AI creates and exacerbates privacy risks, yet practitioners lack effective resources to identify and mitigate these risks. We present Privy, a tool that guides practitioners without privacy expertise through structured privacy impact assessments to: (i) identify relevant risks in novel AI product concepts, and (ii) propose appropriate mitigations. Privy was shaped by a formative study with 11 practitioners, which informed two versions -- one LLM-powered, the other template-based. We evaluated these two versions of Privy through a between-subjects, controlled study with 24 separate practitioners, whose assessments were reviewed by 13 independent privacy experts. Results show that Privy helps practitioners produce privacy assessments that experts deemed high quality: practitioners identified relevant risks and proposed appropriate mitigation strategies. These effects were augmented in the LLM-powered version. Practitioners themselves rated Privy as being useful and usable, and their feedback illustrates how it helps overcome long-standing awareness, motivation, and ability barriers in privacy work.
@article{arxiv.2509.23525,
title = {Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product Concepts},
author = {Hao-Ping Lee and Yu-Ju Yang and Matthew Bilik and Isadora Krsek and Thomas Serban von Davier and Kyzyl Monteiro and Jason Lin and Shivani Agarwal and Jodi Forlizzi and Sauvik Das},
journal= {arXiv preprint arXiv:2509.23525},
year = {2026}
}