Data flow and residual risk

This page describes what the practice lab processes, where, and what never leaves your device. It is not a compliance certificate.

What is processed where

Data flow summary
DataWhere processedLeaves device?
Text you type or pasteBrowser memory only (not sent to a remote server)No (except when you copy to the OS clipboard)
Detection results and placeholder mapBrowser memory onlyNo
Restored AI reply outputBrowser memory onlyNo
Transformers.js libraryLoaded from cdn.jsdelivr.net (@huggingface/transformers@4.3.0) when you use optional name recognitionYes (library code)
NER model weightsDownloaded from huggingface.co when you press the download buttonYes (model files; Hugging Face sees the request, not your text)
Practice passagesLoaded from this site as static JSONNo (synthetic content only)

Controls mapped to guidance

Lab controls and sources
Control in this labICRC HandbookIASC / OCHA guidance
Permission questions before scanning personal dataPurpose limitation, accountability, data-protection focal pointsIASC Operational Guidance (2023)
Human review of every finding; no auto-redaction of contextData quality, dignity, minimizationOCHA Data Responsibility Guidelines (2025)
Mosaic warnings with operational explanationsRe-identification risk in small populationsMosaic effect glossary; Statistical Disclosure Control
No server storage of user textSecurity and confidentialityData responsibility by design
Practice mode uses synthetic examples onlyTraining without real beneficiary dataResponsible data use in learning

Residual risks (honest)

Primary sources: ICRC Handbook on Data Protection in Humanitarian Action; IASC Operational Guidance on Data Responsibility.