Screenpipe: 24/7 local AI screen and mic recording
github.com
github.com
However, I find it very frustrating that all of the tools that just record your mic or sell a pin or whatever never think about privacy. They seem to take the Google approach that the person who owns the device is allows to consent for everyone else around them (or any data they share with certain people) when that is not ok.
That is before talking about the major concern of people doing this at work without their company knowing, bringing it into a meeting and potentially leaking sensitive information.
I realize that unfortunately there is nothing that can be done at this point to stop this technology from being used by people, but I just wish the people that were making these tools thought about the fact that you are not asking for the consent of people around you.
Only single party consent is required for recording conversations whether on a phone or in person - Ireland, Italy, Czechia, Latvia, Poland, The Netherlands... in fact the only prominent country that comes to mind re: two party consent is Germany.
That is the problem here.
I know that some things that people share with me are more or less sensitive, and I use my knowledge and empathy to decide what I should and shouldn't repeat. I would tell my friend "Oh yeah, Carl said he can't make it to the party tonight," but I wouldn't tell them "Carl is absent from the party due to an IBS flare-up."
A well-meaning friend or coworker might never consider telling another person these personal details, but not think twice about it when enabling a service like this.
How would writing down what we are told change things, versus remembering it, considering what we write down wouldn't be shared with anyone but ourselves?
How about recording, considering what we record wouldn't be shared with anyone but ourselves?
How would somebody suffering from a disability such as hearing loss, vision loss, memory loss, or IBS change that? Should people with disabilities be forced to disclose them whenever they have a conversation? Does that include Carl with IBS? Or would some people with disabilities have to disclose while others are allowed to keep theirs private?
Why do you think so?
You still can have a private conversation to which no third parties are privy, you just have to use the right tools and avoid using the tools that don't match your requirements. Which is getting harder as most tools don't seem to have real privacy in mind (everyone loves the word and boasts about it, but few actually mean or practice it), but there's still plenty of tools that do and no signs this niche is dying or anything.
Even the big tech seem to respect this to some extent, because there is a genuine demand for explicitly end-to-end private conversations, and because it allows companies to avoid liability and keep certain cans of worms closed. I'd say the trends aren't looking strictly antiutopian in this regard, and it's still uncertain how everything is going to turn out.
This reasoning goes against the Right to Delegate [1]. It doesn't matter if you're remembering it using your brain, a notebook, an assistive tool, or Screenpipe. You're just remembering it.
Whether or not you would tell another person these details is another matter altogether, and has no relation to Screenpipe, which does not, from my knowledge, republish your information anywhere else automatically.
In summary: we're talking about an auto-remembering tool here. Your example talks about repeating certain sensitive details. There is no relation between your example and the topic on hand.
"But isn't it the same? You're repeating the information to Screenpipe!"
In the context of your example, I consider "repeating" to be "repeating to a person". See:
> A well-meaning friend or coworker might never consider telling another person these personal details, but not think twice about it when enabling a service like this.
"Another person". Just as you would not think twice about repeating such data to a notebook (e.g. maybe you have bad memory), you also would not think twice about repeating such data to Screenpipe.
There are some exceptions, such as confidential information, where you would not be allowed to write things down on a notebook. In those cases, yes, you should not use Screenpipe. But the IBS example does not cover that; a friend, in my experience, generally does not expect such levels of secrecy unless they explicitly request so (e.g. "Hey, turn off your computer for a while/Hey, don't bring any phones to my house. We need to talk.").
"What about phone recording laws?"
Yeah, you're right. That throws a wrench in my argument that automated remembering has no difference to manual remembering. I could say that there ought to be no difference, but you're right that this isn't necessarily the case.
I could then argue that this only applies to phone calls, and perhaps video calls. For example, there's no need to get the consent of the people around you in public when you record or take photos, as long as you're not harassing someone.
But then this just becomes a legal question (what is) rather than a moral one (what ought to be).
As I get it, it's meant for personal use, not for automatically sharing with anyone - although those Notion plugins are a potentially gray area, simply because Notion is a third party.
The idea is that if you forgot if Carl can make it or not, you can look in up on your private computer (which is assumed to be reasonably secure against unauthorized access), not that it should somehow act as a virtual secretary and automatically respond to others if Carl can make to a party or not. Doing the former does not create any issues wrt privacy (privacy is about not sharing sensitive data - and there is no data sharing), doing the latter is questionable at best.
