Conflect: Reflective Privacy Policy for Apps
- Conflect is an interactive contextual privacy policy system for mobile apps that uses a reflective thinking framework to connect on-screen actions with detailed policy information.
- The system integrates advanced OCR, UI analysis, and LLM-based policy extraction to achieve 94.0% accuracy and deliver risk alerts with an average latency of 4.35 seconds.
- User studies show that Conflect enhances privacy awareness and control by reducing cognitive load through non-intrusive sidebar alerts and layered, actionable disclosures.
Conflect is an interactive contextual privacy policy (CPP) for mobile apps, guided by a reflective thinking framework. It is motivated by two linked observations: privacy policies are lengthy and complex, leading to user neglect, and contextual privacy policies present information at the point of risk but may lack engagement and disrupt tasks. Through three workshops with experienced designers and researchers, the system’s designers constructed the design space of reflective thinking-based CPP design and identified the disconnect between context and action as the most critical problem. Conflect addresses that problem by using sidebar alerts, allowing users to reflect on contextualized risks and fostering their control (Zhang et al., 16 Sep 2025).
1. Definition and design premise
Conflect is situated within contextual privacy policy design for mobile applications. Its central premise is that privacy information should be presented in relation to concrete, on-screen actions, but in a form that does not collapse into either static policy text or highly disruptive just-in-time interruption. The system therefore combines contextual privacy detection, privacy policy extraction, and reflective presentation in a single pipeline.
The formative basis of the system is a reflective thinking framework. The design rationale explicitly draws on Reflective Thinking, especially the Experience-Reflection-Action (ERA) cycle and Driscoll’s “What? So what? Now what?” model. In this formulation, the user first encounters a contextually triggered privacy risk cue, then connects the observed action or trigger to policy and risk explanations, and finally receives means to exercise control.
A key design insight is the identification of the disconnect between abstract policy and concrete user action. Conflect operationalizes that insight by situating privacy information in actionable, personally relevant scenarios. This suggests a deliberate shift from document-centric privacy notice delivery toward interaction-centric disclosure.
2. Reflective thinking as the organizing framework
The reflective thinking model structures both the content and timing of disclosure. In the Experience stage, the user is exposed to a contextual cue indicating that an on-screen element is associated with a privacy risk. In the Reflection stage, the system presents a connection between the current interface context, the relevant privacy policy segment, and a risk description. In the Action stage, the interface supports user control, including muting future alerts for a given risk and nudging the user to review or change privacy settings in the host app.
Conflect’s use of reflective thinking is not limited to presentation style. It also determines the layered progression of information. The system moves from concise contextual notice, to reflective risk description, to policy excerpt. That progression is designed to connect immediate interface experience with legal text and potential consequences, rather than presenting policy text in isolation.
The reflective component is therefore both cognitive and operational. It is cognitive because it is intended to facilitate critical thinking about consequences; it is operational because it links disclosure to available controls. A plausible implication is that Conflect treats privacy comprehension as an activity embedded in ongoing app use rather than as a separate reading task.
3. System architecture and operational flow
Conflect’s architecture consists of three main modules: Contextual Privacy Detection, Privacy Policy Extraction, and Reflective Presentation. The high-level flow is screenshot capture, followed by contextual privacy detection, privacy policy extraction, and reflective presentation.
In Contextual Privacy Detection, the system uses OCR and UI analysis to detect sensitive information fields on-screen, such as text inputs and icons. OCR text is recognized by PaddleOCR and classified into data types via LLM (GPT-3.5). Icons are classified by ResNet and then mapped to privacy data categories. Visual mapping through bounding boxes anchors privacy alerts to relevant UI elements.
In Privacy Policy Extraction, the system locates the app’s privacy policy via web search, with LLMs leveraging app names. It then segments policy text to extract data-specific policy excerpts using LLM prompts. Extraction is structured for data collection, sharing, usage, and disclosure.
In Reflective Presentation, detected on-screen elements are aligned with corresponding policy snippets using shared data categories. LLMs (GPT-4o) generate concise, contextualized descriptions and risk scenarios from original privacy policy text. The resulting output for each relevant screen element is a bundle consisting of the data category, a short summary, a reflective description, and a relevant policy excerpt.
All steps leverage prompt engineering to enforce strict adherence to extraction, summarization, and risk scenario generation rules, minimizing hallucination or irrelevance.
4. Interface design and interaction model
The most distinctive interaction element in Conflect is the sidebar alert mechanism. The collapsed sidebar acts as a minimal visual indicator and animates to signal new privacy risks. The expanded sidebar uses color-coded icons in a traffic-light scheme for risk severity. This structure is intended to function as an ambient, non-intrusive trigger.
When a risk is selected, popup notifications appear with bounding boxes around pertinent UI elements. The disclosure is layered. The first layer provides a concise data practice summary. The second layer provides a contextual risk scenario. The third layer exposes the policy excerpt for deeper inspection. This layered disclosure is integral to the reflective thinking design, because it stages the movement from immediate awareness to contextual reasoning and then to source text.
