English

Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product Concepts

Human-Computer Interaction 2026-01-27 v2 Artificial Intelligence

Abstract

AI creates and exacerbates privacy risks, yet practitioners lack effective resources to identify and mitigate these risks. We present Privy, a tool that guides practitioners without privacy expertise through structured privacy impact assessments to: (i) identify relevant risks in novel AI product concepts, and (ii) propose appropriate mitigations. Privy was shaped by a formative study with 11 practitioners, which informed two versions -- one LLM-powered, the other template-based. We evaluated these two versions of Privy through a between-subjects, controlled study with 24 separate practitioners, whose assessments were reviewed by 13 independent privacy experts. Results show that Privy helps practitioners produce privacy assessments that experts deemed high quality: practitioners identified relevant risks and proposed appropriate mitigation strategies. These effects were augmented in the LLM-powered version. Practitioners themselves rated Privy as being useful and usable, and their feedback illustrates how it helps overcome long-standing awareness, motivation, and ability barriers in privacy work.

Keywords

Cite

@article{arxiv.2509.23525,
  title  = {Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product Concepts},
  author = {Hao-Ping Lee and Yu-Ju Yang and Matthew Bilik and Isadora Krsek and Thomas Serban von Davier and Kyzyl Monteiro and Jason Lin and Shivani Agarwal and Jodi Forlizzi and Sauvik Das},
  journal= {arXiv preprint arXiv:2509.23525},
  year   = {2026}
}