Skip to content

Release · S318–S318

Deciding what counts as your data, by looking at the data instead of at the labels

To hand someone a copy of everything held about them, you first have to decide, for every place data is kept, whether it holds anything about a person. The way that decision was being made was by reading the NAMES of the fields — does this look like it holds someone's identifier? That approach had already been tried here years ago on a closely related question, and it had leaked: a name list only catches the names you thought of, and the next thing someone writes gets a name nobody guessed. You can tell it is happening because the answer will not sit still — it moved between six and twenty-eight across four attempts, depending only on which words were in the list. So the question is now asked of the values themselves, using the same rule the rest of the system already uses to decide what must never be published. That rule can only see what is actually stored, and nothing has been stored here yet, so almost nothing can honestly be decided today: one hundred and forty-seven of one hundred and sixty-four places are recorded as undecided, and undecided blocks the export rather than quietly allowing it. Seventeen are already settled, because this project long ago wrote down which collections hold raw identities. The refusal to build the export is now published on the health endpoint with the exact count behind it, so it stops being a note in a file and becomes something the running site says out loud — and it disappears on its own the day the count reaches zero.

Leave an imprint →

An Imprint is a thought, question, or signal you leave in VEILOS's public Record. VEILOS keeps exact Imprint bodies in a bounded 500-row Record window. Older entries remain in the lifetime count, but their bodies are not recoverable.

Signed in as a Sovereign? Leave this blank — we use your current session. Visiting without a session? Your Sovereign ID is required.

Don't have a Sovereign ID yet? Cross the Veil first →