A Privacy Nerd’s Threat Model for Online Face-Blurring Tools
Evaluate a face-blurring tool by tracing originals, frames, uploads, logs, and downloads. Build a useful threat model without relying on privacy slogans.
On this page
A useful threat model for a face-blurring tool starts with one question: what are you trying to prevent? Uploading an unreleased clip to a provider, revealing a person's face in the result, and leaking a filename through logs are separate problems.
Write down the concern before comparing tools. Otherwise “private” becomes a word that can mean almost anything.
Trace the source and its derivatives
List the original video, extracted frames, face thumbnails, tracking data, processed result, and support attachments. Ask where each item is created and how long it remains available.
A vendor saying it deletes “the video” may be describing only the input object. That statement tells you little about outputs, thumbnails, logs, backups, or a file attached to a support ticket.
For local software, ask the same questions about browser storage, temporary files, and the downloads folder.
Separate the provider from the endpoint
If you do not want a provider receiving source media, an on-device workflow is relevant. If the laptop itself is compromised or shared with people who should not see the video, local processing does not solve the main problem.
For Unseen's local path, prepare the engine, disconnect, and test import through export with harmless footage. That is a useful observable property. It is not an independent code audit or a guarantee about extensions and operating-system software.
Ask questions that can be answered
- Does the source video leave the device in this mode?
- Are detection and rendering both local?
- Does switching modes change the upload behavior?
- What happens to input, output, and derived files after a failed job?
- What information should be excluded from a support request?
Answers should identify a mode and a stage of processing. “We take privacy seriously” does not tell you whether an upload occurs.
A network trace can help an experienced user examine behavior, but interpret it carefully. Downloading a model is different from uploading a frame. Silence during one test does not establish all future behavior.
Include the published result in the model
Even a perfectly local tool can produce an unsafe output if it misses a face. The person you are protecting may also be recognized by voice, clothing, or the room behind them.
Decide whether you are hiding someone from casual viewers, acquaintances, or a motivated person with other footage. That changes what counts as an adequate edit.
Use local versus cloud for the product decision. Use the retention questions if you are willing to upload but need clear deletion commitments. Keep the test tied to the threat you actually have.
Try it on a short clip
Start with a difficult moment from your video, then inspect the exported result.
Open Unseen