AI-based privacy-focused library app
The privacy-oriented library app addresses the challenge of balancing privacy and access by implementing AI-driven personalization, two-way authentication, and real-time compliance checks, ensuring secure and compliant access to library resources.
Patent Information
- Application Number
- DE202025102835
- Authority / Receiving Office
- DE · DE
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-08-07
- Estimated Expiration
- 2035-05-31
AI Technical Summary
Libraries face challenges in balancing user privacy protection with continuous information access, particularly when using third-party services, as existing Android apps collect and share personal data without user awareness, compromising mental freedom and privacy.
A privacy-oriented library app with AI-controlled personalization, two-way authentication, a privacy dashboard, and real-time compliance checks, ensuring secure access and data control through encryption and anonymous data handling.
Enhances user data security and privacy, allowing users to maintain mental freedom with secure access to library resources while adhering to privacy laws, using AI-driven personalization and encryption to protect personal and non-personal data.
Abstract
Description
TECHNICAL FIELDThe present invention relates to privacy-oriented library apps and is based on library science-tailored principles to provide secure access to library resources and protect users privacy.BACKGROUNDAs electronic resources have become more and more popular in recent 20 years, libraryaries take a leading role in protecting their users' online privacy from external hazards. They must therefore ensure that the legal requirements of authorities and external service providers are complied with and that at the same time the users are granted a certain degree of control over their personal and non-personal data, since this is indispensable for the protection of their online privacy. Thus, libraries are currently difficult to find a trade-off between protecting their users' privacy and ensuring continuous information access. The ability to understand complex security and privacy policies, protect library users' privacy, allow access to resources, or compromise or pricing personal data, particularly when using third party services, as well as external monitoring threats are some of the complex challenges that library operators must share in providing online resources. To provide smooth access to information while preserving users privacy and fairly distributing online information demand without compromising users' mental freedom, libraries must make difficult decisions.The data analytics tools of Android apps collect a variety of private user data, including location data that could pass travel habits to third parties, gender data, and the user's interests and preferences, such as favourites, videos, or websites, as well as in-app interactions such as function selection, app registration time, and unique identifiers such as IMEI numbers and MAC addresses that could potentially result in the creation of user profiles. Users were not aware that their personal data was passed to analytical companies because many apps did not inform the users of their privacy policies. To account for privacy concerns regarding the confidentiality and security of their personal and non-personal data, privacy-oriented apps must be developed that are customized to library users.SUMMARYEmbodiments according to the present invention provide a privacy-oriented library application and a corresponding system. The privacy-oriented library application and the corresponding system include a privacy-oriented library app installed on the user device, an app activation process, AI-controlled personalization, a secret study finder, privacy settings, a privacy dashboard, real-time recognition, an application server, a processor, and a storage medium.Embodiments according to the present invention also provide a system for a privacy-oriented library application and a corresponding system. The aim of the concept is to increase data security and to allow library users to experience their mental freedom without jeopardizing their online privacy. The system includes receiving authentication data, user commands, network traffic, API queries and user activity data, processing the received data, reporting the monitored data, and ensuring protection.Embodiments of the present invention may provide a number of advantages depending on the configuration. Embodiments of the present application provide a system and a system with design principles that include multiple functions, including an activation process with two-way authentication and a privacy dashboard with an age matching function. The AI-directed personalization provides secure chat and encrypts communication between users, AI-LLMs, and library personnel. It has protection mechanisms for anonymous assessment, annotation, checking and sharing of resources. A design feature, such as a home learning room searcher with an automatically generated ID, ensures access to various learning areas. It also provides options for filtering rooms based on usage policies or for using the AI voice assistant. In the embodiment of the present invention, the privacy setting provides privacy keys with rating tests to measure the awareness of the users and to review their data. Moreover, the real-time compliance check, detection of privacy violations and security checks allow the app administrator to detect unusual data requests and to keep track of the latest changes in privacy laws. Finally, these functions allow further scaling of the app and at the same time provide a simplified user interface using AI technologies and other functions that give users maximum control over their data and at the same time improve their general access experience.These and other advantages result from the use of the embodiments described herein.The foregoing summary is provided to understand some embodiments of the present invention. It is neither exhaustive nor exhaustive and does not provide a complete overview of the present invention and its various embodiments. It represents