The product has three connected but deliberately separate frames.
Purpose: help a person understand and control potentially harmful or manipulative content in the moment.
Outputs include local warnings, highlights, blur/hide controls, explanations, and account or keyword controls.
Success means the person can make an informed choice without the product taking control away from them.
Purpose: help a person recognize patterns in their own exposure and usage.
Outputs include platform/time summaries, content-category trends, and repeated exposure patterns.
Insights describe associations and observations. They do not diagnose a person, declare content harmful with certainty, or claim causation.
Purpose: support approved studies of content exposure, usage patterns, feedback, and wellbeing.
Research is a backlog frame, not an automatic destination for product data. It requires its own consent, protocol, retention policy, access controls, and export format.
All three frames can use local events, but only the research frame can produce a research export. Raw captures remain disposable unless a separate, explicit capture-review consent is active.
Personal safety actions are useful product features, but they change what a person sees and does. The default insight experience—and any future observational research baseline—must keep those actions off unless the person explicitly enables one. If an approved study evaluates blur, warnings, or another protection feature, it is an intervention condition and must be analyzed separately from passive observation.
Personal safety and personal insights begin with Browser Observation. Active-tab analysis is a person-triggered enhancement when text and page metadata cannot answer the question. Research sessions are a backlog-only mode with separate consent and approval; they must not be repurposed into normal-product monitoring.
The product should behave like a food tracker that analyzes a meal photo: capture or inspect a bounded serving, derive useful categories and estimates, show the result, and discard the original by default. The analogy stops at the data boundary: content exposure can involve other people, private conversations, and highly sensitive material, so retention must be stricter than a typical food log.