Data and privacy
A technical description of how data works in Teleportation Lab. No legal boilerplate, just the substance.
In short
We do not ask for data that could identify a person. No video of the session is created. An email address appears in the database only if the participant enters it themselves, in order to receive a photo portal; until they do, measurement results cannot be traced back to who produced them.
What the camera does
The camera is active only during measurement and is released immediately afterwards, the camera indicator goes off. During the five-minute session itself the camera is not running, unless extended mode with heart rate variability is enabled.
Face detection happens locally, in the browser. The video stream and full frames never leave the device and are not recorded, neither in the browser nor on our server.
What is sent for processing
Pulse is calculated using the cloud VitalLens model by Rouast Labs. What is sent is not video and not camera frames, but the result of local preprocessing: the face area compressed into thumbnails of about 40 × 40 pixels, without audio. Such a thumbnail cannot show facial detail, it is only sufficient for analysing changes in skin colour.
Nothing identifying is sent along with this data: no email, no session identifier, no IP address, no state ratings. Requests to VitalLens are anonymous and are not linked to the record in our database.
The role of our server
Our server acts as a technical proxy: it adds the service access key and passes the request on. Frames are not buffered to disk and not logged: this proxy’s logs contain only the request method, path, response code and duration.
Separately, we log measurement failures: which step failed, the error text, a signal-quality flag, the anonymous browser identifier, and the irreversible hashes of the IP address and User-Agent. This exists so we can fix a measurement that is not working for someone.
How the photo portal video is delivered
The photo portal video is not hosted by us but by the video service Bunny, and the browser requests it from there directly over a signed link. That means Bunny sees the device’s IP address and User-Agent for the duration of playback — as any site you load something from does. No email, no session identifier and no measurement results are sent there.
What happens on the VitalLens side
According to the Rouast Labs documentation, the received data is processed in volatile memory only and deleted immediately after the result is returned. They do not retain video, images or the resulting vital signs. Only numbers come back: pulse, signal quality metrics and, in extended mode, heart rate variability metrics.
Policy: rouast.com/privacy
What we store
For each session, the Teleportation Lab database holds:
- measurement results: pulse before and after, ratings for calm, energy and lightness;
- heart rate variability metrics, if the session ran in extended mode;
- a signal quality flag, used to exclude invalid measurements from statistics;
- technical fields: the chosen photo portal, session time, browser time zone and its offset, test session flag, repeat visit flag, a link to the review, and a flag recording that the email was sent;
- an anonymous browser identifier, an irreversible hash of the IP address and an irreversible hash of the browser's User-Agent string. Neither raw IP addresses nor raw User-Agent strings are stored. These fields exist only to distinguish repeat and automated sessions.
Original images and video of the measurement are not stored.
When personal data appears
There are only two cases.
Email. The participant enters it at the gift step, to receive a photo portal. It is used to send the email and to link repeat visits by the same person. The email delivery service receives the address and the message itself, which contains a personal link to the gift page. From that point the session is no longer anonymous to us: it is linked to the address.
A recorded review. The participant chooses to record a video or a voice message. Before recording starts, they confirm consent to the use of that recording in public project materials. Without consent it is not published. Both are asked because a face and a voice are each recognisable. This is a separate path from measurement and has nothing to do with pulse calculation.
A written review may be published without a name and without any other link to the person.
Where data is stored
On a server in a European data centre in Germany. Transfers use secure connections. All published research results are anonymised.
Retention and deletion
Anonymised measurement results are stored indefinitely: they are the research dataset itself and are not linked to any person.
An email address and a recorded review can be deleted on request. Write from the address you provided: privacy@teleportal.art. If no email was provided, we hold no data that could identify a particular person.
What we do not do
- We do not create or store video of the session.
- We do not ask for a name, phone number, documents or other identifying data.
- We do not share data with third parties, apart from three technical cases described above: frame processing in VitalLens, delivery of the photo portal video via Bunny, and sending the message via the email delivery service.
- We do not use a recorded review without the participant's consent.
- We do not delete or adjust inconvenient measurements to produce more striking statistics.
How the study works: teleportal.art/research