AURELIUS · PUBLIC BETA · ENTER →

01 // The Question

The Aurelius Experiment

Can an intelligent system become more useful as people contribute without requiring those people to become increasingly observable?

Aurelius is a privacy-first reflection commons. Contributors submit anonymous reflections that pass through a multi-stage privacy pipeline — hard PII redaction, AI-assisted semantic anonymization, and content moderation — before entering the collective. AI operates as a sensemaking layer over eligible public reflections, surfacing patterns, echoes, narrative synthesis, and ritual passages. The system is organized around the reflection as the record rather than the user as the product. Built on AWS (Lambda, DynamoDB, API Gateway, Amplify) with OpenAI for anonymization and collective intelligence.

02 // Constraints Become Architecture

Every technical decision emerged from a human constraint.

People should not need persistent identity to contribute

→ Anonymous contribution — no accounts, no profiles

Privacy should be structural, not a policy promise

→ Minimize collected data at the application level

Contributors should not become more observable over time

→ No cross-reflection linkage or activity history

PII disclosure should be impossible even if attempted

→ Hard privacy guarantee — system removes identity

03 // System Reconstruction

Architecture Map

Interactive reconstruction of the current production system. Select a mode to reinterpret the architecture. Select a journey to trace a signal path.

Journeys:
Browser clientReflectionPage.jsx → …HTTP API (us-west-2)Lambda (Node.js ESM)classifyReflection(ra…Return 400, no storagesanitizeHardPII(rawCo…semanticAnonymize(har…DynamoDB item constru…DynamoDB table (us-we…approved && publicapproved && public &&…WitnessCollectivePage…aureliusGenerateNarra…aureliusGenerateEchoaureliusGenerateScrip…aureliusInquiryGPT-4o-miniHTTP response (not pe…Structured JSON logsfield: shadow_eligibl…

04 // Privacy as Absence

Privacy is visible in what the system refuses to remember.

Privacy expressed as missing columns.

The reflection is the record. The contributor is not.

Stored

reflection_idtimestampcontent (sanitized only)pii_redactedprivacy_pipeline_versionhard_redaction_summarysemantic_privacy_appliedsemantic_privacy_entitiessemantic_privacy_risk_levelmoderation_statusmoderation_reasonvisibilityanalysis_eligibleshadow_eligiblecategorieslocation (city-level)themeperspectivesource

Absent from the application model

name / real_nameemailaccount / user_profilesession_historybehavioral_historyIP_addressdevice_fingerprintadvertising_idraw_unsanitized_contentcontributor_graphread_historyinteraction_timeline

Sanitized Example Record

{
  "reflection_id": "f47ac10b-58cc-4372-a567-0e02b2c3d479",
  "content": "There is something about the way a morning in [a city] feels after loss — not sadness exactly, but an openness that I did not choose. A close companion once told me that grief is just love with nowhere to go. I am beginning to think they were right.",
  "anonymous_user_id": "anonymous",
  "moderation_status": "approved",
  "visibility": "public",
  "analysis_eligible": true,
  "pii_redacted": true,
  "semantic_privacy_applied": true,
  "privacy_pipeline_version": "v1-hard-regex-plus-semantic-ai"
}

Application-layer scope

This describes the Aurelius application schema and persistence model. Infrastructure-level metadata (network logs, request headers) exists independently of the application data model and is not represented here.

05 // Recovered Logic

Principles become real when the system has to make a decision.

Aurelius translates its constraints into small, explicit decision boundaries: what gets removed, what can enter the collective, what remains hidden, and what downstream systems are allowed to see.

Privacy Gate / 01

Obvious identifiers are removed before anything else happens.

sanitizeHardPII(rawContent)

replaceAndCount(/[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,}/gi, "[EMAIL]")
replaceAndCount(/(\+?1[\s.-]?)?\(?\d{3}\)?[\s.-]?\d{3}[\s.-]?\d{4}/g, "[PHONE]")
replaceAndCount(/https?:\/\/[^\s]+|www\.[^\s]+/gi, "[URL]")
replaceAndCount(/@[a-zA-Z0-9._-]{2,30}/g, "[HANDLE]")
replaceAndCount(/\d{3}-\d{2}-\d{4}/g, "[SENSITIVE_ID]")
replaceAndCount(/\d{1,6}\s+.*?(Street|Ave|Blvd|Drive|Lane|Court)/gi, "[ADDRESS]")

The first privacy boundary is deterministic. Known identifier patterns are removed before semantic processing or persistence.


Semantic Privacy / 02

Identity can survive after the obvious identifiers are gone.

semanticAnonymize(hardRedactedText)
// model: gpt-4o-mini | temperature: 0.1

"Replace names with relational/contextual descriptors."
"Preserve emotional structure."
"Do not add new facts."

// person → "a close companion"
// workplace → "[an organization]"
// school → "[a school]"
// city → "[a city]"

A second pass uses AI to detect identity carried by meaning rather than formatting. The prompt itself is the privacy specification.


