Next week, I will present on this topic, and other privacy-related ideas, in the webinar “Deliberately Safeguarding Privacy and Confidentiality in the Age of AI.”
Tuesday, April 21st, 2026, 12:00 Mountain.
$99/person, special rates for groups available.
https://www.library20.com/ai-privacy
The article explains that privacy means more than just keeping secrets — it includes the right to be left alone, not be tracked, and not be misrepresented. Even incorrect data about a person can still harm their privacy.
It outlines a model of “privacy harms,” including physical, economic, reputational, discrimination, relationship, psychological, and autonomy harms. Many of these harms are hard to prove but can still cause real damage.
The author argues that AI harms privacy in two main ways: by removing privacy (collecting, selling, or repurposing data) and by intruding into daily life through surveillance and profiling.
Users often give up privacy without thinking, due to convenience, design choices, and treating AI like a human. This “commodification of privacy” makes full access to tools feel dependent on sharing personal data.
The solution is more deliberate, human-centered use of technology. The author suggests focusing on user control, clear terms of use, and privacy-conscious platforms like BoodleBox as alternatives to data-mining AI models.
Since early 2024, when I participated in the Digital Rhetorical Privacy Collective panel on generative AI and privacy, I have been intrigued by the impact of the actions that individual users have on their privacy, confidentiality, and data integrity.
As I write this, I am reading a post about a driver’s license that had the wrong Sex signifier, and the potential implications that could have on treatment and interactions with the mis-tagged person in society. This was a mistake made by a person, to be sure. However, that data was surely going to be scraped, or deliberately put into, a Digital Asset Management system (DAM) or database or some kind, where it would be accessed by other services or future queries in the same institution. The mistake would live on if it were not caught.
The point I am trying to make is, even if AI has the wrong data about us, any data about us is an invasion of our privacy.
This question has so many answers, it would be impossible to talk about them all in detail. Just some of the definitions of this term are:
The right to be left alone.
The right to not be known (more commonly known, thanks to the GDPR, as “the right to be forgotten,” or “the right to erasure”.
The right to not have to disclose something about oneself.
The right to not be discussed (this is a “definition” taken from the concept that even data that puts a person in a “false light” can be damaging to privacy).
With each of these definitions in mind, let us continue and see how these definitions can be transgressed by individuals, organizations, and, yes, technology.
One of the difficulties of publicly discussing privacy infringements, and holding those who harm our privacy responsible, is the fact that they are intangible. It is annoying when, as we like to say, “our phone is listening to us,” (really, the algorithm is tracking our actions and comparing them to other individual actions near us), but what actual harm is being done?
What about other instances, where are more genuinely hurt, but intangibly, by something someone has said, done, or pressured us to do, but there is no physical evidence of that? Courts have had a notoriously hard time holding bad actors responsible for many privacy violations, because there is no tangible evidence for these intrusions.
In 2021, Danielle Keats-Citron and Daniel Solove created a model of “privacy harms” that attempted to taxonomize not what privacy is (Solove did that beforehand), but how it can be violated. This is just as true for genAI tools, who work at the behest of human users, as it was for individuals and corporations five years ago. They group the possible ways for people or organizations to harm others into:
physical harms: very obviously, any occurrence or action that can lead to physical injury or death. This not only includes positive injuries (harmful things happening) but also negative injuries (helpful things not happening).
economic harms: monetary or other financial losses occurring from a loss of privacy. Obvious cases are identity theft, but data breaches or organizations creating profiles from personally-identifiable data, and then selling those profiles for other uses, could also be considered economic harm. One example of this, which was not found in the plaintiffs’ favor, is Dwyer v. American Express Co.
reputational harms: This is especially relevant to the last- discussed (and most often overlooked) definition of privacy above. Even if the “personal data” shared about a person is not true, or is shared out of context (which is mal-information, if you remember our misinformation post), it can irrevocably damage other’s opinions about the victim, who either may not hear any retraction, or may not believe the retraction when they hear it.
