Integrating User-Facing Privacy Tools into Conversational Agents (CA)

Problem Definition
Privacy is inherently contextual, meaning that it cannot be fully preserved through after-the-fact (once users data is collected) data controls alone. Instead, it needs to also be approached during interactions with technologies and by supporting end-users in taking protective actions.
This is especially essential in Conversational Agents (CAs) due to ambiguities around their privacy and security measures, prior documented privacy incidents, and growing public concerns about the erosion of privacy by AI tools as they can enable detailed profiling and creating risks of data misuse beyond users' informed consent.
Supporting users' meaningful agency over privacy requires deeper understanding of how they currently behave and reason about data disclosure and protection in the moment of CA interactions and across varied and realistic chatbot use scenarios. In such investigation, it should be acknowledged that privacy attitudes can vary across individuals based on factors including age, gender, education, and geographic locations.
In this study, we built a just-in-time privacy notice panel, supporting privacy awareness and protection, and integrated it into a simulated interface of ChatGPT. Our goals is to qualitatively investigate in-the-moment sensitive information disclosure and protection behaviors among CS undergrads and master's students in the United States, along with their reasoning underlying these behaviors.
Research Process
The focus of this project is on solving a problem that exists for actual users of differentially private data. Therefore, to make sure that we are solving the right problem for the right users, we are taking a user-centered design approach.
Tool Design
ChatGPT Interface Simulation
Privacy Notice Panel Design
Study Design
Study Phases
User Tasks
Participants & Data Collection
Data Analysis
Results
Behaviors in Info Disclosure
Rationale Behind Information Disclosure
Behaviors in Using Protective Approaches
Rationale Behind Using or Avoiding Approaches
Discussions
Privacy in Attentional Foci
Privacy Reasoning
Filtering Task-Irrelevant Info
Automation VS User Control
Promoting Manual Protections
Privacy Agency by Socio-technical Considerations
Phase 1: Tool Design
ChatGPT Interface Simulation • Privacy Notice Panel Design
TODO - See Our Paper—https://arxiv.org/abs/2601.18125
Phase 2: Study Design
Study Phases • User Tasks • Participants and Data Collection • Data Analysis
TODO - See Our Paper—https://arxiv.org/abs/2601.18125
Phase 3: Results
Behaviors in Info Disclosure • Rationale Behind Info Disclosure • Behaviors in Using Protective Approaches • Rationale Behind Using Approaches
TODO - See Our Paper—https://arxiv.org/abs/2601.18125
Phase 4: Discussions
TODO - See Our Paper—https://arxiv.org/abs/2601.18125
Limitations
TODO - See Our Paper—https://arxiv.org/abs/2601.18125
Reflection
TODO - See Our Paper—https://arxiv.org/abs/2601.18125