This capstone project focused on developing comprehensive design recommendations to enhance privacy protections and user control within ChatGPT and similar AI chat interfaces. Through user research and design analysis, our team identified key areas for improvement in privacy-conscious AI interactions.
Completed as an independently directed capstone project for a course on privacy and accessibility, examining the intersection of AI technology and user privacy rights.
User research, UX design, wireframing
3 person design team, independently directed capstone project
Figma, qualitative research methods
2 months
How can we enhance privacy protections and user control in AI chat interfaces while maintaining usability and functionality?
Through comprehensive research and design analysis, we developed targeted recommendations for improving privacy-conscious design patterns in ChatGPT and similar AI interfaces.
Our research methodology combined multiple approaches to comprehensively understand privacy concerns and develop actionable design solutions.
Research, privacy policy analysis, and conversational AI landscape exploration
Quantitative data collection from 60 college students across 14 universities
In-depth qualitative insights from 6 participants with hands-on privacy feature testing
Privacy-focused UI recommendations and interactive prototyping
We conducted comprehensive research to understand the current landscape of conversational AI and privacy concerns, establishing a foundation for our design recommendations.
Conversational AI chatbots are virtual agents that use "large volumes of data, machine learning, and natural language processing to help imitate human interactions." Examples include ChatGPT, Claude, Copilot, and Perplexity. Released at the end of 2022, ChatGPT immediately attracted attention for its ability to respond in-depth to natural language prompts, acquiring over 100 million users within two months.
Training involves pre-training (where the model learns grammar and general knowledge from large public datasets) and fine-tuning (where the model is refined using smaller, specialized datasets to improve specific behaviors). ChatGPT excels in text generation, often surpassing human performance in summarizing content, answering questions, and providing feedback. However, users must be cautious as it can make factual errors or hallucinate.
Users must be aware of privacy implications and data sharing policies, as OpenAI collects, stores, and trains ChatGPT with an immense amount of user data.
Conversational AI chatbots pose numerous privacy risks as they leverage user input data for contextually relevant interactions. These concerns stem from data collection and usage practices, lack of consent and transparency, and limited technical knowledge among users.
We analyzed OpenAI's privacy policy to understand current transparency practices and identify areas for improvement.
Privacy policies inform users about personal information collection, usage, protection, and user choices. In the United States, companies have discretion over disclosure levels due to the absence of nationwide privacy laws.
The ChatGPT privacy policy contains ten sections covering data collection, usage, and sharing practices.
Grammarly's Flesch reading-ease test scored OpenAI's privacy policy as 37, indicating it requires at least some college education to understand and may not be easy to read.
Privacy policy readability analysis from Grammarly
To understand student perceptions and usage patterns of AI chatbots, we conducted a comprehensive survey across multiple universities.
Undergraduate students
Universities across the US
From Brown & RISD
The survey was designed to collect quantitative and qualitative data on undergraduate university students' usage and perceptions of generative conversational AI chatbots. It was developed by the research team in two rounds of drafting and discussion, with feedback provided by Dr. Diana Freed.
The survey collected demographic information (university, major, graduation year, gender, and age) and included a mix of multiple-choice, multi-select, and short-answer questions focused on understanding perceptions of AI, usage patterns, and privacy considerations. Results were anonymous unless respondents volunteered for follow-up interviews by providing their email address.
Researchers used purposeful sampling to focus on undergraduate students across the United States, distributing the survey through individual outreach, EdStem classrooms for academic course communities, and Slack communities to reach diverse student groups.
Following the survey, we conducted in-depth interviews to gain deeper insights into student behaviors and privacy awareness when using AI chatbots.
Of the 14 respondents who expressed willingness to interview in the survey, we reached out to 6 participants representing diverse experiences, usage patterns, and opinions on AI chatbots.
The six interviews were conducted over Zoom or in-person between individual participants and one researcher. Each session included:
Participants were asked to locate and interact with specific privacy features including training data permissions, memory settings, temporary chat features, and default preferences. We also examined their understanding of ChatGPT's privacy policy—testing their prior knowledge, ability to locate the policy within the interface, and identifying surprising or concerning aspects after reading it.
Our interviews revealed significant gaps in privacy awareness and feature discoverability:
"All participants thought that they should be initially presented with privacy setting choices" - highlighting a clear user need for transparent, upfront privacy controls.
Based on our research findings, we developed comprehensive design recommendations to address the critical privacy and transparency gaps identified in user interviews and surveys.
Design UI elements and user experiences that better inform users about where their data is going and how it's being used, creating actionable solutions through Figma prototypes.
Existing ChatGPT interface analyzed for privacy design opportunities
Users need more granular control over their data and privacy settings
Clear information about data collection and usage practices
Easy-to-find and understand privacy features and settings
We identified specific interface improvements to address immediate usability issues with existing privacy features.
ChatGPT currently tells users that information was added to memory, but it's not immediately clear that this notification is clickable. We added visual cues to make it look like a button, with a pop-up that shows what information was added and allows users to manage their memories.
Many interview participants immediately looked in settings for terms and policies. We added a direct link in the settings panel, in addition to the existing access point from the question mark icon in the main interface.
We completely redesigned the onboarding experience to prioritize privacy education and conscious decision-making from the very beginning of a user's ChatGPT journey.
Current single-page login with implicit agreement
ChatGPT's existing login experience consists of a single page where users enter their email and click "Agree" to continue. Most users implicitly agree to all terms without actually viewing them.
We restructured this into a comprehensive 6-step sequence that promotes conscious agreement and user education:
Step 1: Clean login interface without pressure
Removes the immediate "Agree" button and presents a cleaner interface focused on user credentials, allowing users to proceed without feeling pressured to agree to terms they haven't read.
Step 2: Explicit privacy policy agreement
Users must scroll through the full Privacy Policy with larger font sizes and bolded headings for better readability. They are then presented with explicit "Agree" or "Disagree" options, ensuring conscious decision-making.
Step 3: Data terminology clarification
After policy agreement, users learn about ChatGPT's technical terminology in plain language. This page clarifies how ChatGPT analyzes conversations, uses data to improve the model, and processes information.
Step 4: Memory storage personalization
Users choose whether ChatGPT tracks their previous searches and conversations, providing granular privacy control from the start of their experience.
Step 5: Multi-factor authentication setup
Users can set up or opt out of multi-factor authentication. If they opt in, they can choose between SMS authentication, authentication app, or third-party authentication app for enhanced account security.
Step 6: Review and finalize selections
Finally, users see an overview of their selections, which they can review and modify before continuing to ChatGPT. This ensures complete transparency and control over privacy preferences.
It was important to make this sequence clear and straightforward to inform users about how ChatGPT works while presenting important options from the start without overwhelming users.
While this creates a longer account creation process, our research showed the critical need for initial education before users begin using the application. Without this, users are forced to discover privacy features themselves—or never at all.
We created an interactive Figma prototype to help existing users understand and navigate ChatGPT's privacy-related features after account creation.
Navigate and modify data controls and privacy preferences
Find and access privacy documentation within the interface
Understand and use private conversation modes
Interact with and control ChatGPT's memory features
The walkthrough begins in the settings by describing privacy-related features in Security, Privacy, and Data Controls, highlighting the new location of the "Terms and Policies" link.
Settings introduction and navigation
Data controls guidance
Memory update interaction
Temporary chat feature
This capstone project provided valuable insights into the intersection of AI technology and user privacy, highlighting critical gaps in current interface design that impact user awareness and control over their personal data.