discrimination harms: The Daodejing has a caution that I think should be the mantra for most metadata practitioners: “first, we name; then, we describe; then, we set one first (and) another last. As soon as we finish naming, it is time to stop.” One way of thinking about this is, the more categories we create for people, things, and events, the more reasons we have to create or circumscribe those categories. There will always be “proper” and “improper” ways to interact or act on certain categories of information, and so metadata can enshrine discriminatory and unethical presuppositions and practices just by its inclusion. Of course, the ethical person will control for those and not make decisions based on metadata alone. However, we cannot count on everyone being ethical. This is just one way that data-related privacy infringement can result in discrimination.
relationship harms: This is somewhat related to the “discrimination” and “reputational” harms sections above. If strangers will react to data unscrupulously and/or fabricated data, then the people closest to the victim may change how they interact with the victim as well.
psychological harms: Simply knowing that one’s privacy has been breached can be traumatic, but if one knows that certain details about one’s life has been discussed (even if true or not), the psychological harms can compound. These harms can range from mere irritation to the most aggressive form of physical harms against oneself.
autonomy harms: This category somewhat blends into the last one. One of the main types of psychological harms, according to Keats-Citron and Solove, is “disturbance,” or intrusion of the aggressor into the life, thoughts, or behaviors of the victim. If this happens consistently, or if it feared that this will happen consistently, the person could significantly change how they do, or what they do, in order to avoid any further harms related to the privacy violation. Other autonomy harms of more direct, such as requiring privacy collections as a term of service or access (we will talk about how consumers make this fun below!).
Now that we know the different types of harms, how does it harm our privacy? As you read below, think of ways that AI has done either of the two actions below, and how those might map onto the “privacy harms” model above.
Any technology inherently involves using personal data, from activating your phone, to going onto Google Maps, to playing music on Spotify or YouTube. This data is either voluntarily handed to the technology (through user registration, or accepting cookies,) or is extrapolated by the provider through browser and window tracking, or comparable strategies for other interfaces. In either way, there are two main ways that technology providers, including AI providers, either misuse your data, gain more data (even if anonymized), or transfer your data for profit.
This can happen in several ways. When AI tools harvest user prompts, conversations, and uploaded documents without explicit informed consent, they are appropriating that data, placing it out of context, and ofttimes build user profiles (even if anonymized). Initially, for example, OpenAI’s ChatGPT chatbots were creating data-harvested psychographic profiles on each user to improve its performance for those users. Now, it sells those profiles (non-consented disclosure) and/or uses it to optimize ads (appropriation), in either way enriching third parties.
Further actions happen to that data, which can distort even correct data and information so it appears in a non-benign context or nuance. For instance, user prompts could become fragmented and repurposed in ways the user never intended.
For a discussion on how Facebook and YouTube commit this version of privacy violation every second, see those sections in the post below.
AI in Preexisting Web Services
·
May 28, 2025
In November 2022, when ChatGPT was released, the whole world acted like the field of artificial intelligence had never existed until that moment—we all hovered around our computers and asked LLMs all types of questions—and feared that the entire field of writing was going to be changed forever.
This occurs when a technology inescapably enters into a person’s personal life, thoughts, and decisions without their control. One excellent piece of technology that does this is the automated home assistant, either Amazon Alexa or Google Home. How many times have you had a conversation, and the Google Home chimes in unexpectedly, or how many times have you asked your Google Home a question that 1. you could have searched for yourself, or 2. you did not need to know? In either case, the automated assistant became such an integral part of your life that you asked it a question without a second thought, or you discounted the interruption as “a normal part of having technology.”
Google Home and Amazon Alexa are audial AI tools, and these intrusions are just some of the ways that technology has invaded our lives. When AI tools track not just what users say but how they say it, when they say it, and what patterns emerge across multiple interactions, they engage in surveillance that extends far beyond traditional monitoring. This surveillance enables providers to construct detailed psychological and behavioral profiles that users never explicitly authorized. The framework's concept of interrogation becomes particularly relevant when AI systems prompt users for increasingly personal information under the guise of providing better service or more personalized responses. Users may feel compelled to share intimate details to receive adequate assistance, creating a coercive dynamic where privacy erosion becomes the price of functionality. Additionally, AI's capacity for identification—linking anonymized data back to specific individuals through pattern recognition and cross-referencing—means that even ostensibly private or anonymous interactions can be traced back to their source. The intrusive nature of AI extends to its ability to make inferences about aspects of users' lives they never explicitly shared, drawing conclusions about political beliefs, health conditions, financial situations, or personal relationships based on indirect signals. This represents a form of privacy violation that traditional frameworks struggle to address, as the harm occurs not through direct data theft but through algorithmic inference and prediction that users cannot easily detect, contest, or control.
