Essay

A camera company has

to answer this first.

If you build software, nobody opens your website wondering whether you are following them. If you put cameras on hundreds of thousands of vehicles moving through public space, that is the first thing a thoughtful person wonders, and every sentence you write about your product is read through it.

Most companies in this position respond by writing a policy, filing it in the footer, and getting on with the marketing. We think that is a category error. The question is not a legal formality to be discharged. It is the central question about what kind of company this is.

The category has a record

This suspicion has been earned, and not by us alone.

Road camera networks originally deployed for stolen-vehicle recovery have been used to follow people who were not suspected of any crime, including by individual officers acting on personal motives. Location datasets gathered for advertising have been resold to buyers whose purposes the people generating the data would never have agreed to. Systems sold to municipalities as safety infrastructure have quietly acquired capabilities nobody voted on.

In most of these cases nothing was breached and nobody was hacked. The systems worked exactly as designed. The design permitted a use nobody had thought hard enough about.

The failure was not security. It was that a capability existed, and eventually somebody asked to use it.

What follows from taking that seriously

If you accept that the risk is capability rather than intent, three things follow, and they are inconvenient.

You have to give up revenue you could have had. Plate recognition is commercially valuable and technically straightforward. So is person-level search. We do not build either, which forecloses real business. That is what the commitment costs, and a commitment that costs nothing is not one.

You have to write down what you refuse, not only what you do. A list of things a company does is marketing. A list of things it will not do, published where customers and regulators can hold you to it, is a constraint. The second list is the useful one and it is the one almost nobody publishes.

You have to make the architecture checkable. Anyone can promise restraint. Far fewer will state exactly what their system is incapable of and invite an independent party to verify it. A guarantee you can test beats a policy you have to trust.

Why it is in the navigation

Footers are where things go to be technically available. A buyer in a public body has to be able to defend their supplier in a council meeting. A fleet safety director has to answer a works council. A driver has to be able to find out what is recorded about them without reading a contract they never signed.

None of those people should have to scroll to the bottom of a marketing site to find the answer, so the answer sits between the products and the company, in the navigation, where it is the fourth thing you see.

The standard we would like to be held to

Not “we take your privacy seriously.” Everyone says that, including the companies in the paragraph above, and it has been drained of meaning.

The standard is narrower and checkable: can an informed critic read our privacy pages and find a specific claim that turns out not to be true? If they can, we have failed, and we would rather find out from them than from a journalist.