Recordings increase risks, and it's concerning that I don't see a single word about even the existence of retention policies (and whenever Screenpipe can "realize" and go off the record when it detects something sensitive, pausing recording until it notices the topic changes), but besides that I'm not sure how it harms any reasonable privacy. IMHO, trying to prohibit making notes is not really reasonable, but not sharing such notes with anyone without consent is very reasonable (YMMV, of course).
Seems like you answered your own question? Since there's nothing they can do, what would you want them to do?
Build in functionality so it only recognizes your voice and everything else is removed?
Don't hide behind "privacy" promises or "your data is secure" when that doesn't fix the issue.
Just because we can admit that the reality is the problem is not going away doesn't mean that we just give up and not talk about it.
... or ... if I see it from a different standpoint then doing nothing is not that a bad idea actully. In my case I make it very hard sharing (accessing) pictures of my kids with relatives. Knowing how the big tech hijacking the communication that is used by average folk and how ignorant most are towards privacy implications on others I rather not share pictures except with those few being able to handle secure channel and private thing the way supposed to. Or they can come over in person. So I have to agree now, doing nothing, not using contemporary technology is a great idea! And ban it from (your own) children too.
https://www.thesignshed.co.uk/cdn/shop/products/24-hour-cctv...
Possibly change the usual 'hi' greating to the more appropriate 'sign this release form before coming close or talk!' one.
This is what's often overlooked (intentionally so?) in discussions about privacy. Too much of privacy is framed as "I am OK with sharing this data." But too often the data you hold is actually about other people: contact lists, conversations, associations. When you let a third party sift through your information, you're also making that decision for everyone else you interact with. I think the right way to think about privacy is: even if I have nothing to hide, I respect the agency of those I communicate with, so I won't make that decision to disclose unilaterally.
So when one of the social media sites recommends someone I may know, have no other contacts with this person and I recently shared my number with them. I get angry.
I will never understand how we got to the point that someone else can consent to a company gathering up my data just because it happens to be on their phone.
I don't think it's overlooked, some people talk about it. But a lot of companies try to push it away because they take "privacy" seriously while ignoring the consent problem.
I was wondering for a long time how it knew. I think it was because some of my ex-housemates shared their contacts with FB and it discovered us as a social group.
It is really an eye-opening experience to sign up to Facebook for the first time in recent years. It already knows so much about you and your interests. It’s as if there was already a profile with your name on it that they were building, without even approaching to ask for consent.
It's no longer "your" data if you gave it to someone else.
Clippy?
It just wasn't helpful and we lacked the tech at the time to really make it helpful. My impression was that it was basically a glorified AIM Chatbot with some hooks into Office to get some context.
Remember when cameras started appearing on phones and supposedly phones had to make noises when photos were taken, or when special phone models were made WITHOUT cameras? what happened to those conservative restrictions?
Obviously, some personal responsibility on how this personally recorded data is handled, stored and shared must be upheld but I'm skeptical of attempts at banning these new capabilities - specially, as you say, organizations have long been able to do this, just not individuals (not easily at least)
The normalisation of AI + continual recording from audio or video recording devices (say future smart glasses) would create an entirely different order of self consciousness.
The chilling effect of a subconscious awareness of being continually observed and recorded precludes many kinds of practical freedom. Political protest, 'controversial' speech, spontaneous performance etc. Just as paradoxically, being able to share our thoughts at any time reduces their value and their capacity to amuse entertain or instate change. Have you ever tried to have a conversation with someone who's filming you with their phone? Or tried to completely forget the 'hot' mic in an interview? There's a basic disingenuousness to performance, and if we're all forced to perform all the time - the healthy space for self is diminished to the interior. A place our technology will no doubt force into the light in due course.
I trust humans, and their ability to be more conscious as you are: yes, it will take some generations, but the direction is conscience and the struggle for freedom: I've just read an article about slavery in England before and after the Norman Conquest of 1066 (up to 30% of the population were slaves, who were treated brutally), and how is England today (and us writing this in English).