Collective Gate / 03

Preservation and publication are different decisions.

classifyReflection(rawContent) → {
  moderationStatus,  // approved | blocked | crisis_shadow | shadow_candidate | non_reflection
  visibility,        // public | hidden
  analysisEligible,  // true | false
  shadowEligible     // true | false
}

approved        → visibility: "public",  analysisEligible: true
shadow_candidate → visibility: "hidden", analysisEligible: true
crisis_shadow   → visibility: "hidden", analysisEligible: false
blocked         → never stored

Content can be preserved without automatically becoming public or entering collective analysis. Classification operates on raw text before any privacy processing.


Read Boundary / 04

Downstream systems do not receive everything that exists.

const isPublicReflection = (item) => {
  const moderationStatus = item.moderation_status?.S;
  const visibility = item.visibility?.S;
  const analysisEligible = item.analysis_eligible?.BOOL;

  return (
    moderationStatus === "approved" &&
    visibility === "public" &&
    analysisEligible === true
  );
};

// shadow_candidate: analysisEligible=true BUT visibility="hidden"
// → fails the visibility check → never reaches downstream

The read path fails closed. A stored reflection must explicitly satisfy every eligibility condition before it can surface downstream. Public is an explicit state, not a default.


Preservation / 05

Intense content does not have to be erased simply because it should not be surfaced.

// shadow_candidate assignment:
moderationStatus: "shadow_candidate"
visibility: "hidden"
analysisEligible: true   // field present
shadowEligible: true     // field present

// but downstream public endpoints enforce:
// visibility === "public" → fails
// result: stored, never surfaced, never analyzed
// shadow_eligible is architecturally present, operationally inert

The system can preserve difficult material without immediately publishing it. Storage, visibility, and analytical eligibility remain separate decisions. The shadow path exists structurally but has no active consumer.

06 // Excavation Layers

The architecture was not designed all at once. It was excavated.

Each layer emerged when an earlier assumption encountered the behavior of a real system. What began as a simple anonymous reflection interface became a set of increasingly explicit boundaries around identity, persistence, visibility, and collective analysis.

Layer 01

Anonymous Contribution

Participation does not require persistent identity.

Aurelius began by treating the reflection — not an account — as the fundamental record. No profile or persistent contributor identity is required to participate.

Layer 02

Privacy Before Persistence

An anonymous interface is not the same as an anonymous data model.

Removing accounts was insufficient if identifying information could still enter storage through the reflection itself. Privacy therefore became a processing boundary before persistence.

Layer 03

Storage ≠ Publication

Preserving something and publishing it are different decisions.

Moderation revealed that a reflection may be worth preserving without being appropriate to surface publicly. Storage and visibility became separate states.

Layer 04

Visibility ≠ Analysis

Hidden content should not automatically become collective intelligence.

Once Aurelius began generating echoes, narratives, scripture, and inquiry responses, visibility alone was no longer enough. Analytical eligibility became an independent boundary.

Layer 05

Fail Closed Downstream

A boundary enforced once is not necessarily a boundary enforced everywhere.

Legacy and test records revealed that submission-time classification was insufficient by itself. Downstream read paths now independently require explicit public and analytical eligibility before a reflection can enter collective outputs.

Privacy became less a feature of Aurelius than a property produced by overlapping boundaries.

07 // Interface Artifacts

The architecture eventually becomes an experience.

These are the surfaces through which Aurelius becomes legible to a participant: reflection, witnessing, synthesis, and inquiry. The interface is intentionally quieter than the machinery beneath it.

Artifact 01ReflectContribution Surface
Aurelius reflection interface — anonymous contribution surface

No account required. The contribution interface does not establish persistent contributor identity.

Artifact 02WitnessCollective Surface
Aurelius witness the collective — public reflections decoupled from contributor identity

Public reflections are decoupled from contributor identity. Witnessing does not require observing who contributed.

Artifact 03Patterns
Aurelius emerging patterns — AI-surfaced signals from eligible collective

AI surfaces patterns without claiming authority. Sensemaking, not prediction.

Artifact 04Scripture
Aurelius scripture generation — ritual passage from the collective

Collective material transformed into contemplative passage rather than feed or ranking.

What appears simple at the interface is supported by a deliberately complicated refusal to know more about the participant than necessary.

08 // Live Artifact

The experiment is still running.

This is not a reconstruction or screenshot. It is a reduced production interface connected to the same Aurelius submission pipeline.

Live ArtifactReflectProduction SurfaceLive System

Live System // Production Pipeline

Submissions made here enter the same Aurelius privacy, moderation, persistence, and eligibility pipeline documented above.

Open Aurelius in Full →

09 // Field Recording

Section pending — Phase 2

10 // The Experiment Continues

Aurelius is not presented here as a finished answer.

It is an experiment in whether intelligent systems can become more useful as people contribute — without requiring those people to become increasingly observable.

The architecture will change.
The constraints should not.

Enter the Experiment →

Public Beta · Active System · August 2026