Choosing companions

Source/event record · Guide · prepared 19 September 2026

A household companion needs rules for the people who did not install it

A one-page charter covers microphones, shared rooms, notifications, guests, children, purchases and the right to pause a connected companion.

Prepared for local review · Site publication: not set · 471 words

A companion on one person’s phone can still speak on a kitchen counter, display intimate notifications on a lock screen, hear a roommate or appear to a child. Individual account consent does not settle shared-space consent. A household charter makes ordinary boundaries explicit before a surprising moment turns into a conflict.

Map the shared surfaces

List every place the companion can appear: phone speaker, smart display, headset, television, car, robot, lock screen and shared tablet. Mark microphones, cameras, cloud connection, voice activation and purchasing. NIST’s consumer smart-home guidance recommends getting household agreement before bringing in a device and reviewing security and privacy features. A software companion deserves the same practical conversation even when it has no dedicated hardware.

Write five default rules

  • Private by default: headphones and hidden notification previews in shared spaces.
  • Ask before capture: no recording, photos or camera use around others without permission.
  • No proxy consent: one account holder cannot enroll another person’s voice or face.
  • Pause means pause: any household member can request silence in a shared room.
  • Purchases need an owner: require authentication and name who can approve charges.

Add rules for guests, children, work calls and overnight quiet hours. This is a household agreement, not surveillance of the primary user.

Configure the device to match

Turn off unused integrations, limit lock-screen content, use a distinct account, enable multi-factor authentication and place connected devices on an appropriate network segment. NIST IR 8425 describes capabilities expected of consumer IoT products, including product configuration, data protection and cybersecurity-state awareness. The charter cannot compensate for controls a product does not offer; record those gaps.

Use a hypothetical boundary check

Suppose Alex uses voice chat in a shared living room. The household agrees on headphones after 9 p.m., no wake-word listening, no camera use when guests are present, and notification previews hidden. A visiting child asks the companion a question; Alex ends the session rather than treating curiosity as parental permission. After an update, the household rechecks the microphone and notification settings.

Review after change

Revisit the page when someone moves in, a child gains device access, hardware is added, or an update changes permissions. Anyone should be able to withdraw shared-space permission without having to argue about the relationship’s value.

Agree on a consequence before a breach

If a notification exposes private relationship language on a shared display, hide previews immediately and review whether the device remains an appropriate surface. If the microphone activates around a guest, end the session and explain what was captured before resuming. Repeated boundary failures can mean removing the integration from the room. Predetermined consequences reduce arguments about intent and keep the focus on the household member whose privacy was affected.

Boundaries protect both use and non-use. Pair this charter with the privacy control audit and the notification audit to turn agreement into settings.

Sources & reading trail