{"id":"1c64888a-c739-43d5-ba65-13de2d4e5b08","arxiv_id":"2502.05686","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"Trajectory-based location features raise privacy concerns more than points of interest, and some obfuscation raises comfort, but the paper's own summary tables contain internal inconsistencies.","lead":"A survey of 1,405 Americans finds that people are less comfortable sharing detailed trajectory data, such as frequent routes, than visits to points of interest, and that some obfuscation of location features increases comfort. The results could inform FTC rules for data brokers that sell individual location data.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Unquantified post hoc exclusion of vignette responses on free-text quality could bias the key feature and obfuscation effects; report counts and re-run without exclusions.","rationale":"The reader identifies vignette operationalization as the weakest assumption. That is a genuine measurement-validity threat, and I partially agree with it. However, the more decisive issue is the unquantified, outcome-dependent exclusion of responses. Even granting perfect vignette comprehension, the analysis would still be invalid if the analytic sample is a non-random subset created by an unreported filter correlated with the dependent variable. The free-text explanation is part of the same response; deleting cases where text 'does not match' the Likert answer is equivalent to deleting uncomfortable or confused respondents, and there is no evidence this is orthogonal to feature type or demographics. This concern is directly checkable by the authors, whereas the vignette-comprehension concern would require a new study. The internal contradiction about mean comfort levels in RQ2 and Table 14 is also real, but it is a supporting-claim inconsistency rather than the central load-bearing threat. Since the current manuscript already receives a CONDITIONAL verdict, my read does not change the verdict; it strengthens the conditions by adding explicit reporting and robustness requirements around the exclusion rule.","tokens_in":29757,"tokens_out":4986,"duration_ms":55097,"concrete_test":"Obtain from the authors the full anonymized response-level dataset with exclusion flags. First, report the overall excluded N and counts stratified by feature, actor, purpose, race/ethnicity, education, and response time. Second, compute inter-rater reliability (Cohen's kappa) on a random subset of the manual reviews. Third, re-estimate the mixed-effects ordinal regression in Section 4 / Table 5 on the unfiltered data and on data filtered only by the 10-second rule. If the key odds ratios (detailed trajectory features below 1; obfuscated walking, home, and work features above 1) shift materially or lose significance, the central claims are not robust to the exclusion rule.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claims rest on the mixed-effects ordinal regression in Table 5, but the analytic sample is not the 7,025 vignette responses described in Section 3.2. Section 5 states that responses were removed when the required free-form explanation \"did not clearly match\" the selected Likert comfort level, based on manual review by two researchers who \"agreed upon its quality,\" plus removal of responses faster than 10 seconds. No exclusion counts, criteria, or inter-rater reliability are reported. This is outcome-dependent filtering: whether a response is kept depends on the participant's written justification for the same comfort rating that is the dependent variable. If the probability of exclusion varies by feature (e.g., participants write vaguer or shorter justifications for complex trajectory maps), the finding that detailed trajectories lower comfort and obfuscation raises comfort could be amplified or even produced by the filter. It could also differentially remove responses from lower-education or non-native English speakers, directly threatening the RQ3 demographic comparisons. Because the exclusion rule is applied after data collection and is not pre-specified, no reader can tell whether the odds ratios in Table 5 (e.g., Most Frequent Trips Detailed OR 0.74; Frequent Walking Activity Obfuscated OR 1.58) survive without it. This is the most load-bearing gap: all three headline findings pass through this filter.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports a factorial vignette survey of 1,405 U.S. participants, each answering five randomized vignettes that combine actors, purposes, and location features, with features presented in detailed or obfuscated forms. The authors fit a weighted mixed-effects ordinal regression (Table 5) to estimate effects on a 5-point comfort scale, use Kruskal-Wallis and Dunn post-hoc tests for interaction analyses, and train classifiers to predict comfort from vignette and demographic or privacy-attitude features. The headline findings are that detailed trajectory features reduce comfort relative to detailed points of interest, some obfuscation practices increase comfort, and race/ethnicity and education are associated with differences in comfort; the abstract also reports a predictive F1 score of 0.6.","tokens_in":29964,"tokens_out":6605,"duration_ms":71235,"significance":"If