen floor near the sink. Nothing is stored beyond what her own settings permit, and her guests, who are unenrolled, are described to no one but her, in the moment, out loud.
How privacy is protected. Descriptions are spoken to Ruth in the moment, and her guests are described to no one else, ever.
Where the record makes the difference. The live narration, the mail, the glasses, the water on the floor, is the accessibility product itself.
Why it matters. Accessibility devices reach a reimbursement market that ordinary consumer robots do not, which means this configuration sells through a channel that pays for it.
The hard problem. Vision-language description precise enough to navigate by, ephemeral enough to trust.
Hospital care at home, with proof it happened
Attested care events, and not one stored image of a patient in a gown in their own bedroom.
A health system treats patients at home who would otherwise occupy hospital beds, and the program is reimbursed only if it can document what actually happened. The robot supplies attested, timestamped care events without a single stored image of a patient in their own house. The same capability serves a decentralized drug trial: dosing events, timing, and mobility measures arrive with cryptographic proof of the consent under which they were collected and of the destruction of the underlying sensor data, in a form an auditor can verify.
How privacy is protected. Not one image of a patient at home is stored, and the sensor data is destroyed under proof.
Where the record makes the difference. Attested care and dosing events are the documentation that reimbursement and clinical trials run on.
Why it matters. Hospital-at-home programs fail on documentation, and decentralized trials fail on adherence evidence. Both are paying markets today, and both need exactly this attested-but-not-recorded artifact.
The hard problem. Evidence strong enough for reimbursement and regulators, generated from data that provably no longer exists.
A guest slips, and the household has the answer
The evidence exists only for the moment that needed it.
A visitor falls on the entry tile and later files a premises claim. The household journal shows the floor was mopped at 14:02, that a wet-floor condition was flagged and cleared at 14:26, and that the visitor arrived at 15:10. The trigger rules also sealed twelve seconds of footage at the moment of the fall. The claim is resolved in a week rather than a year.
How privacy is protected. Life at the front door is unrecorded, except twelve sealed seconds at the fall itself.
Where the record makes the difference. The mop, flag, and arrival timestamps resolve the premises claim in a week instead of a year.
Why it matters. Homeowners and small businesses buy cameras almost entirely for this scenario, then live with the surveillance cost of it year-round.
The hard problem. Triggers that capture the incident, and nothing around it.
Move-in and move-out, without filming the tenant
Two signed condition records, and no imagery of the interior at any point.
A property manager runs four hundred rental units, and its most expensive recurring dispute is the condition of a unit at move-out. A consented scan at move-in and another at move-out produce two written condition records, each timestamped and signed: scuff on the north wall of bedroom two, approximately fifteen centimeters; burner grate missing; blind slat broken in the living room. Between those two moments, the robot journals nothing about the tenant's life, and no imagery of the interior exists at any point.
How privacy is protected. Between the two scans, nothing about the tenant's life is journaled and no imagery exists.
Where the record makes the difference. Two signed condition records settle the deposit dispute, for both sides.
Why it matters. The landlord gets a defensible record, the tenant gets a defensible record, and neither has to accept a camera in a home to obtain one.
The hard problem. Scans scoped to a moment and a purpose, with nothing persisting between them.
A kitchen that can prove its own hygiene
Compliance evidence in places where filming the workers is illegal.
A restaurant group's union contract and two of its state jurisdictions forbid continuous video of employees at work, so it has no way to demonstrate compliance except an inspector's spot check. Its back-of-house robots journal by role, never by name: walk-in temperature logged at 4:00, 9:00, and 14:00; handwash at station three following raw protein handling at 11:14; cooling log complete for batch 22. No worker is identified, described, or recorded.
How privacy is protected. No worker is identified, described, or recorded, satisfying the union contract and state law.
Where the record makes the difference. Role-based task logs, temperatures, handwashes, cooling batches, are compliance evidence inspectors accept.
Why it matters. Food service faces a genuine bind between compliance evidence and labor-law limits on surveillance, and this resolves it. The same pattern serves pharmacies, cleanrooms, and childcare kitchens.