There are many discussions in public discourse of why companies and organizations commit data privacy violations or allow them to happen: greed, optimization of products or services, contracts with other providers or entities, over-compliance with regulations, and on and on. But, why do we as users allow this to happen? Why do we not think through the implications of our interactions with technology? Neal Postman, in his TECHNOPOLY, says that this is in part because technology was designed to not invite critical discussions of its side effects and assumptions. For a more thorough examination of this book, which I believe should be on every AI user’s shelf, read the article below.
Now, I want to talk about two ways that we fall into the trap of not critically thinking about our technology interactions.
This is a term, to be clear, that I made up one day as I was driving to pick up a table I bought on Facebook Marketplace, listening to the excellent TV show Wings and drinking Diet A&W. There is nothing special about it, and there is probably someone more eloquent than I am who has talked about this. However, I have not seen any discourse about it, and it shocked me. I will probably do another post or a webinar about it.
The “commodification of privacy” occurs when a technology provider, or an AI tool, makes full functionality conditional upon giving up any or all personal data, whether it is location or age, or address, or any other personal data point. Obviously, there are some instances in which personal data might be necessary, such as personalization of health tracking and management applications. However, even these systems may ask for more than they need, all so they can have higher functionality.
This is most plainly seen in Google Maps. You cannot have full functionality of Google Maps (in other words, “use it like you would a GPS”), unless you give Google Maps constant location access. Many of us (myself included) turn this on and do not think twice. However, the location tracking occurs even when we are not using the app, unless we have turned it off or restricted those permissions.
In terms of AI tools, this appears in “we will allow you temporary chats, or un-logged chats, but that means you will never be able to refer to these chats again.” Even if this feature did not exist, previous technologies and their providers have conditioned us to give up our personal data so easily that we might give it up anyway. This conditioning is compounded by another aspect of AI that takes advantage of our psychological makeup.
Another factor in this decision, which I have talked about in multiple previous posts, is “artificial agency,” or what others have called “pseudanthropy,” or “faux humanity,” is our tendency to interact with AI tools the same way that we would interact with other human beings. This bewrays a tendency, whether conscious or unconscious, to think of these tools as humans, entities with intentionality, feelings, empathy, goals, emotions, and other human-like traits. As I mentioned in my post on this subject, which you can read below, we tend to skip straight to the center of the social penetration onion when we interact with AI tools, whereas even our closest human friends took months to reach that level of dialogical intimacy.
Although we are human, and fallible, and are prone to fall victim to tricks such as those above, there is still hope. As Father says in Paradise Lost, “within [humanity itself] the danger lies, yet within [their] power.” As I talked about in my session on “Learning about AI through Science Fiction,” the solution to an increasing machine-centered world is ensuring that our actions are human-centered.
Three years ago, Sean Falconer opined that, compared to “opt out” policies for data-tracking entities, AI had “no delete button.” Now, of course, most AI providers have a Privacy policy and one or more opt-out methods, from temporary chats to a general form.
However, Falconer’s comment on this was a bit amiss in my view. Even with delete buttons, there was no way to remove the data provided to companies who had already harvested some data. Furthermore, if they had already sold that data in profile or in aggregate, there was no way to un-sell that. The data was already out in the marketplace.
Furthermore, and this has become more explicit since the deliberate privacy actions have been made available, we are not only responsible for our own data in our prompts. Just because our data is not tracked does not mean that others’ data is safe. We could put other peoples’ data into our prompts, which makes us culpable for that violation unless the AI tool is secured. Informed consent from students, patrons, and any other agents or stakeholders is a must.
This action is a call again automation and for more deliberate interactions. We must address each objective, project, and prompt one by one. The more we rely on AI agents, or multi-step un-monitored processes, the more likely we are potentially “authorizing” through our prompts the violation of other’s privacy.
