Recognising the problem
One of the challenges with privacy is that people often do not recognise the problem in the first place. In design discussions, a feature can appear harmless or even helpful. Teams may shrug their shoulders and move on because nothing looks obviously wrong. The privacy implications only become visible when someone pauses and questions the context in which the data is being used.
Even when that moment happens, privacy problems are hard to formalise. It is not always obvious what they look like in practice, or how engineers should go about identifying them in real systems.
In our training on application privacy, we focus on practical, technical thinking rather than dashboards or purely compliance-driven conversations. And yet, even in deeply technical discussions, privacy behaves differently from traditional security findings. It often feels less precise than traditional security findings, less concrete. It is harder to formalise.
Engineers want actionable, technical guidance. We want that too. “You’ll know it when you see it” is not a satisfying answer for a development team trying to build responsibly.
And yet, in practice, that instinctive recognition plays a powerful role. That tension is where Context & Cringe began.
Cringe as a signal
Rather than attempting to define privacy harm purely in formal terms, we began experimenting with something more immediate: the visceral reaction.
The game invites players to combine elements of an app with different forms of data use and deliberately try to create (or avoid) the most “cringey” outcome, the scenario that feels viscerally uncomfortable.
“Cringe” becomes a proxy.
It stands in for a kind of privacy harm that may be difficult to encode in a technical requirement or articulate in policy language, but is easy to recognise intuitively. It is hard to formalise, but easy to feel when you see it.
During one of our game workshops, the participants created the scenario of a taxi service using religious information to “improve” service. One person may argue that it is a legitimate use case, tailored to user needs. Another may immediately feel uneasy. The vigorous discussion that followed shows where the learning happens.
Same data. Same feature. Different context, different reactions. Privacy reveals its subjectivity very quickly.
Moving beyond “you’ll know it when you see it”
There is a tension in how privacy problems are discussed.
On the one hand, privacy is often described as “squishy”. Less crisp than traditional security issues. Even with taxonomies and frameworks, formally identifying privacy problems in real systems is not straightforward. On the other hand, we cannot leave engineers with vague intuition alone. What we observed was that people often do recognise the moment when something feels uncomfortable, but they struggle to explain why. The reaction comes first. The reasoning comes later. Context & Cringe was designed to surface that moment.
The game is not a complete framework for privacy design. It does not replace structured analysis. Instead, it helps surface the instinctive reaction that often precedes it. It makes visible the moment something “feels off”, before we can fully articulate why.
Cringe is not the final answer. It is the starting point.
Our broader work focuses on making privacy usable for builders. The goal is not to strip away nuance, but to translate it into tools and approaches engineers can meaningfully apply.
Designing for disagreement
One of the most powerful aspects of using “cringe” as a learning device is that it exposes disagreement. In a room of engineers, designers and privacy professionals, not everyone reacts the same way. What feels intrusive to one participant may feel justified to another. The debate itself becomes the lesson.
By forcing players to construct scenarios deliberately and then discuss them openly, we make visible what is often left implicit. Small contextual shifts - purpose, audience, perceived intent - can dramatically amplify or reduce discomfort.
Rather than telling participants what is right or wrong, the gameplay encourages them to explore why they reacted the way they did. Understanding your own reaction is useful.
From theory towards experience
Context & Cringe did not begin as a product idea. It grew out of years of teaching privacy as a contextual, layered problem, one that is both deeply technical and deeply human. Our realisation was not that privacy lacked theory. It was that theory alone did not always change behaviour.
By focusing on that emotional signal, the moment of discomfort, we found a practical way to make context visible. Not by explaining it more, but by letting people experience it.
Cringe makes context tangible. And once you learn to notice it, you can design with it.
In our next article, we’ll look at how that thinking gradually evolved into a structured, repeatable format, and how an idea rooted in theory became something people could actually play.