Emotuit processes engagement signals client-side wherever possible and transmits numerical scores only — never images or video. In Signals configuration no biometric data is processed at all. Content-level analytics can run with no personally identifiable information, and the entire pipeline can be deployed on-premise or air-gapped with zero external dependencies.
Architecture at a glance
Emotuit is designed around one principle: compute as close to the learner as possible, transmit as little as possible.
| Stage | Where it runs | What it produces |
|---|---|---|
| Behavioural capture | Learner's browser | Browser events — visibility, focus, dwell, scroll |
| Face detection (Learn only) | Learner's browser | Bounding box and landmarks — never transmitted |
| Emotion classification (Learn only) | Learner's browser | 7-value probability vector |
| Baseline calibration | Learner's browser | Deviation scores |
| Engagement scoring | Browser or backend | Engagement index, 0–1 |
| Content correlation | Backend | Per-section aggregate |
| Reporting | Dashboard | Content-level heatmaps |
The two rows marked Learn only do not exist in the Signals configuration. There is no camera access, no biometric processing, and no emotion inference anywhere in the pipeline.
What data is processed
Always:
- Browser visibility and focus state changes
- Dwell time per content section
- Scroll depth and velocity
- Interaction events and response latency
- Session start, end and abandonment point
- Content position identifiers — which slide, section or module
Only in Learn configuration, and only client-side:
- Webcam frames, processed in-browser and immediately discarded
- Facial landmark coordinates, held in memory only
- Emotion probability vectors, reduced to a numerical engagement contribution
Optional, and off by default:
- Learner identifiers, where you need per-person reporting rather than content-level
What never leaves the device
Webcam frames · video · still images · facial landmark coordinates · face embeddings or templates · biometric identifiers of any kind · audio.
Frames are processed in a canvas buffer and discarded on the next tick. There is no code path that uploads an image, because there is no endpoint that accepts one.
Deployment models
| Model | Where data lives | Sub-processors | Best for |
|---|---|---|---|
| Hosted | Our infrastructure, EU region | Listed in DPIA pack | Most commercial deployments |
| Self-hosted | Your infrastructure | None | Regulated industries, strict data residency |
| Air-gapped | Your infrastructure, no external network | None | Government, defence, classified environments |
In self-hosted and air-gapped models, nothing leaves your network. Models are bundled with the SDK rather than fetched from a CDN, so there are no third-party requests at runtime.
Retention and deletion
- Raw event data — retained for the configured window, default 90 days, then deleted
- Aggregated content-level data — retained indefinitely by default; contains no personal data in anonymous mode
- Per-learner baselines — held within your tenancy, deleted on account deletion
- Deletion requests — actioned within 30 days; aggregate content data survives because it contains no personal data
Retention windows are configurable. If your policy says 30 days, set it to 30 days.
Compliance position
GDPR. Behavioural telemetry is ordinary personal data where it is linked to an identifiable person, and not personal data at all in anonymous mode. In Learn configuration, biometric data is processed on-device but never transmitted, which materially narrows the processing footprint. You will need a lawful basis and a DPIA for systematic monitoring either way.
EU AI Act. Article 5(1)(f) prohibits AI systems that infer emotions from biometric data in workplace and education contexts.
- Signals processes no biometric data and infers no emotional state, and is designed to sit outside the prohibition.
- Learn infers emotional states from biometric data and should not be deployed in EU workplace or education settings. It is intended for market research, UX and media testing, and other contexts outside Article 5(1)(f).
We will provide our written position for your specific configuration and deployment context as part of the DPIA pack.
We give you a documented vendor position and the underlying architecture so your own counsel can reach their own conclusion. We do not ask you to take a compliance claim on trust, and you should not accept one from any vendor in this category.
Other frameworks. The architecture is designed to be compatible with COPPA requirements, institutional data governance policies, and public sector data handling standards. Air-gapped deployment addresses most residency and sovereignty requirements directly.
For your DPIA
The pack we send includes:
- Completed supplier assessment section
- Data-flow diagrams for your deployment model
- Full field-level data inventory
- Sub-processor list with locations and transfer mechanisms
- Retention schedule
- Our written EU AI Act Article 5(1)(f) analysis for your configuration
- Security architecture summary
- Incident response and breach notification process
It is included in the engagement rather than billed as professional services, and turnaround is usually two working days. Request it here.
Frequently asked questions
Are facial images ever transmitted or stored?
Can Emotuit run without processing personal data?
Can it run in an air-gapped environment?
Who are your sub-processors?
Do you use customer data to train models?
Need the full DPIA pack?
Supplier assessment, data-flow diagrams, sub-processor list and our written Article 5 position. Usually within two working days.