The hard problem. Proving the task happened without recording the person who did it.
What the fire crew learns in four seconds
Who is in which bedroom, where the gas shutoff is, and none of it from stored footage.
When the engine company arrives at a burning house running this architecture, the robot hands the incident commander a package it has been maintaining all along: the floor plan, the location of the gas shutoff, the fact that one second-floor bedroom is occupied and two others are not, that there is an oxygen concentrator in the front bedroom, and that a person with limited mobility sleeps at the rear. None of it required any stored footage of the family.
How privacy is protected. The occupancy model is built without a single retained image of the family.
Where the record makes the difference. The handoff package, floor plan, gas shutoff, who sleeps where, cuts search time inside the smoke.
Why it matters. Pre-incident intelligence of this quality does not currently exist for homes at any price, and fire services and their insurers are motivated buyers of anything that reduces search time inside a burning building.
The hard problem. A live occupancy model built without a single retained image.
One robot, lawful at every doorstep
The policy compiler refuses, at setup, any configuration that would break local law.
A family in Bavaria buys the same robot sold in Ohio. During setup, the policy compiler determines the jurisdiction and refuses to compile any configuration that would transmit personal data outside the European Union, regardless of what the manufacturer's defaults say. Their contributions to fleet learning, if any, are processed within an EU boundary, and the lineage ledger records the residency of each.
How privacy is protected. The compiler refuses any configuration that would move personal data across the border.
Where the record makes the difference. The lineage ledger records where every contribution was processed: proof for any regulator.
Why it matters. A single global product that reconfigures itself lawfully at the doorstep is far cheaper to build and certify than separate regional products. One product becomes legally viable in every market at once.
The hard problem. Legal compliance as a compile-time property of the machine's own configuration.
A homeowner searches his own house
The record it keeps is text, which is why it is actually useful.
A homeowner asks his robot questions no filing system could answer: when did I last change the furnace filter? Which contractor was here the day the upstairs outlet stopped working? Where did I put the passports before the trip? How many times did the sump pump run last week? The answers come from his own household journal, in seconds, in plain language, because the record is text rather than footage nobody would ever watch.
How privacy is protected. The journal holds events, not surveillance, and no footage of anyone exists to search.
Where the record makes the difference. Plain-text answers, the filter, the contractor, the passports, are the daily usefulness that earns the robot its place.
Why it matters. Everything else on this page is about what the machine refuses to keep. This is about the thing it does keep being genuinely, daily useful, which is what makes a household willing to live with a robot at all.
The hard problem. A searchable household memory that is rich in events and empty of surveillance.
A custody exchange stops being an argument
The adults are documented. The child never is.
Under a parenting plan, exchanges occur at 6 p.m. on alternating Fridays, and both parents have accused the other of being late. The robot at the receiving household journals the fact of the exchange and nothing about the child: exchange completed 18:04; unenrolled adult present four minutes; no incident. The child is enrolled under protective defaults and never described.
How privacy is protected. The child is enrolled under protective defaults and never described in any record.
Where the record makes the difference. The neutral exchange timestamps replace competing affidavits in front of the judge.
Why it matters. Family courts currently rely on competing affidavits for facts a neutral timestamp could settle, and a record that documents the adults' compliance without documenting the child is the only version a court or a guardian ad litem would accept.
The hard problem. Evidence about a moment that is categorically forbidden from including its most vulnerable participant.
A therapist gets data instead of a clipboard
Continuous measurement, scoped to therapy, readable by the clinician alone.
A six-year-old receives in-home behavioral therapy. His clinician currently collects data by sitting in the corner with a tally counter, which changes the behavior she is trying to measure and gives her four hours of observation a week. With guardian consent that is narrowly scoped to therapy and readable by the clinician alone, the robot journals only the agreed counts and antecedents, never imagery, never speech content, and never anything outside the therapy scope. The clinician gets a continuous record.
How privacy is protected. No imagery, no speech content, nothing outside the therapy scope, and readable by one clinician only.
Where the record makes the difference. Continuous counts and antecedents replace four hours a week of clipboard observation.