selected concepts of the embodiments of the present invention in simplified form and is provided as an introduction to the following more detailed description. It is understood that further embodiments of the present invention are possible, which use one or more of the features mentioned above or described in detail below alone or in combination.DETAILED DESCRIPTIONA privacy-oriented library application and a system (hereinafter referred to as a system) according to an embodiment of the present invention. According to an embodiment of the present invention, the system may include a privacy-oriented library app installed on a user device, an app activation process, AI-controlled personalization, a secret study finder, privacy settings, a privacy dashboard, real-time recognition, an application server, a processor, and a storage medium.In an embodiment of the present invention, the application server may be, but is not limited to, a laptop, a desktop PC, or the like. The application server may be a cloud server in one embodiment of the present invention. Embodiments of the present invention are intended to include or otherwise cover any type of application server, including known, related, and / or later developed technologies.In an embodiment of the present invention, the application server may include the processor and the storage medium. In one embodiment of the present invention, the processor may be configured to execute programming instructions associated with the system. According to embodiments of the present invention, the processor may be, but is not limited to, a programmable logic controller (PLC), a microcontroller, a microprocessor, a computing device, a development board, etc. Embodiments of the present invention are intended to include or otherwise cover any type of processor, including known related techniques and / or later developed technologies.In an embodiment of the present invention, the storage medium may include the programming instructions. In an embodiment of the present invention, the programming instructions may be data processing executed by the processing unit to allocate bandwidth and provide security functions. The storage medium may be a non-transitory storage medium that may be configured to store the programming instructions for controlling the operations of the privacy oriented library application and the system according to an embodiment of the present invention. The storage medium may be, for example, a RAM memory, a ROM memory, a flash memory, and so forth. Embodiments of the present invention are intended to include or otherwise cover all types of storage media, including known, related, and / or later developed technologies.According to an embodiment of the present invention, communication unit 120 may utilize a network, such as a data network such as the Internet, a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), etc. Embodiments of the present invention are intended to include or otherwise cover any type of data network, including known, related, and / or later developed technologies. In another embodiment of the present invention, the network may be a wireless network, such as a cellular network, and may utilize various technologies, including enhanced data rates for global evolution (EDGE), general packet radio service (GPRS), etc. Embodiments of the present invention are intended to include or otherwise cover any type of wireless network, including known, related, and / or later developed technologies.According to one embodiment of the present invention, the system for developing innovative privacy-oriented apps for library users includes understanding the users' critical privacy concerns with respect to data security without compromising their user experience.According to an embodiment of the present invention, the system includes an app activation process that includes a multi-layered system that consists of a three-factor authentication, such as link verification, sent to a registered email address or phone number to ensure a privacy-oriented activation process.According to an embodiment of the present invention, the app activation process comprises two-way authentication. In the first step, users download the app via the QR code on the back of their activated library identification card. During installation, the app displays the library privacy policy in short sections as well as the minimum data for access to the application's services. To activate the app, users must grant their approval. Then, users must enter the e-mail address used in requesting a library ID. The system then sends an acknowledgement link to this email address. This link contains either an anonymous username or a randomly generated ID assigned to each user. To complete the activation process, users must click on the e-mail confirmation link and enter a passcode with the e-mail one-time password (OTP), and a CAPTCHA code. After completion of all steps, users only have to enter their passcode and the randomly generated ID for future access.According to an embodiment of the present invention, the app activation process includes the flow of the link. To ensure security and prevent unauthorized access, the e-mail link expires within 24 hours. To reactivate the app after 24 hours without activation, users must rescan the QR code on the back of their library identification card.According to an embodiment of the present invention, the app activation process comprises checking the forgotten password. Users must click on the "forget password" option and enter their active email address or telephone number registered with the library. After transmitting this contact data, users automatically receive an acknowledgement link that they must enter into the app in order to obtain access again.According to one embodiment of the present invention, the email ID or phone number captured upon app activation is masked by default to protect the users personal identities associated with the devices. The acquisition of e-mail ID and telephone number serves to verify unknown device applications, with verification by OTP enabling access to the app. With these concepts, the activation and reactivation