What I hope, in my lifetime, is keeping trusting human by seeing trends and tools that go into that direction
1. I would submit data only to a private (in house and even on premises) LLM setup (think of ollama, for example)
2. By using this (especially experimenting with it in a contest as close as possible to your king of professional 'circle of trust'), users become conscious on power and risks
It's not easy, but take a stupid example I've read about:
Nothing better than having a colors printer in your office to show your workers that any document can be reproduced indefinitely (think of an 100$ bill)
"To interact with our support bot, please enable screen recording and keyboard logging."
"Thanks! Now go to the settings and enter your password."
"Thanks! All your Bitcoin are belong to us!"
What scares me most is not "cash", but how culture (and world culture) is affected by this.
Take HN, for example: yes, it's a great place and we like it... and we know the quality of its content, but the influence of HN in AI chats results is way too high.
As an example: the other day I wrote a post here, where I asked to post AI answers to a question.. a couple of users posted their answer... and then, few hours later, I re-posted the question myself in perplexity and phind...
well... and the first answer was a link to my post in HN (!)
English content is then easily translated in other languages, ... which is great, but it's too much influence... it gives even more "power" to an already powerful "western" culture.
Take what is was Esperanto vs. the predominant English culture
So, I am more scared of what we'll lose.
Take Pellagra, the disease, and how it spread in Europe: a total catastrophe just because we took the corn from the Americas ...loosing, on the way, how to prepare it (Nixtamalization); something (another thing) Mesoamerica's natives knew very well: such "details" can easily be lost, I'm afraid.
That's not the tool's job.
Fundamentally this _has_ to be the operator's job to take consent and deal with the legal repercussions of how the tool they run on their own device for their benefit works.
This is exactly how a physical microphones works: you don't have ethical safeguards that prevent you from pushing the record button if you're not using it according to your state's law.
We had your approach for phone calls on smartphones, especially on iOS, and as a result the vast majority of people effectively can't record phone calls even when they have full right to do so. In the current situation companies will record the call while you won't, which sucks.
On one recent videoconf with a startup founder, it turned out that they were using some random AI product with access to video and audio on the call, without my knowledge or consent.
(Thanks a lot; now some AI gold rush company has video and audio recording of me, as well as ingested the non-public information on the call.)
Their response to me asking about that made me sure I wanted nothing to do with that startup.
But some AI company probably still has that private data, and if so, presumably will go on to leak it various ways.
And it seems the only way to get an AI goldrush company to actually remove all trace of data it's obtained sketchily/illegally, might be to go legal scorched-earth on the company and its executives, as well as to any affiliates to whom they've leaked.
We shouldn't need random people undertaking filing lawsuits and criminal complaints, just because some random other person was oblivious/indifferent about "consenting" on their behalf. Which "consent" I don't think is legal consent (especially not in "two-party" states), but AI goldrush companies don't care, yet.
And something like this... yikes. Sure, boss, you're not doing eyeball tracking, but all they would have to do is install this on a work computer and just ask AI for a percentage of time not directly spent hammering out code and pay you piecemeal per keystroke or something truly awful. (and the webcam module is coming later, I'm sure.) The future is dystopian.
Personally, I think it's courteous to at least inform that it's being recorded, legality aside.
> typically the law applies to the state where the recording is made.
https://recordinglaw.com/united-states-recording-laws/one-pa...
There are far more one-party states, 37, then two-party.
Both OpenAI and Anthropic don't train on data sent to them via their API. If they leak that private data it was from a security breach, not because they piped it into their training run.
(Cue a dozen comments saying "if you believe them about that you're naive", to which I have no useful response.)
I was watching CNBC interview last week with the founder of https://mercor.com/ (backed by Benchmark, $250m valuation).
The founder was pitching that their company would take every employee's employment and payroll history (even from prior roles) and use that to make AI recommendations to employers on things like compensation, employee retention, employee performance, etc.
The majority of what the founder was describing would clearly be illegal if any human did it by hand. But somehow because a LLM is doing it, it becomes legal.
Specific example: In most states it's illegal for a company to ask job candidates what their salary was in prior roles. But suddenly it's no longer illegal if a big company like ADP feeds all the data into a LLM and query against the LLM instead of the raw dataset.
Copyright issues wasn't enough to regulate LLMs. But I suspect once we start seeing LLMs used in HR, performance reviews, pay raise decisions, hiring decisions, etc, people will start to care.
[0] https://www.cnbc.com/video/2024/09/27/streamlining-hiring-wi...
https://theworknumber.com/solutions/products/income-employme...
