<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Sensitivity Apple Privacy Engineering Notes</title>
    <link>https://sensitivityscan.com/learn</link>
    <description>Practitioner notes about on-device media classification, privacy boundaries, and safe human review on Apple platforms.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 01 Sep 2026 20:00:00 GMT</lastBuildDate>
    <atom:link href="https://sensitivityscan.com/developer-feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How On-Device Sensitive Photo Scanning Works</title>
      <link>https://sensitivityscan.com/learn/how-on-device-photo-scanning-works</link>
      <guid isPermaLink="true">https://sensitivityscan.com/learn/how-on-device-photo-scanning-works</guid>
      <description>The data path and limitations behind a private library review.</description>
      <content:encoded><![CDATA[<h2>Permission opens the library to the app</h2><p>On iPhone and iPad, a scanner needs Photos permission to read the items it is asked to classify. On Mac, a workflow may use the Photos library or folders a person explicitly selects. Permission is necessary for the job, but it does not explain where the media goes afterward.</p>
        <h2>Classification happens on the device</h2><p>In an on-device workflow, the app supplies local image or video data to a model running on the iPhone, iPad, or Mac. The result is a score or category used to build a review queue. For Sensitivity, the media is not uploaded to Sensitivity servers for classification.</p>
        <h2>iCloud can still download an item</h2><p>Photos may keep an optimized copy locally while the original remains in iCloud. When a scan requests an iCloud-only item, Apple Photos may download it to the device. That is an Apple Photos transfer into local storage, not an upload from the scanner to its developer.</p>
        <h2>Results need their own protection</h2><p>Local classification can still reveal private information if the result list is exposed. Sensitivity places review behind device authentication and stores scan state locally. Its analytics excludes media contents, thumbnails, filenames, album names, media identifiers, and detection results.</p>
        <h2>Questions every privacy policy should answer</h2><ul><li>Are photos or videos uploaded for classification?</li><li>Is an account required?</li><li>Do analytics events include media identifiers or classifications?</li><li>Where are result lists and scan progress stored?</li><li>Can the app automatically hide, move, or delete media?</li><li>What happens when an item exists only in iCloud?</li><li>What are the known detection limitations?</li></ul>
        <h2>Local does not mean perfect</h2><p>Processing location and model accuracy are separate. A local detector can still flag ordinary media and miss private content. Video sampling can miss moments between frames. The correct product role is to reduce a manual review set while keeping every decision with the user.</p><div class="article-note"><strong>A useful media boundary</strong><p>Local classification, no media uploads, protected results, no automatic deletion, and an explicit human-review requirement can be independently stated and tested.</p></div>
        <h2>Details for Sensitivity</h2><ul><li><a href="https://sensitivityscan.com/privacy">Privacy policy and stored-data table</a></li><li><a href="https://sensitivityscan.com/about">Developer, disclosures, and guide process</a></li><li><a href="https://sensitivityscan.com/learn/photo-scanner-false-positives">False positives and missed items</a></li></ul>
        <div class="article-note"><strong>Scanning text inside images is a separate job</strong><p>Sensitivity classifies likely private photo and video content; it does not look for passwords, recovery codes, or API keys written inside an image. I also build SecretScan for that separate camera-roll audit. Its OCR runs on the device and every possible match remains under human review. <a href="https://mityapolianskii.github.io/secretscan-app-store-pages/scan-api-keys-in-screenshots.html">Read the developer screenshot guide</a> or <a href="https://apps.apple.com/app/apple-store/id6763880476?pt=120611987&amp;ct=sensitivity_crosspromo_sep2&amp;mt=8">try the free screenshot scan</a>.</p></div>]]></content:encoded>
      <dc:creator>Dmytro Polianskyi</dc:creator>
      <pubDate>Wed, 26 Aug 2026 20:00:00 GMT</pubDate>
    </item>
    <item>
      <title>False Positives in Sensitive Photo Scanners</title>
      <link>https://sensitivityscan.com/learn/photo-scanner-false-positives</link>
      <guid isPermaLink="true">https://sensitivityscan.com/learn/photo-scanner-false-positives</guid>
      <description>Why detectors make mistakes and how to review suggestions safely.</description>
      <content:encoded><![CDATA[<h2>What a false positive is</h2><p>A false positive is an ordinary or acceptable image classified as likely sensitive. Beaches, sports, skin-colored backgrounds, artwork, medical photos, cropped bodies, and screenshots can resemble patterns that a nudity detector associates with sensitive content.</p>
        <h2>False negatives matter too</h2><p>A false negative is private content the detector does not suggest. Low light, unusual framing, heavy cropping, clothing, small subjects, illustrations, and video moments between sampled frames can all make detection harder. That is why a scanner cannot certify that a library is clean.</p>
        <h2>Thresholds trade one error for another</h2><p>A broad threshold can surface more possible matches but also more ordinary images. A strict threshold can create a shorter list while missing ambiguous content. There is no universal setting that reflects every person’s definition of private.</p>
        <h2>A safe review policy</h2><ol><li>Treat the result list as a queue, not a conclusion.</li><li>Open the full-resolution photo or enough of the video timeline to understand it.</li><li>Check neighboring items from the same moment.</li><li>Keep deletion selections small enough to verify.</li><li>Review Recently Deleted after any cleanup.</li><li>Use a manual pass for dates or contexts where missing an item would matter.</li></ol><div class="article-note"><strong>Never automate deletion</strong><p>A privacy tool should reduce review work without turning an uncertain model output into an irreversible action.</p></div>
        <h2>Privacy and accuracy are different questions</h2><p>On-device processing answers where classification happens. It does not make a detector perfect. A trustworthy product should explain both its media boundary and its accuracy boundary: where the data goes, whether an account is required, whether results leave the device, and whether the user reviews every action.</p>
        <h2>How Sensitivity uses results</h2><p>Sensitivity analyzes media on the device and displays likely matches behind device authentication. It does not upload media for classification and does not delete anything automatically. The user decides whether to keep, hide, or delete each item.</p>
        <h2>Further details</h2><ul><li><a href="https://sensitivityscan.com/privacy">Sensitivity privacy policy</a></li><li><a href="https://sensitivityscan.com/about">Product boundaries and editorial process</a></li><li><a href="https://sensitivityscan.com/learn/how-on-device-photo-scanning-works">How on-device scanning works</a></li></ul>]]></content:encoded>
      <dc:creator>Dmytro Polianskyi</dc:creator>
      <pubDate>Wed, 26 Aug 2026 20:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