systems of the library app focus on the privacy and security of the users. However, after the library ID or membership has expired, app access automatically ends, along with the minimum data (e.g., personal and non-personal data) acquired during the access period.According to an embodiment of the present invention, the system comprises a data protection dashboard. Upon first opening the app, a pop-up window appears that facilitates users to manage their privacy settings. After clicking on one of the options offered here, a 30-second animated video appears, highlighting the protection functions of three user-friendly data protection options-even accessible to minors and older users and equipped with AI voice assistance. A one-time click on the privacy settings prevents cookie pops each time a new web page or resource is visited. AI agents simplify the process to a single, one-time setting, where users can return to the privacy settings at all times and update their settings.In an embodiment of the present invention, the privacy dashboard may be a device used by a user. The admin dashboard may be, but is not limited to, a personal computer, a consumer device, or the like. Embodiments of the present invention are intended to include or otherwise cover any type of admin dashboard, including known, related, and / or later developed technologies. In an embodiment of the present invention, the PC may be, but is not limited to, a desktop, a server, a laptop, or the like. Embodiments of the present invention are intended to include or otherwise cover any type of PC, including known, related, and / or later developed technologies.In an embodiment of the present invention, the privacy dashboard may be, but is not limited to, a tablet, a mobile phone, a notebook, a netbook, a smartphone, a wearable device, a handheld device, or the like. Embodiments of the present invention are intended to include or otherwise cover all types of consumer devices, including known, related, and / or later developed technologies. Embodiments of the present invention are intended to include or otherwise cover all types of data protection dashboards, including known, related, and / or later developed technologies.According to an embodiment of the present invention, the privacy dashboard may include software applications such as a navigation application, a camera application, a media player application, a social networking application, and the like. In a preferred embodiment of the present invention, the privacy dashboard may comprise a computer application, which may be a computer readable program installed on the privacy dashboard for executing functions of the system.Further, in an embodiment of the present invention, the user device may be a device used by a user. The user device may be, for example, a personal computer, a consumer device, or the like. Embodiments of the present invention are intended to include or otherwise cover any type of user device, including known, related, and / or later developed technologies. In an embodiment of the present invention, the PC may be, for example, a desktop PC, a server, a laptop, or the like. Embodiments of the present invention are intended to include or otherwise cover any type of personal computer, including known, related, and / or later developed technologies.In an embodiment of the present invention, the user device may be, among other things, a tablet, a mobile phone, a notebook, a netbook, a smartphone, a portable device, a handheld device, etc. Embodiments of the present invention are intended to include or otherwise cover all types of user devices, including known, related, and / or later developed technologies.According to an embodiment of the present invention, the user device may comprise software applications, for example a navigation application, a camera application, a media player application, a social networking application, etc. In a preferred embodiment of the present invention, the user device may comprise a computer application, which may be a computer readable program installed on the user device for executing functions of the system.In the embodiment of the present invention, users may select three buttons or use the AI assistant configuring the "Maximum Privacy" button. By selecting this option, maximum anonymousization of all personal data (e.g., name, department, sex, phone number, family status, address, etc.) and non-personal usage data (e.g., leased print and E resources, desire lists, search and release history, playlists, read time, and other usage details) is ensured. Also, app fingerprinting is constrained (e.g., mobile device / tablet design, voice settings, font size, login time, camera access, location, API queries, device ID, network usage, etc.). Because the use of fingerprinting IDs across different devices or sessions may possibly result in inadvertent user identification, this setting allocates a randomly automatically generated ID at different update rates to ensure that it is not tracked. This gives users full control over their data. End-to-end encryption ensures that only users can access their accounts, regardless of whether the data is stored or transmitted.In the embodiment of the present invention, users may select three buttons or use the AI assistant configuring the "Medium Privacy" button. This option provides a balanced level of anonymousization of the users personal and usage data by a randomized, automatically generated ID with different update rates. There is no association with sensitive personal information (e.g., name, department, sex, telephone number, family status, address, etc.) or usage data. However, this setting does not provide protection from device level tracking or app fingerprinting.In the embodiment of the present invention, users may select three buttons or use the AI assistant configuring the "Low Privacy" button. This adjustment provides the lowest level of anonymousization. Users may search the app with either an assigned randomized, automatically generated ID or a self-selected name. When the automatically generated ID is selected, only personal data are protected. When the user selects his selected name, his data