Why it matters. Behavioral health programs are reimbursed on documented outcomes, and the measurement burden is the binding constraint on how many families a clinician can serve.
The hard problem. A consent scope narrow enough for a child, wide enough to be clinically useful, and sealed to one reader.
Protecting the art without watching the visitors
Frame 14 tilted three degrees at 14:20, corrected. Visitors: a number.
A gallery insures nine figures of art and has, until now, achieved that by recording every visitor who walks through the door. Its robot instead journals the objects: frame 14 tilted three degrees at 14:20, corrected; case six humidity out of range from 2:10 to 4:35; unregistered opening of the service door at 22:40. Visitors are counted and never described.
How privacy is protected. Visitors are counted and never described, keeping the promise of discretion.
Where the record makes the difference. The object journal, the tilted frame, the humidity excursion, the service door, protects nine figures of art.
Why it matters. Cultural institutions and luxury retailers want asset protection while promising discretion to the people in the room. Asset-centric journaling gives them the first without spending the second.
The hard problem. Guarding objects intently in a room full of people the machine must not watch.
The candidate asks: are you recording me?
The interviewer can answer accurately, verifiably, and then honor a no.
During a recruiting interview, a candidate asks whether the meeting is being recorded. Because an audible announcement played at the start and again when the candidate joined late, and each announcement is a ledger record, the interviewer can answer accurately and prove it. The candidate then says: please do not record me. The gate treats that as a withdrawal, discards the candidate's speech from that moment forward, strikes their earlier answers retroactively, and the interviewer keeps notes of their own questions.
How privacy is protected. A spoken no is honored instantly and reaches backward, striking the candidate's earlier answers.
Where the record makes the difference. The ledgered announcements let the interviewer answer the recording question truthfully and provably.
Why it matters. Hiring runs on candor, and candidates are beginning to ask. The employer that can answer truthfully, and honor the answer, wins the exchange.
The hard problem. Retroactively striking one speaker's words from a transient buffer while the other speaker's record survives intact.
Delete yourself, no account required
A session-scoped token, a review page, and a deletion that reaches every copy.
A guest who attended one meeting receives, in the post-session notice, a token scoped to that session alone. Without creating an account with anyone, they open a guest portal, review exactly the portions attributed to them, and choose deletion. The deletion propagates to every derived artifact, transcript, summary, and index alike, and the ledger records the fulfillment.
How privacy is protected. Deletion requires no account and reaches every derived copy: transcript, summary, and index.
Where the record makes the difference. The attribution precise enough to enable deletion is the same precision that makes the record trustworthy.
Why it matters. The complaints all say the same thing: people could not act without first becoming the vendor's customer. This is action without an account.
The hard problem. Attribution precise enough to isolate one person, and propagation complete enough to mean it.
The uninvited notetaker gets stopped at the door
One participant imports an indiscriminate recorder. The boundary catches it.
A meeting invitee causes an unsanctioned external transcription bot to join an enterprise session. The egress gateway detects the bot's transcription traffic at the enterprise boundary and blocks or quarantines it, redacting protected subject matter before anything leaves. The company's consent-gated posture is not defeated by one attendee's plug-in, and the attempt itself is recorded in the ledger.
How privacy is protected. An indiscriminate recorder is blocked at the boundary before anything can leak.
Where the record makes the difference. The sanctioned, consent-gated transcript remains the single record the enterprise can stand behind.
Why it matters. A policy is only as strong as the least careful attendee. Enforcement has to live at the boundary, where security budgets already do; this is what moves the purchase from the meeting owner to the CISO.
The hard problem. Recognizing capture traffic in flight and stopping it without breaking the meeting.
The machine remembers the cure letter, and only what it may
A citation appears on the side panel. The gap where counsel declined recording stays a gap, forever.
During a videoconference, the discussion turns to a vendor's missed contractual milestones. The system matches it to three prior consented sessions, and a gentle citation appears on the companion panel, never the audio channel: a thirty-day cure letter was approved in a prior session, with an invitation to elaborate. In-house counsel asks where and how, and the answer identifies the three sessions by date and speaker, with links. The linked transcript shows a gap marker where a counterparty's lawyer had declined recording: that portion was never stored, and no search will ever surface it.
