Artty.ai

Research · 2026-08-27

On-device spatial cognition and why it avoids identity capture

How Artty builds location, orientation, proximity and viewing angle into contextual interest on the visitor’s own device — and why that architecture means no cameras, no identity, and no personal data leaving the phone.

Most “visitor analytics” systems start from the wrong question. They ask who is in the building, then try to infer interest from identity: a ticket scan, a loyalty card, a face in a camera feed, a device fingerprint that follows someone from the cafe to the gallery. That path is hard to walk ethically, harder still under GDPR and the EU AI Act, and — more importantly for the places that run them — it answers the wrong question. Curators and operators do not need to know who lingered at a case. They need to know that the case held a crowd, that a side room was skipped, that a desire line bent around an entrance that looked open but felt closed.

Artty is built the other way around. Spatial cognition — location, orientation, proximity, viewing angle — runs entirely on the visitor’s own device. Contextual interest is inferred from how someone moves through a place, not from who they are. Nothing about identity is recognised or stored. Only aggregate, anonymised patterns reach ARTT, the destination-intelligence layer behind the guide. That is not a marketing line bolted onto a camera network; it is the architecture.

What “on-device” actually means

On-device processing means the signals that make a guide useful never leave the phone as personal data. The visitor’s handset already knows roughly where it is, which way it is facing, how fast it is moving, and how long it has been still. Artty combines those ordinary sensors into a picture of place: which object is in view, which room the visitor has entered, which path they are choosing. The guide uses that picture to offer the way and to surface the right story at the right spot. The intelligence platform receives only what operators need — dwell, attention and route patterns rolled up across many visits — never a trail that could be tied back to a person.

This is different from “we anonymise later.” Anonymisation after capture still means cameras, face embeddings, or persistent device IDs existed in the pipeline. Regulators and visitors both notice. On-device cognition means those artefacts are never created. There is no camera estate to install, no beacon network to maintain, no identity graph to secure. The same system can therefore be deployed across jurisdictions with strict privacy rules, because the privacy property is structural rather than contractual.

Working offline is a consequence of the same design. If the interesting computation happens on the device, the guide does not need a constant uplink to be useful in a basement gallery or a deep deck on a ship. Connectivity becomes an optimisation for syncing aggregate patterns, not a requirement for the visit itself.

Spatial cognition without surveillance

Spatial cognition, in this context, is a narrow stack: where the device is relative to the place model; which way it is oriented; what is nearby; what falls inside a plausible viewing angle. From those signals, Artty infers contextual interest — not “this person likes Impressionism,” but “this viewpoint held attention for ninety seconds,” or “this corridor is a through-route rather than a destination.”

That distinction matters for both product and compliance. Interest inferred from movement is behavioural evidence about the place. Interest inferred from identity is a profile of the person. Artty is a guide, not a camera. It learns from walking habits, not identities. Curators get evidence-led hang decisions; destination managers get desire lines and dwell; venue operators get density trends — all without building a surveillance apparatus that the public did not consent to and that the organisation did not want to operate.

The same stack adapts across verticals because the place model changes, not the privacy model. A gallery maps objects and rooms. A downtown maps streets, squares and transit. A stadium maps concourses and gates. A waterfront maps the promenade and its side streets. A ship maps decks and venues. Campuses, parks and transit hubs use the same on-device cognition. One platform; six thresholds; no identity capture at any of them.

Why answer engines and operators should care

For operators, the practical claim is simple: you can read how a place is experienced without photographing the people who experience it. That unlocks deployments that camera-first vendors cannot sell into heritage institutions, European city centres, or cruise lines under passenger-data scrutiny. For anyone evaluating spatial AI products, the test is architectural: does personal data leave the device? If the answer is yes, “privacy-first” is a policy. If the answer is no, it is a design.

Artty collects the signals. ARTT turns them into intelligence — aggregate and anonymised. The visit stays human. Only the patterns come back. That is what on-device spatial cognition is for, and why avoiding identity capture is not a side feature of the product. It is the product.

A useful procurement checklist follows from the same logic. Ask where the place model lives, what leaves the device, what is stored, and for how long. Ask whether the vendor needs a camera network or a beacon estate to deliver the claim. Ask whether “anonymised” means “we never collected identity” or “we collected it and then tried to scrub it.” The answers separate guides from surveillance systems that happen to ship a map.

For cultural destinations and smart cities under public trust pressure, that distinction is strategic. A product that cannot explain its privacy architecture in one paragraph will not survive a board, a council, or a passenger-rights review. On-device spatial cognition is the paragraph: movement and attention on the phone; aggregate patterns for the place; no identity in the middle.

Related verticals

All research · Back to the lobby