IANAL, but I believe it does not. As it was famously said way back in the day, a computer can never be held accountable, therefore a computer must never make a management decision.
There is always a human in the loop who makes the actual decision (even if that's just a formality), and if this decision is based on a flawed computer's recommendation, the flaws still apply. I think it was repeatedly proven that "company's computer says so" is not a legal defense.
For both companies and consumers, it was a step up. Now, I'm not sure if that's the case.
Today there's still many legal and moral qualms about using credit score for job applicants. It's illegal in many areas and highly scrutinized if a company does this.
So, yeah, you're right that it's an issue - and chances are we'll see a wider bans on this (governments are extremely slow).
Selling and purchasing employment history is thankfully banned in a growing number of states. Their business prospects in the US will eventually shrink to zero.
No, perfectly legal and acceptable (if we apply the same standards as we did for copyright).
A model like that… It’s basically going to be a ZIP code to salary coefficient mapping on steroids (with more parameters). The model by itself is probably (IANAL) legal if it can no longer produce any data points for individuals, but whenever using it for hiring purposes is legal or not certainly depends on inputs: e.g. feed it protected category (or a data that strongly correlates with one, e.g. name -> gender) and it most likely won’t fare well in court.
At a greater level, I've always wanted something like this, but we shouldn't be able to collect info on other people without their permission. The dangers of breaches or abuse are too great.
Since corporations are holding back the greatest benefits, we should be able to remember commercial works we've accessed, and collect and organize info on corporations, and some info on governments, but by their nature corporations will be better at getting the upper hand and the resulting attacks on government might not be for the better for society at large.
Yes, some parts of some governments conduct abuses which should be called out, but that is specific departments, other departments work to other principles, sometimes pushing back against the abuse. Otherwise comparing governments to business or computers is a downward spiral. This[1] is an interesting series on this topic.
1. https://en.wikipedia.org/wiki/All_Watched_Over_by_Machines_o...
I've recorded roughly ~1000 hours of livestream of myself this year. 90%+ of it is boring nothingness, but it is not intended for public consumption anyways. I have and will continue to chop up and post on youtube/twitter the interesting moments I do end up capturing, but it's mostly for myself anyways.
I haven't quite gotten to the point where I've been able to articulate the benefits of this practice in a way that might sufficiently pique the interest or at least acceptance of others in the tech community or otherwise, but that's ok. I did make one video where I started to touch on this idea https://www.youtube.com/watch?v=2zqXkNhaJx0 and I will keep working on it and hopefully demonstrate the personal value (and perhaps societal at scale) as time goes on.
The future is going to get pretty weird. Keep an open mind.
Think about it, you can access every single kind of automation through a desktop app or android emulator. Screenpipe becomes a working memory that the LLM develops to have context of its previous actions AND their results.
"Computer, lights" can not only send out a signal like a TV remote, it can check a camera to make sure that the light for the room the user is looking at actually turned on at an appropriate light level for the situation.
No way I’d use something like this that wasn’t local-only, though.
How are you protecting the data locally? Sorry if it's in the README, I didn't see it when skimming.
https://github.com/mediar-ai/screenpipe/blob/4f2391c6dfd8775...
If you assume there's a way to restrict permissions by application (a bit like TCC on Mac for certain folders), you need to then go down a rabbit-hole of what matcher you use to decide what is a "single application" - Mac OS can use developer Team ID (i.e. app signature identity), or similar. You wouldn't want to rely on path or binary name, as those could be spoofed or modified by a rogue app.
So in short, in a multi-user OS, generally the filesystem (asides from Mac OS, under certain circumstances) is fairly widely readable by other software running as the current user. At least in my experience, Mac OS is the desktop OS that is closest to having some level of effective protections against apps accessing "everything" owned by the user (but belonging to other apps).
I'm still very iffy about this. It opens a huge can of worms in terms of privacy. However at least in this case it's not managed by a big company but installed and maintained by the users themselves.
This concept on Mac has been an existing product for years:
When I prototyped doing this for a sub-problem (terminal agent), it was nice to have a tight feedback loop between read/write.
Curious how difficult it would be to add “actions” on top of this, or if it’s mostly geared towards a read-only/replay mindset.
Also, if you transcribe a conversation, but do not record the audio, is that still relevant to recording consent laws? Even if it conversation exists temperarily in some hardware buffer?