the central empirical findings hold, the paper makes a useful contribution to the contextual-integrity literature on location privacy by extending it from points of interest to trajectory-derived features and to current data-broker obfuscation practices. The factorial design is appropriate for the research questions, and the use of a mixed-effects ordinal model with random intercepts for participant and vignette is a sound analytic choice, supported by assumption checks and model comparison in the appendix. The paper also provides a large set of interaction and subgroup analyses that are transparently reported in the appendix. The main risk is not the analytic framework but the quality and comparability of the analytic sample after the exclusions described in Section 5, plus a few claims that outrun the reported numbers.","major_comments":[{"comment":"The response-exclusion procedure is not quantified and is outcome-dependent. The text reports that 7,025 vignette responses were reduced by removing answers whose free-text explanations \"did not clearly match\" the selected Likert comfort level, judged by two researchers who \"agreed upon its quality,\" plus responses faster than 10 seconds. No exclusion counts, explicit coding criteria, or inter-rater reliability are given, and the analytic sample size for Table 5 is never stated. Because whether a response is kept depends on the written justification given for the same comfort rating that is the dependent variable, differential exclusion across features, actors, purposes, or demographic groups could produce or amplify the headline effects in Table 5, such as Most Frequent Trips (Detailed) OR 0.74 and Frequent Walking Activity (Obfuscated) OR 1.58. Please report how many responses were removed by each criterion, by feature/actor/purpose and by demographic stratum, and re-estimate the main regressions and RQ2 mean comparisons with and without these exclusions as a robustness check.","section":"Section 7 and Table 14"},{"comment":"Section 7 states that \"all means were higher for obfuscation features than for their detailed counterpart,\" but Table 14 contradicts this: International visits (Detailed) has mean 0.286 versus 0.247 for International visits (Obfuscated), and Work location (Detailed) has mean 0.268 versus 0.263 for Work location (Obfuscated). This \"all\" claim is load-bearing for RQ2, which the abstract summarizes as \"some data broker based obfuscation practices increase levels of comfort.\" Please revise the claim to the subset of features for which the data actually show higher means, and correct the related sentence in Section 10 (\"the mean values were lower\") if it was intended to say \"higher.\"","section":"Section 8 and Table 5"},{"comment":"The abstract and conclusion claim that education has an effect on data-sharing privacy perceptions, but Table 5 shows no statistically significant education coefficient (Bachelors and above OR 0.814, p=0.103; Under Highschool OR 0.983, p=0.94). The only supporting evidence is the exploratory interaction analysis in Section 8.2 and Table 22. The claim should be limited to the interaction results and the conclusion reformulated accordingly, or the main-effects regression should be complemented by a preregistered or otherwise explicitly confirmatory interaction test. As written, the abstract overstates what the primary model supports.","section":"Section 9 and Tables 7-8"},{"comment":"The predictive modeling section does not describe how the 80/20 train/test split handles the repeated-measures structure of the data. Each participant contributes five vignette responses, and Model 2 includes individual privacy attitudes as features; a random split can place the same participant's other responses in the training set, leaking individual-level information and inflating the reported F1 of 0.6. Please use participant-grouped cross-validation (for example, GroupKFold or leave-participants-out) and report class frequencies and per-participant performance, or explicitly justify why a response-level split is appropriate.","section":"Section 3"},{"comment":"The validity of every comfort rating depends on participants' comprehension of the synthetic visualizations, but the only reported validation is a qualitative study with 5 Craigslist respondents who each answered 10 vignette questions. That is weak evidence for comprehension across 1,405 participants from a broader U.S. panel, especially because the detailed and obfuscated visualizations differ substantially in visual complexity. Please add a quantitative comprehension check or report coding of the free-text explanations by feature type to show that non-comprehension does not vary systematically across features and obfuscation conditions; otherwise the feature comparisons in Table 5 may partly reflect reactions to visual complexity rather than to the intended location feature.","section":"Section 5"}],"minor_comments":[{"comment":"The justification for the 10-second cutoff cites an average adult reading speed of \"100-1200 words/min,\" which appears to be a typo; 1200 words per minute is far above typical reading speeds. Please correct the range and show the response-time distribution used to