







The key questions: how much power will apps be given to determine and enforce what data is permissioned? What incentives will apps have to make any data public? So far the protocol has been a forcing function for (adversarial) interop. We need to be intentional about not recreating app silos.
daniel holmgren 🫠
hey we're really working on permissioned data! read the first in a series of posts i'll be doing about our design decisions along the way. this one is about our decision to not do an e2ee system
Feb 12, 2026 at 6:56 PM
but should apps see our data? - building [at] habitat
thinking small on the protocol
Permissioned Data: Space Access - Nick's Blog
Stepping outside the shapes series for a deep dive: how space configuration decides which people and which apps get credentials. Here be dragons.
research.latha.org
A permissioned appview for research documents on AT Protocol. True data ownership with optional monetization.
How to handle granular permissions | Authorization Resources | Google for Developers
Granular permissions give users more control over the specific data they share with apps, improving transparency, security, and trust.

Your Data, Your Control
How data portability can unlock competition and empower consumers January 15, 2026 Copyright and permission to reproduce For information on the Competition Bureau's activities, please contact: Information Centre Competition Bureau 50 Victoria Street Gatineau QC K1A 0C9
AI Wants Your Life: Tech Boss Meredith Whittaker Says No | The Mishal Husain Show
Confer is bringing foundational AI privacy to Meta
I started building Confer because I saw how amazing LLMs are, and as a result, how much of our data is flowing through them. Already, AI chat apps have become some of the largest centralized data lakes in history, containing more sensitive data than anything ever before. We are using LLMs for the kind of unfiltered thinking that we might do in a private journal – except this journal is an API endpoint to a data pipeline specifically designed for extracting meaning and context.

Government to ease data consent rules for AI development | The Asahi Shimbun Asia & Japan Watch
To accelerate artificial intelligence development, the government plans to relax consent requirements for access to personal information while introducing tougher penalties for intentional misuse.

User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies
Hundreds of millions of people now regularly interact with large language models via chatbots. Model developers are eager to acquire new sources of high-quality training data as they race to improve model capabilities and win market share. This paper analyzes the privacy policies of six U.S. frontier AI developers to understand how they use their users' chats to train models. Drawing primarily on the California Consumer Privacy Act, we develop a novel qualitative coding schema that we apply to each developer's relevant privacy policies to compare data collection and use practices across the six companies. We find that all six developers appear to employ their users' chat data to train and improve their models by default, and that some retain this data indefinitely. Developers may collect and train on personal information disclosed in chats, including sensitive information such as biometric and health data, as well as files uploaded by users. Four of the six companies we examined appear to include children's chat data for model training, as well as customer data from other products. On the whole, developers' privacy policies often lack essential information about their practices, highlighting the need for greater transparency and accountability. We address the implications of users' lack of consent for the use of their chat data for model training, data security issues arising from indefinite chat data retention, and training on children's chat data. We conclude by providing recommendations to policymakers and developers to address the data privacy challenges posed by LLM-powered chatbots.

User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies
Hundreds of millions of people now regularly interact with large language models via chatbots. Model developers are eager to acquire new sources of high-quality training data as they race to improve model capabilities and win market share. This paper analyzes the privacy policies of six U.S. frontier AI developers to understand how they use their users' chats to train models. Drawing primarily on the California Consumer Privacy Act, we develop a novel qualitative coding schema that we apply to each developer's relevant privacy policies to compare data collection and use practices across the six companies. We find that all six developers appear to employ their users' chat data to train and improve their models by default, and that some retain this data indefinitely. Developers may collect and train on personal information disclosed in chats, including sensitive information such as biometric and health data, as well as files uploaded by users. Four of the six companies we examined appear to include children's chat data for model training, as well as customer data from other products. On the whole, developers' privacy policies often lack essential information about their practices, highlighting the need for greater transparency and accountability. We address the implications of users' lack of consent for the use of their chat data for model training, data security issues arising from indefinite chat data retention, and training on children's chat data. We conclude by providing recommendations to policymakers and developers to address the data privacy challenges posed by LLM-powered chatbots.

At Habitat, we've been thinking about what apps might need to build rich permission-ed interactions and interoperate. Here's our take ⤵️
Habitat's road to release: 03 ReBAC on spaces
habitat.leaflet.publooking for feedback on the first pass of permissioned data protocol lexicons! hop in & let me know your thoughts! discourse.atprotocol.community/t/permissioned-data-pds-lexic…
Permissioned Data PDS Lexicons
discourse.atprotocol.communityhere it is folks! lots of details to still nail down, but this is roughly where our heads are at for the design of a permissioned data protocol give it a read and let me know your thoughts!
Permissioned Data Diary 4: The Big Picture
dholms.leaflet.pub