can be exposed and the protection of the user data is not guaranteed, especially when searching external resources.In the present invention, users may select three buttons or use the AI assistant configuring the button "AI-privacy". For advanced users who do not wish to select any of the three default options, a fourth button is available. This allows detailed control of the privacy and security settings using an AI voice announcement. Examples: "Hey Privacy Dashboard, Deactivate Cookie from this particular online supplier / aggregator." OR "What types of necessary cookie are captured, stored and passed to third party?" OR "Please present the privacy policies of this supplier / aggregator / publisher in simplified English."In the present invention, these privacy policies and cookie alerts are interpreted and displayed clearly and pregnantly in snippet format, avoiding skilled jargon, so that users can make informed decisions about their privacy. With this AI voice assistance, parents who allow their children to access the app can protect young users by enabling content filtering based on age-matched and user-defined data protection levels. It can also prevent logging of children's online activities depending on parent prompts. By default, when accessing institutional E-resources via the app, the users' personal identities and device information are masked. However, if users agree or pass personal information directly to service providers (e.g., through self-registration), security and privacy of that data is outside of the control of the privacy dashboard functions of the app.According to an embodiment of the present invention, the system and system comprises AI-controlled personalization. This function encrypts communication for information services between users, AI-LLM models, and library personnel.In a preferred embodiment of the present invention, the AI-controlled personalization comprises a user-employee query. All communication between users and library personnel is end-to-end encrypted. For example, a randomly generated access key is generated by the AI agents for each ticket, for example for a "long and specific request" which requires the intervention of a technical library provider. The library staff returns the response to these tickets to each access key so that no personal data needs to be passed.In a preferred embodiment of the present invention, the AI-controlled personalization comprises chat and recommendation. Users may use information services or make requests using KI-LLM models. These are trained by libraryaries (e.g., from records of a particular library that uses the app) to answer both short and long queries without storing the users' chats or data on the central server. For example, the AI-LLM chat box recommends reading recommendations based on the usage data stored on the user's device.In a preferred embodiment of the present invention, the AI-controlled personalization comprises a rating moderation. The app enables users to like, evaluate, review, and share certain chapters, articles, books, etc. anonymously. However, it also offers users the possibility of either using the automatically generated ID or creating a new pseudonym profile when clicking on the tab "Like", "Evaluate", "Review publish" or "Share". To maintain annunciation of anonymous scores, integrated AI tools recognize Hasreden or Spam and report them to the app administrator to meet the platform standards.According to an embodiment of the present invention, the system and system includes a private learning location finder. This function helps users find a learning space suitable for them and book a learning cabin or a quiet learning area in the library. This AI function operates on real-time data integrated into the library's local RFID system.In the embodiment of the present invention, the private learning space finder enables anonymous accounting. Users can search for and book rooms of their choice using an automatically generated ID assigned to each registered user without having to price personal data. Using real-time data of the app, the AI recognizes and locates a preferred learning space and displays a pop-up with the available types of learning spaces.The storage medium may include the programming instructions in the form of programming modules, such as a data receiving module, a data processing module, and a reporting module.
Claims
A privacy-oriented library application and a corresponding system, the system comprising: a privacy-oriented library app installed on the user device; an app activation process; AI-controlled personalization; a secret study finder; a privacy setting; a privacy dashboard; real-time discovery; a processor on an application server; and a storage medium configured to store programming instructions executable by the processor; wherein the storage medium comprises: a data receiving module configured to receive authentication data, user commands, network traffic, API queries, and user activity data; a data processing module configured to process the received data; and a reporting module that continuously monitors and ensures protection displayed in the privacy dashboard; wherein the app provides end-to-end encryption, identity masking, remote identity checking, and anonymous data processing.The system of claim 1, wherein the user device is configured to communicate with the application server using a communication unit.The system of claim 1, wherein the app activation process comprises two-way authentication, the left-running function, and the "forget password" function.The system of claim 1, wherein the AI-controlled personalization utilizes user-employee queries, chat, recommendations, and rating moderation.The system of claim 1, wherein the private study finder uses anonymous bookings, private space filters, secure access, and availability warnings.The system of claim 1, wherein the privacy settings comprise private taps, the private settings change capability, a privacy rating, and a privacy audite.The system of claim 1, wherein the privacy dashboard is configured for real-time detection including compliance checking, negotiation suggestions, and detection of violations.