One of the most harmful trends I have seen on both ends of the “hype vs. anti-hype” AI discourse is the conglomeration and conflation of various terms, ideas, uses, and offerings. As a librarian, and archivist, who is particularly concerned with metadata and its use in defining and cataloging information resources, the terms we use must be precise. The end conclusion of this thought is that we are not trying to fight against all AI. Even those who are anti-hype anti-AI create presentations that incorporate Microsoft Designer, which is an AI tool. This illustrates a disconnect between our terms and philosophies, how we think about technology, and our actual practice, how we interact with technology.
We should be focusing on our identity as users, as individuals, vs. data-mining Terms of Use. It is possible to have functional AI conversations, and create AI-human artifacts, without relinquishing our privacy and autonomy. To be clear, a mindset like this requires a commitment to avoiding automation (to which privacy-relinquishment related to AI appears to be inextricably linked). We must use tools in a way in which we are in control of the process, product, and everything in between. This includes “conversation steering” and “objective-focused” interactions.
For an older examination of some of these issues, see the article below.
For a newer take on these ideas, see the post below.
Do We "Bring the Human" to Human-AI Machine Interactions?
·
August 19, 2025
I came across the above image in an email that was sent to me from Harvard Business Review, but it originated in this blog post on the HBR website. Lest we think that HBR is plagiarizing, the author of the post is also the founder of filtered.com . In this post, I am going to combine insights from my own experience as well as the results of the HBR surv…
I have talked about BoodleBox as a privacy solution before in detail, so I will put that link below.
However, the tool is worth briefly considering in the context of the issues brought up in this article.
The commodification of privacy and the intrusive nature of most generative AI tools create significant barriers to ethical AI adoption in education and professional settings. However, not all AI platforms operate under the same data-mining business model that has become standard in the industry. BoodleBox represents a fundamentally different approach to AI tool design, one that prioritizes user privacy and data security while maintaining full functionality. This platform demonstrates that the false choice between “full functionality with privacy violation” or “limited functionality with privacy protection” is not inevitable, but rather a consequence of business decisions that prioritize profit over user welfare.
BoodleBox addresses both privacy removal and privacy intrusion through multiple technical and organizational measures. Regarding privacy removal, BoodleBox has implemented what they term “context optimization technology,” which reduces token transmission to AI model providers by up to 96%. This means that even before anonymization occurs, the vast majority of user data never leaves BoodleBox’s secure environment.
Furthermore, BoodleBox accesses all AI models exclusively through Enterprise API accounts that contractually prohibit model training on user data. The platform’s FERPA, HIPAA, GDPR, and SOC2 Type II compliance certifications provide external verification of these practices, demonstrating that BoodleBox’s privacy protections have been audited and validated by both governmental and private entities. When a federal judge ordered ChatGPT to surrender all user chats to the federal government in June 2025, BoodleBox users were completely protected because the platform’s Enterprise API accounts were specifically excluded from the preservation order, and because all prompts had been anonymized before reaching model providers in the first place.
Regarding privacy intrusion, BoodleBox’s architecture prevents the surveillance and interrogation harms that characterize most AI tools. The platform practices “Least Privilege Access” at both micro and macro levels, meaning that if an employee or the organization itself does not absolutely need an aspect of user data to provide service, they do not have access to it. BoodleBox collects only username, password, email address, payment information, platform usage statistics, and information voluntarily provided in formal surveys. This stands in stark contrast to tools like Google Home or Amazon Alexa, which continuously monitor user behavior to construct detailed psychological profiles. The platform’s encryption both in transit and at rest, combined with regular security audits and penetration testing, ensures that uploaded documents remain confidential and cannot be accessed by unauthorized parties. BoodleBox’s anonymization and parsing processes prevent model providers from linking data back to specific individuals through pattern recognition or cross-referencing.
The commodification of privacy and the intrusive nature of most AI tools need not be inevitable features of generative AI adoption. As we center our interactions with AI around ourselves, focus on our objectives, and control our impulses when it comes to “communicating” with AI, we will not have our privacy removed or intruded upon.
Next week, I will present on this topic, and other privacy-related ideas, in the webinar “Deliberately Safeguarding Privacy and Confidentiality in the Age of AI.”
Tuesday, April 21st, 2026, 12:00 Mountain.
$99/person, special rates for groups available.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.