Open product module
Anonymization and privacy
A boundary that decides what may leave a private session and how content is reduced before reuse.
Why it exists
Privacy is a product rule, not a cosmetic label. This module keeps personal decision content separate from any consented, anonymized learning signal.
Inputs and outputs
Inputs
- Explicit consent state
- Private session or account data
- The permitted transformation boundary
Outputs
- A redacted or anonymized record
- A rejection reason when safety is uncertain
- A deletion/export boundary for the person
Visual flow
- Check consent
- Classify the data boundary
- Remove or generalise identifying content
- Reject unsafe material
- Keep rights and deletion paths intact
Practical example
Situation
A user wants to allow product learning but keep their decision private.
Result
The boundary stores only a consented, reduced signal and keeps the original chain in the private account boundary.
Limitations
- Anonymization is not a promise of perfect irreversibility.
- No consent means no dataset collection.
- The public page never contains real user examples.
Open and closed boundary
Open here
The distinction between private, anonymized, and rejected data is public.
Kept private
Raw sessions, private identifiers, and production transformation heuristics never belong in the atlas.