At home, the camera is locked until you open it.
The hardest question about a robot in a home is not what it can do. It is who can see through it. Our answer is a lock on the robot itself, not a setting on a server.
How the lock works
At home, no camera picture leaves the robot, for anyone, unless the owner opens it from their own phone for a set number of minutes. The robot says so out loud when the camera opens and again when it locks. The camera still works inside the robot for safety, to see what is in its way and to recognise its owner, and those face prints stay on the robot. Only pictures leaving it are stopped.
The robot decides it is home from its own map and from the home's Wi-Fi radios, recognised by their hardware address rather than a network name anyone could copy. It never takes a server's word for it. If its settings cannot be read, it locks. After every restart, it starts locked.
Privacy mode, anywhere
The owner can switch on privacy mode from their live page or by asking Cole. The robot says camera and microphone off, and nothing it sees or hears leaves it until the owner turns privacy mode off from their own phone. Every lock, unlock and refusal reaches the owner as a message.
Honest about our own robot
Our test robot has a development mode for the weeks we are building, which lifts the home lock for at most seven days. It can only be switched on from the owner's phone, every page shows when it is on, and it ends by itself. A founding home starts with the lock on.