Security and data handling

Written for the people who have to sign this off. If something you need isn't here, ask and we'll send it.

In short

Emotuit processes engagement signals client-side wherever possible and transmits numerical scores only — never images or video. In Signals configuration no biometric data is processed at all. Content-level analytics can run with no personally identifiable information, and the entire pipeline can be deployed on-premise or air-gapped with zero external dependencies.

Architecture at a glance

Emotuit is designed around one principle: compute as close to the learner as possible, transmit as little as possible.

Stage Where it runs What it produces
Behavioural capture Learner's browser Browser events — visibility, focus, dwell, scroll
Face detection (Learn only) Learner's browser Bounding box and landmarks — never transmitted
Emotion classification (Learn only) Learner's browser 7-value probability vector
Baseline calibration Learner's browser Deviation scores
Engagement scoring Browser or backend Engagement index, 0–1
Content correlation Backend Per-section aggregate
Reporting Dashboard Content-level heatmaps

The two rows marked Learn only do not exist in the Signals configuration. There is no camera access, no biometric processing, and no emotion inference anywhere in the pipeline.

What data is processed

Always:

Only in Learn configuration, and only client-side:

Optional, and off by default:

What never leaves the device

Never transmitted, never stored, under any configuration

Webcam frames · video · still images · facial landmark coordinates · face embeddings or templates · biometric identifiers of any kind · audio.

Frames are processed in a canvas buffer and discarded on the next tick. There is no code path that uploads an image, because there is no endpoint that accepts one.

Deployment models

Model Where data lives Sub-processors Best for
Hosted Our infrastructure, EU region Listed in DPIA pack Most commercial deployments
Self-hosted Your infrastructure None Regulated industries, strict data residency
Air-gapped Your infrastructure, no external network None Government, defence, classified environments

In self-hosted and air-gapped models, nothing leaves your network. Models are bundled with the SDK rather than fetched from a CDN, so there are no third-party requests at runtime.

Retention and deletion

Retention windows are configurable. If your policy says 30 days, set it to 30 days.

Compliance position

GDPR. Behavioural telemetry is ordinary personal data where it is linked to an identifiable person, and not personal data at all in anonymous mode. In Learn configuration, biometric data is processed on-device but never transmitted, which materially narrows the processing footprint. You will need a lawful basis and a DPIA for systematic monitoring either way.

EU AI Act. Article 5(1)(f) prohibits AI systems that infer emotions from biometric data in workplace and education contexts.

We will provide our written position for your specific configuration and deployment context as part of the DPIA pack.

Other frameworks. The architecture is designed to be compatible with COPPA requirements, institutional data governance policies, and public sector data handling standards. Air-gapped deployment addresses most residency and sovereignty requirements directly.

For your DPIA

The pack we send includes:

  1. Completed supplier assessment section
  2. Data-flow diagrams for your deployment model
  3. Full field-level data inventory
  4. Sub-processor list with locations and transfer mechanisms
  5. Retention schedule
  6. Our written EU AI Act Article 5(1)(f) analysis for your configuration
  7. Security architecture summary
  8. Incident response and breach notification process

It is included in the engagement rather than billed as professional services, and turnaround is usually two working days. Request it here.

Frequently asked questions

Are facial images ever transmitted or stored?
No. In the Learn configuration, face detection and emotion classification run entirely client-side via TensorFlow.js or ONNX Runtime Web. Only numerical scores leave the device. In the Signals configuration there is no camera access at all. At no point are images or video transmitted or stored.
Can Emotuit run without processing personal data?
Yes. In anonymous mode, data is aggregated to content level at the point of collection — no session identifiers linked to individuals, no user IDs. You get section-level engagement data with no personal data processed, which takes most of the GDPR analysis off the table.
Can it run in an air-gapped environment?
Yes. The pipeline has zero external network dependencies. Models are bundled, inference is local, and the analytics backend can be self-hosted. This is what makes it deployable in government, defence and regulated environments where cloud services are not permitted.
Who are your sub-processors?
This depends on your deployment model, and the full list forms part of the DPIA pack. In a self-hosted or air-gapped deployment there are no sub-processors, because nothing leaves your infrastructure.
Do you use customer data to train models?
No. Customer engagement data is not used to train or improve models across accounts. Where per-learner baselines are calculated, they are calculated within your tenancy and stay there.

Need the full DPIA pack?

Supplier assessment, data-flow diagrams, sub-processor list and our written Article 5 position. Usually within two working days.

Request the pack
Get Started

See what completion rates can't tell you

Find out exactly where your content works, where it fails, and what disengagement looks like before people leave.

Request a Demo