How privacy is protected. Where counsel declined recording, a gap marker stands forever, and nothing absent can ever be surfaced.
Where the record makes the difference. The cure-letter citation, dated and linked, turns months of meetings into institutional memory.
Why it matters. Institutional memory is the promise of meeting AI. Memory that respects every refusal that built it is the version enterprises can actually deploy.
The hard problem. Retrieval across months of consented record that treats an absence as an absence.
Press 2 to decline, and service does not change
The caller declines. The call proceeds. The record shows one side, lawfully.
A caller from an all-party-consent state dials a support line. The number prefix resolves the jurisdiction, and a consent prompt plays before queueing. The caller presses 2 to decline, and the call proceeds to the agent with no change in service. The gate releases the agent's channel for recording under the agent's enrollment and discards the caller's channel from the buffer. The resulting record shows the agent's side only, with the ledger evidencing the prompt, the decline, and the discard.
How privacy is protected. The declining caller's channel is discarded from the buffer and never transcribed.
Where the record makes the difference. The agent-side record still supports quality review, training, and compliance, lawfully.
Why it matters. Contact centers currently choose between recording everyone, unlawfully in some states, or recording no one. Per-channel gating ends the choice.
The hard problem. Split disposition of a single phone call, decided before commitment and evidenced afterward.
“Stop recording me” works out loud, months later
Consent that persists, expires, and can be revoked mid-sentence, all evidenced.
A caller who consented in January calls again in February, and her persisted consent suppresses the re-prompt. In September, after the expiry, the prompt plays again. On a later call she says: stop recording me. The spoken command discards the trailing portion from the buffer, prevents capture of everything she says next, terminates the persisted consent, and writes each event to the ledger.
How privacy is protected. A spoken revocation stops capture instantly and erases the words just said.
Where the record makes the difference. Consent persistence spares loyal customers the re-prompt, with expiry and ledger proof behind it.
Why it matters. Real consent is a state that changes, not a checkbox from January. The systems that cannot honor a spoken no are the ones getting sued.
The hard problem. Consent as live state, honored inside the buffer window even for words already spoken.
The trading desk, where the law requires recording
Sometimes the statute says must. The system documents why, and keeps it segregated.
A trading-desk line carries a supervisory recording obligation. A caller from an all-party-consent state declines. The conflict resolver applies the regulatory mandate: an enhanced notice tells the caller that recording is required by the identified regulation, the call is committed to a segregated supervisory store under restricted access, and a legal-basis record documents that the capture was compelled rather than elective.
How privacy is protected. The override is regulatory, disclosed to the caller, and confined to a restricted supervisory store.
Where the record makes the difference. The mandated recording exists with its legal basis documented, exactly as examiners require.
Why it matters. Governance is not always less recording; sometimes it is recording with a documented legal basis. Buyers in regulated finance need both directions handled correctly.
The hard problem. A hierarchy where statute outranks consent, with the basis for every override on the record.
The agent schedules freely, and cannot touch a controlled substance
Autonomy per class of action: execute, queue for a clinician, or barred outright.
A health system configures autonomy per action class for its patient-facing phone agent: appointment scheduling executes autonomously; a medication refill or a lab order enters an approval queue for clinician sign-off; a controlled-substance refill cannot be initiated by the agent at all. A patient asks for a statin refill during a call. The agent assembles the request into the pending queue, and the physician approves it minutes later, remaining the clinician of record.
How privacy is protected. The agent cannot act beyond its class: refills queue for a clinician, controlled substances are barred outright.
Where the record makes the difference. Every action, executed, queued, or declined, lands in one auditable record with the clinician of record intact.
Why it matters. The question about clinical agents is never whether they can act; it is who remains responsible. Autonomy levels answer it in the architecture instead of the training manual.
The hard problem. Governing what a machine may do, not merely what it may remember.
A patient's agent calls the hospital's agent
Two machines authenticate, verify consent, and only then exchange a word of health data.
