Privacy pipeline
Every face blurred automatically, before the footage ever ships.
- Detects
- Faces · plates · screens · speech
- Redaction
- Irreversible, pixel-level
- Confirmed by
- 100% human review
- Recorded
- Per episode, in the data card
Illustrative synthetic frame. Toggle Raw source to see the detector input that stays internal, and Anonymized output — the only version delivered. Bounding boxes mark each detected region; the blur is baked into the pixels that ship.
On real footage
How computer vision detects a face, boxes it, and blurs it.
The synthetic viewer above shows the whole scene at once. Here is the same two-stage pass on an actual first-person frame — detection, then irreversible blur.
face · 0.80Stage one — detect. A vision model runs over each frame and returns, for every face it finds, four numbers — the bounding-box coordinates (x, y, width, height)— and a confidence score between 0 and 1. In the frame on the left the rider's face comes back as a single box at face · 0.80. The model looks for a face regardless of orientation, so a head turned, tilted, or seen through a fisheye lens is still found.
Stage two — track and blur. Across a video those per-frame boxes are linked into a single track, so the region stays covered while the subject moves, turns away, or motion-blurs — not only on the frames where they face the camera. Each tracked box is then blurred directly into the output pixels. Toggle the figure to see the delivered result: the face is gone, and the hands, the scene, and the point of view are untouched.
Detection is never the guarantee on its own — a model has a miss rate, and a missed face is a leaked identity. That is why every clip is confirmed by a human and recorded per file, and why a frame the reviewer is unsure about is dropped rather than shipped.
Want this run on your own footage rather than ours? It is available as anonymization as a service — see the face-blurring service and the step-by-step how to blur faces in video guide.
How it works
Five steps, run on every episode.
The pass is automatic, but a human signs off before anything clears. Detection alone is not the guarantee — the review is.
- 1 · Detect
- A vision model runs on every frame at ingest, flagging faces, heads, licence plates and any legible screen or document.
- 2 · Track
- Detections are linked across frames so a face that turns away, blurs in motion, or leaves and re-enters stays covered for the whole clip.
- 3 · Redact
- Each region is irreversibly blurred in the pixel data — not masked with metadata that a downstream user could switch off.
- 4 · Review
- A human reviewer scrubs the episode and confirms no un-consented person is identifiable in any frame before it is cleared.
- 5 · Certify
- The de-identification pass and reviewer sign-off are recorded against the episode ID in the batch data card.
What gets scrubbed
Not just forward-facing faces.
The guarantees
What makes it trustworthy.
Automatic blurring is common. What matters is whether it is reversible, whether it fails safely, and whether you can prove it happened.
- Irreversible
- Blur is baked into the delivered pixels. There is no un-blurred master shipped alongside and no key to reverse it.
- Consented subjects exempt
- The operator and anyone who signed a release stay in frame — anonymization targets un-consented third parties, not your training signal.
- Fails closed
- If the reviewer is unsure a region is fully covered, the episode is held or discarded, never downgraded and shipped.
- Auditable
- Every episode carries the detector version, pass timestamp and reviewer ID, so the claim is checkable per file.
Anonymization is one checkpoint in a longer consent chain. See the full provenance and consent pipeline for the release language and the six checkpoints every episode passes.
Why we built it
Consent you can hand to counsel.
Egocentric capture happens in real homes, workplaces and semi-public spaces, so bystanders end up in frame. The honest answer is not to pretend they do not — it is to remove them before anyone downstream ever sees the footage. That is what this pass does, on every episode, by default.
It is the same discipline CloudPano has applied to spatial data collection for years: capture at scale, but treat the people in the scene as something to protect rather than something to ship. The result is a dataset your legal team can clear and your researchers can still train on.
Scope a capture with anonymization built in.
Every batch we deliver runs this pass by default. Bring your spec and we will show you a real data card, with the de-identification record per episode.