motivate the cutoff.","section":"Section 8.1"},{"comment":"There is an unresolved cross-reference in Section 8.1 to \"Tables ?? in the Appendix\"; please replace it with the actual table numbers for the race/ethnicity interaction analyses.","section":"Table 1 and Table 5"},{"comment":"The feature names are not fully consistent between Table 1 and the regression rows in Table 5 (for example, \"Places you visit\" versus \"Places you Visit\"); harmonize the naming so readers can map each regression coefficient back to the corresponding vignette visualization.","section":"Section 3.2 and Table 4"},{"comment":"The text calls the sample \"U.S. representative,\" while Table 4 shows notable deviations for Hispanic participants (7.6% versus 14.9% of the census) and for the education-by-race cells; \"approximately representative\" with the weighting description would be a more precise characterization.","section":"Section 10"}],"recommendation":"major_revision","confidential_remarks":"The manuscript is within scope for a computers-and-society venue and the empirical contribution is timely. The main issue for publication is not the analytic approach but the transparency of the exclusion pipeline: the absence of exclusion counts and robustness estimates leaves the central odds ratios in Table 5 undetermined. The Section 7 \"all means\" claim is contradicted by the paper's own Table 14 and should be corrected regardless of other revisions. I did not treat the paper's novelty claims as blocking, but the literature review could be strengthened to support the \"first\" statements about trajectory-feature perceptions."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Hi [Colleague],\n\nThe thing to know: this paper is the first large-scale measurement I've seen of US comfort with trajectory-level location features (frequent trips, walking routes, inferred transport modes) and with the obfuscation variants data brokers actually use. Prior work mostly stops at POI visits, so the feature set is a real contribution. The factorial vignette design is appropriate, the sample is roughly US-representative at n=1,405, and the mixed-effects ordinal regression is the right tool. The central findings—detailed trajectory features are less comfortable than POI visits, and some obfuscated features (walking, home/work at census-tract level) are more comfortable—are supported by the reported coefficients and consistent with prior actor/purpose results.\n\nThe soft spot is Section 5's sample-exclusion step. The authors removed vignette responses whose free-text justifications 'did not clearly match' the selected Likert comfort rating, manually reviewed by two researchers 'who agreed,' and also dropped responses under 10 seconds. No counts, criteria, or inter-rater reliability are reported. Because the exclusion depends on the same rating that is the dependent variable, it is outcome-dependent filtering. If people write vaguer justifications for complex trajectory maps, or if the filter disproportionately affects lower-education or non-native-English respondents, the feature and demographic effects could be amplified. I don't think this invalidates the paper, and the stress-test note is right that it is the most load-bearing gap. But the authors need to report exclusion counts, pre-specify criteria, and re-run the analysis with and without the excluded responses. That is a quick check and would settle it.\n\nSmaller issues: Section 7 claims all obfuscated means were higher than detailed counterparts, but Table 14 shows International visits and Work location go the other way. There is a broken 'Tables ??' cross-reference in Section 8.1. No code or data are shipped, only a promise to share 'if required.' The F1=0.6 in the abstract is only for the model with privacy attitudes added as inputs; that is disclosed in Section 9.2, but the abstract overstates it somewhat. The 5-participant Craigslist pilot for vignette comprehension is thin; I'd have liked a validation item inside the main survey.\n\nBottom line: the measurement contribution is genuine, the statistics are mostly sound, and this deserves a serious referee. I'd send it to review with a clear request to fix the exclusion reporting and the Table 14 contradiction before the headline findings are relied on. I'd also encourage the authors to release the anonymized data.","headline":"Real new measurement of trajectory-feature privacy perceptions, but the headline effects depend on an unreported post hoc exclusion step; deserves review with a revision request.","tokens_in":30532,"tokens_out":4189,"would_cite":true,"duration_ms":39425,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that Americans' comfort with sharing location data is determined more by what is extracted—detailed trip routes versus obfuscated census-tract summaries—than by whether tracking happens at all, and that obfuscation…","keywords":["location data privacy","data brokers","obfuscation","trajectory data","privacy perceptions","factorial vignette survey","mixed-effects ordinal regression","comfort prediction"],"falsifier":"Have a fresh sample of participants view the same vignette either with its interactive visualization or with a text-only description of the feature, and