Privacy pipeline

Every face blurred automatically, before the footage ever ships.

Un-consented people, plates and screens are detected and irreversibly redacted at ingest, then confirmed by a human reviewer. You train on the hands, objects and point of view — never on someone who never agreed to be there.
Detects
Faces · plates · screens · speech
Redaction
Irreversible, pixel-level
Confirmed by
100% human review
Recorded
Per episode, in the data card
What ships to you
RV·1842face · 0.99 · scrubbedface · 0.97 · scrubbedscreen · 0.98 · scrubbedplate · 0.96 · scrubbedDE-IDENTIFIEDINGEST · auto-scrub4 regions · 2 faces · 1 screen · 1 plate0 identities retained

Illustrative synthetic frame. Toggle Raw source to see the detector input that stays internal, and Anonymized output — the only version delivered. Bounding boxes mark each detected region; the blur is baked into the pixels that ship.

On real footage

How computer vision detects a face, boxes it, and blurs it.

The synthetic viewer above shows the whole scene at once. Here is the same two-stage pass on an actual first-person frame — detection, then irreversible blur.

Bounding box + confidence · internal
A first-person cycling frame with a green bounding box labelled face 0.80 drawn around the rider’s detected face.face · 0.80
Stage one. A vision model scans the frame and returns a bounding box around every face, with a confidence score. Nothing is altered yet — this labelled view stays internal.

Stage one — detect. A vision model runs over each frame and returns, for every face it finds, four numbers — the bounding-box coordinates (x, y, width, height)— and a confidence score between 0 and 1. In the frame on the left the rider's face comes back as a single box at face · 0.80. The model looks for a face regardless of orientation, so a head turned, tilted, or seen through a fisheye lens is still found.

Stage two — track and blur. Across a video those per-frame boxes are linked into a single track, so the region stays covered while the subject moves, turns away, or motion-blurs — not only on the frames where they face the camera. Each tracked box is then blurred directly into the output pixels. Toggle the figure to see the delivered result: the face is gone, and the hands, the scene, and the point of view are untouched.

Detection is never the guarantee on its own — a model has a miss rate, and a missed face is a leaked identity. That is why every clip is confirmed by a human and recorded per file, and why a frame the reviewer is unsure about is dropped rather than shipped.

Want this run on your own footage rather than ours? It is available as anonymization as a service — see the face-blurring service and the step-by-step how to blur faces in video guide.

How it works

Five steps, run on every episode.

The pass is automatic, but a human signs off before anything clears. Detection alone is not the guarantee — the review is.

1 · Detect
A vision model runs on every frame at ingest, flagging faces, heads, licence plates and any legible screen or document.
2 · Track
Detections are linked across frames so a face that turns away, blurs in motion, or leaves and re-enters stays covered for the whole clip.
3 · Redact
Each region is irreversibly blurred in the pixel data — not masked with metadata that a downstream user could switch off.
4 · Review
A human reviewer scrubs the episode and confirms no un-consented person is identifiable in any frame before it is cleared.
5 · Certify
The de-identification pass and reviewer sign-off are recorded against the episode ID in the batch data card.

What gets scrubbed

Not just forward-facing faces.

Faces & headsBystanders, reflections, and partially occluded or profile faces — not just forward-facing detections.
Licence platesVehicle plates visible through windows, doorways, or in outdoor and automotive captures.
Screens & documentsPhone and monitor content, forms, badges and mail that would leak names, addresses or account data.
Spoken identifiersNames, addresses and numbers in any audio track are scrubbed from the transcript and muted in the waveform.

The guarantees

What makes it trustworthy.

Automatic blurring is common. What matters is whether it is reversible, whether it fails safely, and whether you can prove it happened.

Irreversible
Blur is baked into the delivered pixels. There is no un-blurred master shipped alongside and no key to reverse it.
Consented subjects exempt
The operator and anyone who signed a release stay in frame — anonymization targets un-consented third parties, not your training signal.
Fails closed
If the reviewer is unsure a region is fully covered, the episode is held or discarded, never downgraded and shipped.
Auditable
Every episode carries the detector version, pass timestamp and reviewer ID, so the claim is checkable per file.

Anonymization is one checkpoint in a longer consent chain. See the full provenance and consent pipeline for the release language and the six checkpoints every episode passes.

Why we built it

Consent you can hand to counsel.

Egocentric capture happens in real homes, workplaces and semi-public spaces, so bystanders end up in frame. The honest answer is not to pretend they do not — it is to remove them before anyone downstream ever sees the footage. That is what this pass does, on every episode, by default.

It is the same discipline CloudPano has applied to spatial data collection for years: capture at scale, but treat the people in the scene as something to protect rather than something to ship. The result is a dataset your legal team can clear and your researchers can still train on.

Scope a capture with anonymization built in.

Every batch we deliver runs this pass by default. Bring your spec and we will show you a real data card, with the de-identification record per episode.