Check email, respond to some, see some news, pull up tasks, do some code, ship some code, read some more news, watch a tutorial, do some more code, check mails, respond to some etc etc.
At the end of the day send you a summary, some highlights, occasionally call you for manual intervention.
Is there a better way than going through the code or running Wireshark myself? Even these are not bulletproof…
For now, I am resorting to building the simple things for my use myself. The benefit is that its often quite fun.
But why does it say "70 users run screenpipe 24/7!"
What's being reported from the app, that they know this number?
The augmentation of human beings with tech like this is a proto-type for a dismal world where wisdom is lacking and the pure pursuit of knowledge is becoming a more and more seductive path to destruction.
As someone who suffers from ADD, I simply won't be able to recall forever everything someone and I said, so I use technological augmentation in the form of writing down birthdays, for example. When I'm at meetups, when a conversation huddle ends, I'll write down notes, or more likely, send a custom linkedin connection request mentioning what we talked about.
The result is that we have the same, empathetic, human conversation as before, and also next time we talk, I can ask them about their startup or hobby, and also I wish them a happy birthday every year, which I think is a net positive without any downsides.
And you are forgetting all the destructive technology required to get to the "benign" ones.
From my experience, society is better on average as a result of my using notes and calendar entries in the ways I described.
In my case, it's being used in the way I described, increasing the depth of human connections. So the question is, how does my usage result in "human beings to become more mechanical and less empathetic towards life"?
Objectively the notes are being constructed and filtered by an external 3rd party (even if it is run on device locally, someone external is still training and choosing the agent).
It is the homogenization of thought and note taking of everyone using AI to record their lives that is the potential problem.
How so?
That is especially true because we have an economic system that rewards short-term improvements in the efficiency of the system, regardless of the long-term costs. Fossil fuel use, cutting down local forests (has relatively litle short-term impact, but adds up).
And, as we pursue knowledge and technology more vigorously, we slowly lose other forms of gaining knowledge such as a relationship with nature.
Human society is advanced with regard to its knowledge capability, but exceptionally primitive with regard to basic wisdom about community, love, nature, and friendship. We continually donwgrade these things to make way for new technology, and the prisoner's dilemma (tech gives some people advantages, so everyone is pressured to use it), makes it hard to make decisions for the long-run like the Amish do.
Like what do you think everyone who posts here does?
So, not bizarre at all.
what do you think everyone does?
We should celebrate opinions that go against local conventions
I would actually love to be a technological being. This is transhumanism, isn't it?
But then I saw that users can get it free by posting "about screenpipe 10 times on social media".
If you want ads, pay for proper ads! Don’t pay people to turn user content into sneaky ads.
I understand why people hate regular ads, but IMO affiliate promotion (when done without disclosure) and stuff like what you are doing is much worse.
https://staceyoniot.com/connected-toilets-have-a-lesson-for-...
Sounds like you are talking about a new feature that allows content to fit pages better —- saving paper, saving ink. Not sure if the same can be achieved without AI, but it’s a useful feature, not gimmick.
https://arstechnica.com/gadgets/2024/09/in-rare-move-from-pr...
This story is not organic; it is Screenpipe scummily leveraging their client base into sneaking advertising into social media including HN. If their clients are already just leverage at the outset, I have no doubt their clients' data will just be leverage later.
1: https://screenpi.pe/onboarding 2: https://i.imgur.com/UvjXc1I.png
I can't find anything in the docs about how to pause or temporarily stop data collection. People don't like others recording every interaction they have, which is what killed Google Glass.
A random dude is doing the same thing, but in rust (super important to mention right), storing the data in sqlite => Magnificent project, we want more!
You guys are fucking weird.
1. You have a choice. With MS you don't. You can't opt-out, at least for now.
2. And as prev buddy said, you never know what MS will do with your data.
3. Recall will be heavily targeted and from day-1 some malware will target it. Random dude's pet project doesn't (even though it is a security through obscurity).
1) It was not in fact encrypted and any user could mess with it. AND the data was stored in SQLite too. Microsoft only started fixing this after their totally negligent security was brought to light.
2) Recall is maintained and auto updated by Microsoft which can change the rules at any point (e.g. add datamining at a later point). At least with Screenpipe the end user decides. This solution is open-source so you know what's happening.