compare comfort ratings; if the visualization changes ratings substantially, the measured 'feature' effects are partly artifacts of the graphic. A second check: ask participants after the vignette what the map actually showed (e.g., that the polygon is their home county, that the straight line is not the real route); if a large share misidentifies these elements, the comfort levels do not correspond to the intended features.","tokens_in":29525,"feed_emoji":"📍","tokens_out":12349,"duration_ms":103242,"temperature":0.7,"pith_summary":"This paper claims that Americans' comfort with sharing location data depends mainly on the specific feature being extracted—detailed trip routes and walking paths feel intrusive, while obfuscated versions of the same features feel acceptable—not just on whether tracking happens at all. The claim comes from a factorial vignette survey in which 1,405 U.S. participants rated 7,025 randomized scenarios pairing nine actors, ten purposes, and eighteen location features, with each feature shown in a detailed and an obfuscated form. The results show trajectory features are associated with the strongest discomfort, that obfuscation to census-tract or county level raises comfort substantially, and that Hispanic respondents report higher comfort than White respondents. If the findings hold, they give data brokers and regulators a user-grounded basis for deciding which location features should require explicit consent and which privacy-preserving transformations actually reassure people.","feed_headline":"Obfuscated location data feels fine; detailed routes feel like stalking","feed_subtitle":"Vignette survey of 1,405 Americans shows census-tract and county-level summaries erase most of the discomfort.","key_machinery":"The paper's machinery is the factorial vignette: each survey item presents a fixed template—'Actor X wants to do Purpose Y, and for that they need Feature Z'—with one of nine actors, ten purposes, and eighteen location features drawn from the plausible combinations (445 total). Each feature comes in a 'detailed' version (GPS points, exact routes, pin-point home) and an 'obfuscated' version (census tract or county, charts without routes, straight lines between tract centroids), and every vignette is accompanied by an interactive map or chart so respondents see exactly what the feature would look like. Comfort is measured on a 5-point Likert scale and modeled with a mixed-effects ordinal logistic regression in which participant ID and vignette identity are random effects; interaction effects between features and actors or purposes are then probed with Kruskal-Wallis and Dunn post-hoc tests, and the same data feed supervised classifiers for predicting comfort from context, demographics, and privacy attitudes.","core_discovery":"On the paper's own terms, the central discovery is a quantitative map of U.S. privacy comfort across the specific location features that data brokers actually sell. Using a vignette survey in which each question paired one actor, one purpose, and one location feature, the authors show that trajectory-based features are consistently associated with lower comfort than visits to points of interest: the odds of being comfortable with detailed most-frequent-trips are 0.74 times the odds for detailed places visited (p<0.05). Obfuscation reverses this: obfuscated frequent walking activity (odds ratio 1.58), obfuscated home location (1.55), and obfuscated work location (1.46) are each significantly more comfortable than the detailed-place-visits baseline. Race also matters: Hispanic respondents have 1.65 times the odds of White respondents of rating a scenario comfortable, while no significant overall education effect appears in the main regression. Finally, a supervised model that adds privacy attitude answers to the actor-purpose-feature-demographic tuple reaches an F1 score of 0.60 for binary comfortable-versus-uncomfortable prediction.","pith_inferences":["The paper's feature set does not include health-care, religious, or protest destinations as explicit trip types, so the measured comfort for detailed trajectories probably overstates comfort for the most sensitive destination categories; a vignette set that adds these destinations would test whether the 'stalking' reaction intensifies.","Obfuscation comfort may signal perceived rather than actual anonymity: a census-tract polygon still reveals the home neighborhood, and a straight line between tract centroids still reveals commute direction; a follow-up that asks respondents what an adversary could infer from the obfuscated map could separate perceived from actual privacy.","The predictive jump from F1 around 0.28 to 0.60 when privacy attitudes are added suggests a short attitudes questionnaire, not demographics, is the scalable predictor of location-sharing comfort; the paper does not propose such an instrument, but the data support building one."],"forward_implications":["Data brokers and app SDKs could offer per-feature consent screens organized by the six feature clusters, letting users opt into detailed versus obfuscated versions rather than a single all-or-nothing location permission.","Regulators writing bright-line rules for location data