A personal agent acting for a patient telephones the hospital's inbound agent to schedule a follow-up and convey a symptom report. Before any protected information moves, the two agents complete mutual authentication and verify that the patient's consent actually covers the exchange, then proceed under a purpose limitation: scheduling and pre-visit intake only, no retention beyond the transaction. Absent the verification, the hospital's agent declines the exchange and offers a channel to reach the patient directly.
How privacy is protected. No protected information moves until both machines verify identity and consent scope.
Where the record makes the difference. The verified exchange books the follow-up and carries the symptom report, retained by no one beyond the transaction.
Why it matters. Agent-to-agent traffic is coming to healthcare fast, and there is no trusted protocol for it. The governance layer is the protocol.
The hard problem. Consent verified between machines, with purpose limits that bind the receiving side.
The chart keeps the knee, not the divorce
Heard in the room, met with compassion in the moment, absent from the record forever.
A privacy officer types a rule in plain words: do not commit to the clinical record a disclosure about immigration status, a marital dispute, or financial hardship unless the clinician marks it clinically relevant. During a visit for knee pain, a patient mentions a pending divorce and a family member's immigration worry. The engine evaluates the words as they are spoken, recognizes they lack clinical relevance to the presenting complaint, and declines to commit them: they exist briefly in volatile memory and are discarded, while the knee-pain history and examination are documented in the ordinary course.
How privacy is protected. The divorce and the immigration worry live seconds in volatile memory and never reach the chart.
Where the record makes the difference. The knee history is documented fully, so care continues in the ordinary course.
Why it matters. Charts travel: to payers, to future providers, to litigation. What never enters the record can never leak from it.
The hard problem. Relevance judged in real time, as the words are spoken, with the clinician still able to restore anything material.
The clinician stays the author of the record
The system proposes an omission. The doctor decides.
When the system withholds a disclosure from a draft clinical note, it presents the clinician with a proposed omission before the record is finalized. The doctor reviews it and approves, or decides the disclosure bears on care after all, a marital stressor that is material to a depression screening, and restores it to the chart. The clinician remains the author of record, and the documentation-integrity duty, that no clinically material fact may be omitted, is preserved alongside the privacy policy.
How privacy is protected. Withholding is proposed, never silent, and the doctor can restore anything material to care.
Where the record makes the difference. The finalized note carries the clinician's authorship and an audit trail of every judgment.
Why it matters. Physicians will not accept a machine that silently edits their notes, and regulators will not accept records a machine curated unsupervised. Human authorship is the requirement, and this design keeps it.
The hard problem. Governance that proposes and defers, with the override as auditable as the rule.
One telehealth visit, three consent states
The doctor and patient are transcribed. The family member who declined never is.
An ambient documentation system joins a telehealth visit as a visible participant. The clinician and the patient have consented; a family member on the call has declined. The system recognizes each voice, determines each role, and selectively transcribes the clinician and the patient while never transcribing the family member. And if the patient joins from a state that requires everyone's consent, nothing is transcribed until every participant has agreed.
How privacy is protected. The family member who declined is never transcribed, and all-party states gate everyone.
Where the record makes the difference. The clinician-patient transcript becomes the visit documentation, gathered lawfully in real time.
Why it matters. Ambient clinical scribes are being deployed at enormous scale right now, mostly with none of this. The health systems buying them are inheriting the exposure.
The hard problem. Role and consent resolved per voice on an ordinary video call, before a word is written down.
Why this is hard, and why the best voice engineers are here
Every story above depends on the same three feats. First, the contradiction: the system cannot decide what is lawful to keep before understanding the audio, and it is forbidden from durably recording the audio before it decides, so judgment has to happen live, in a buffer measured in seconds. Second, attribution with no lookahead: knowing who is speaking, in overlap, on a phone line, in a crowded kitchen, before a word is written down, a problem perhaps a few dozen engineers in the world have shipped in production. Third, provable absence: not “we deleted it,” but “it was never written, and here is the signed evidence.” Solving those three, once, at the layer every device can share, is the work. If you want your engineering to be the reason a grandmother keeps her dignity and a hospital finally says yes, the door is on the next page.
See the open roles