L6.06.2inference as disclosuredesignresearch

Displaying an inference is itself a disclosure

Aliases: inferred label display · naming the estimate · exposing inferred identity

What it is

“We think you are preparing for a child” on the home screen, in an ad reason, or on a profile page is itself the act of turning an internal estimate into a visible fact. Inference as disclosure means: showing the inferred result tells the user — and anyone who can see that screen — an identity they may never have agreed to have spoken.

Before display, the harm is silent estimation. After display, there is another layer: being named.

Why it happens

An internal tag can be wrong, stale, or used only for ranking, and the user may never notice. Written as copy or a channel, the tag gets a social life: the person has to answer it, deny it, or be read by whoever is standing beside them. Recommendation reasons, interest chips, and notification copy are common disclosure surfaces — built for explainability, they speak an attribute that was never offered.

Disclosure does not rewind. Even if the user taps “not this,” whoever saw it has seen it, and the log still holds “was once shown as X.” So “show it so they can correct it” is not free transparency. It completes a publication first.

A third party seeing it on a shared screen is the same mechanism extended in space. Here the nail is: for the user themselves, display is already disclosure.

Studying it

Put the same inference in three places: fully backstage, visible in ranking but unnamed (only matching content), named in a sentence. Measure surprise, shame, willingness to keep using, attempts to correct. Independent variables: specificity of the name (“health” vs “preparing for a child”), placement (reason line / profile / notification). Dependent variables: felt exposure, intent to correct, intent to continue.

A rise in correction rate is not success on its own. Naming can raise correction and harm together. Report “corrected because it was spoken” separately from “hurt because it was spoken.”

Where it stops holding

Redisplaying a field the user just typed is echo, not inference-as-disclosure. A creator profile whose content already states an identity is out of scope. Legally required notices (“we use automated decisions”) can omit the specific sensitive value. This entry only treats writing an estimate as a visible identity. It does not treat whether sensitive classes should be estimated, and it does not treat whether the misclassified have an appeal.

Applying it

  • By default, do not write inferred attributes as tags, reasons, or channel names. Let content speak; do not let identity speak.
  • If display is required for correction, stay at a neutral behavioural description (“because you recently searched prams”), and do not upgrade it to an identity (“expectant parent”).
  • Check: walk every reason and profile line about to ship, and mark every identity word the user did not type. Each mark is a disclosure and needs its own keep-or-cut decision.

Related

  • Same group: L6.06.1 Behavioural inference can reach information the user never disclosed · L6.06.3 Inferences in sensitive categories need extra constraints · L6.06.4 Combinations of non-sensitive behaviours can yield sensitive attributes; item-wise compliance is not whole-system compliance · L6.06.5 Inferences on shared devices and shared screens disclose to third parties · L6.06.6 Wrong inferences also harm, and the misclassified often have nowhere to appeal · L6.06.7 Tolerance for inference depends on the setting; the same inference is judged differently across products · L6.06.8 Opting out of inference and opting out of data collection are different controls
  • Nearby: L6.07 Presenting Recommendation Reasons · L6.01 Recommendation Reasons · L5.05 The Moderation Principle of Transparency
  • Search terms: inference as disclosure · inferred label display · exposing inferred identity

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/L6.06.2