could reasonably treat detailed trajectory features (frequent trips, walking routes) as higher-risk than place-visit categories, and treat obfuscation to census-tract level as a meaningful mitigation.","Because obfuscated walking activity and home or work locations reach comfort levels at or above detailed place visits, a default-obfuscated data pipeline with an opt-in for detail would align data broker practice with measured user preferences.","Comfort prediction that reaches F1 0.60 using actor-purpose-feature plus demographics and privacy attitudes is accurate enough to let companies pre-test a new location feature's acceptability before deployment, though not precise enough to replace consent."],"supporting_citations":[{"why":"Supplies the actor and purpose lists and the privacy-attitude controls that the vignettes and regression are built on.","marker":"[11]"},{"why":"Provides cross-cultural precedents for actor and purpose effects that the survey extends to trajectory features.","marker":"[15]"},{"why":"Gives the framing that privacy comfort depends on who accesses data and for what purpose, motivating the vignette design.","marker":"[16]"},{"why":"Documents the census-tract home obfuscation practice used to design the obfuscated home feature.","marker":"[12]"},{"why":"Documents the trajectory-protecting obfuscation practice used to design the obfuscated movement features.","marker":"[13]"},{"why":"Supplies the taxonomy distinguishing obfuscation from anonymization, defining which techniques are studied.","marker":"[14]"},{"why":"Provides the statistical modelling approach, mixed-effects ordinal regression, for vignette data.","marker":"[62]"}],"fun_headline_variants":["Detailed routes feel like stalking; obfuscated features ease discomfort","Trajectory data triggers stalking concerns; blurred data feels fine","Obfuscation reduces discomfort with location data, survey finds","1,405 Americans: blurred location data soothes privacy fears"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the synthetic map and chart visualizations shown in the vignettes convey to each of the 1,405 participants the same concrete feature they would be asked to share—an assumption validated only by a qualitative pilot with five respondents before the main fielding.","fun_headline_variants_meta":{"raw":{"variants":["Detailed routes feel like stalking; obfuscated features ease discomfort","Trajectory data triggers stalking concerns; blurred data feels fine","Obfuscation reduces discomfort with location data, survey finds","1,405 Americans: blurred location data soothes privacy fears"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001653,"raw_usage":{"total_tokens":6609,"prompt_tokens":1037,"completion_tokens":5572,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":653,"completion_tokens_details":{"reasoning_tokens":5498}},"tokens_in":653,"tokens_out":5572,"duration_ms":39357,"temperature":1.0,"reasoning_tokens":5498,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-08T18:22:04.706511+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Have a fresh sample of participants view the same vignette either with its interactive visualization or with a text-only description of the feature, and compare comfort ratings; if the visualization changes ratings substantially, the measured 'feature' effects are partly artifacts of the graphic. A second check: ask participants after the vignette what the map actually showed (e.g., that the polygon is their home county, that the straight line is not the real route); if a large share misidentifies these elements, the comfort levels do not correspond to the intended features.","supporting_citations":[{"cited_title":"What is it about location? Berkeley technology law journal / Boalt Hall School of Law, University of California, Berkeley , 12 2019","cited_arxiv_id":null,"evidence_quote":"Supplies the actor and purpose lists and the privacy-attitude controls that the vignettes and regression are built on."},{"cited_title":"Kumar, and Jason Pridmore","cited_arxiv_id":null,"evidence_quote":"Provides cross-cultural precedents for actor and purpose effects that the survey extends to trajectory features."},{"cited_title":"Places data curated for accurate geospatial analytics, 2025","cited_arxiv_id":null,"evidence_quote":"Documents the census-tract home obfuscation practice used to design the obfuscated home feature."},{"cited_title":"https: //docs.spectus.ai/Getting%20Started/User_G uides/Data_Assets/Device_Recurring_Areas _and_Sensitive_Locations/#how-we-expose-t he-devices-recurring-areas","cited_arxiv_id":null,"evidence_quote":"Documents the trajectory-protecting obfuscation practice used to design the obfuscated movement features."},{"cited_title":"The long road to computational loca- tion privacy: A survey","cited_arxiv_id":null,"evidence_quote":"Supplies the taxonomy distinguishing obfuscation from anonymization, defining which techniques are studied."},{"cited_title":"Sta- tistical modelling of vignette data in psychology.British Journal of Psychology, 113(4):1143–1163, 2022","cited_arxiv_id":null,"evidence_quote":"Provides the statistical modelling approach, mixed-effects ordinal regression, for vignette data."}],"review_version":1}