Action controls complete the Experience-Reflection-Action loop. Long-pressing an icon can mute future alerts for that risk. Users can also be nudged to review or change privacy settings in the host app. Qualitative feedback reported that the sidebar approach was praised for minimizing disruption compared to pop-up-heavy solutions, and that layered, contextual disclosure increased perceived agency and satisfaction.
A common misconception about contextual privacy policies is that point-of-risk presentation necessarily requires intrusive interruption. Conflect is presented as a counterexample to that assumption: the sidebar is explicitly designed as a minimally intrusive UX, while still retaining contextuality.
5. Detection, extraction, and generation performance
The system contextually detects privacy risks, extracts policy segments, and automatically generates risk descriptions. Its reported technical performance centers on extraction accuracy, latency, and perceived usefulness of generated descriptions (Zhang et al., 16 Sep 2025).
| Measure | Reported value |
|---|---|
| Policy extraction accuracy on CPP4APP | 94.0% |
| Prompted reflection score | 6.4 / 7 (SD = 0.4) |
| Parallel latency | 4.35 s (SD = 0.93 s) |
| Serial latency | 19.78 s |
The reported policy extraction accuracy is 94.0% on the CPP4APP dataset for correctly extracting policy segments relevant to detected data categories. The average usefulness of generated risk descriptions is 6.4 / 7 on a 7-point Likert scale, with SD = 0.4. Average end-to-end latency from screenshot to scenario display is 4.35 seconds, with SD = 0.93s, using parallelized processing on a server with 8 vCPUs and 32GB RAM. The baseline serial latency was 19.8s, and the detailed latency breakdown attributes 2.49s to GUI element localization and 1.84s to classification.
These values indicate that Conflect is not only a conceptual interface proposal but also a concrete pipeline integrating OCR, icon classification, web-based policy retrieval, policy segmentation, and LLM-based synthesis. The latency figures are especially relevant because Conflect is intended for use during mobile interaction rather than as an offline analysis tool.
6. User study and comparative evaluation
Conflect was evaluated in a within-subjects study with 28 mobile app users. The comparison included three baselines: a traditional privacy policy, a privacy label, and a state-of-the-art CPP. The user study reported that Conflect improves user understanding, trust, and satisfaction while lowering cognitive load compared to CPPs, privacy policies and privacy labels (Zhang et al., 16 Sep 2025).
The quantitative findings are differentiated by instrument. For understanding, Conflect achieved statistically significant higher scores than CPP and comparable or superior performance to other methods. For usability, Conflect significantly outperformed the traditional privacy policy on the System Usability Scale. For cognitive load, Conflect yielded significantly lower cognitive load across all six NASA-TLX dimensions compared to baselines. On the UEQ, Conflect was rated more perspicuous, efficient, dependable, interesting, novel, and comfortable than both privacy policies and privacy labels.
The trust results are more nuanced than a single headline metric suggests. The detailed report states that there were no significant differences across techniques, but qualitative insights revealed higher trust when Conflect is framed as a system-native feature. Qualitative findings also include improved user agency and control, greater privacy awareness, and reduced information overload. Users reported discovering previously unnoticed background data collection and indicated a desire for custom alerts and risk models.
This combination of results suggests that the system’s contribution lies not only in answerable policy extraction and contextual risk generation, but also in the manner in which disclosure is staged, anchored, and operationalized.
7. Position within contextual privacy policy research
Conflect is described as the first CPP system for mobile apps designed around reflective thinking. Its contribution is not merely to surface privacy policy fragments at the point of risk, but to bridge context, explanation, and action in a single interaction design. The system therefore occupies a specific position within privacy interface research: it combines contextual detection, policy-grounded extraction, LLM-mediated summarization, and an interface explicitly designed to support reflection.
Its broader significance lies in the attempt to reconcile three competing demands: contextual relevance, engagement, and non-intrusiveness. The paper frames the underlying tension clearly: CPPs can present information at the point of risk, yet may lack engagement and disrupt tasks. Conflect addresses that tension through sidebar alerts, layered disclosure, and reflective framing.
The reported desire for personalization and custom risk models indicates an extensibility path already identified by participants. This suggests future work on configurable alerting, differentiated risk modeling, and broader adaptation to user preferences. At the same time, the system’s dependence on contextual detection, policy extraction, and LLM-based synthesis means that its practical value remains tied to the robustness of those components.
In summary, Conflect is a reflective thinking-based contextual privacy policy system for mobile applications that combines on-screen privacy risk detection, policy segment extraction, and layered reflective presentation. Its technical results—94.0% policy extraction accuracy on CPP4APP and 4.35s latency—and its user study findings position it as a concrete, empirically evaluated approach to contextual privacy disclosure rather than a purely conceptual interface proposal (Zhang et al., 16 Sep 2025).