Behavision: face recognition for retail, edge to head office

Five components that ship as one product:

- behavision/  the recognition engine. RTSP ingest, YuNet detection, IoU
               tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
               FastAPI dashboard. Identity is decided once per TRACK from an
               average of at least three embeddings, never per frame.
- agent/       the Go edge agent: supervises the engine, holds a durable
               spool, and drains it to MQTT. Nothing is acked before the
               broker confirms.
- desktop/     the shop PC application (Wails + React + tray).
- server/      the cloud API, MQTT consumer, reports and assistant.
- web/         platform.loyaly.ai, the head-office app, embedded in the
               server binary.

The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.

CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
This commit is contained in:
2026-09-04 11:14:18 +05:30
commit dad04e8cda
216 changed files with 40473 additions and 0 deletions

View File

@@ -0,0 +1,45 @@
import { useEffect, useState } from 'react'
import { api } from '../bridge.js'
// The customer's face, when there is one.
//
// Fetched when the sheet opens rather than stored with the customer row: the
// server hands out a signed link that expires in minutes, deliberately, so
// that "delete my data" can actually make a picture stop loading. A link kept
// in a list rendered an hour ago is a broken image.
//
// The fetch lives in a hook and happens ONCE per sheet, because the server
// writes an audit_log row for every read of a face image — "who looked at my
// customers" has to be answerable — and a component that fetched its own copy
// for the picture and again for the caption would put two rows in that log for
// one glance at one person.
export function useCustomerPhoto(id) {
const [photo, setPhoto] = useState(null)
useEffect(() => {
let alive = true
setPhoto(null)
api.visitorPhoto(id)
.then(p => { if (alive) setPhoto(p) })
// A failure to load a photo must never take the customer record with
// it: the name and phone number are what staff opened this for.
.catch(() => { if (alive) setPhoto({ available: false, reason: '' }) })
return () => { alive = false }
}, [id])
return photo
}
// No photo is the normal case — images are off by default — so this renders
// initials, not an error.
export default function CustomerPhoto({ photo, name, onBroken }) {
if (photo?.available) {
return <img className="avatar" src={photo.url} alt={`Photo of ${name}`}
onError={onBroken} />
}
const initials = String(name || '').split(/\s+/).filter(Boolean).slice(0, 2)
.map(w => w[0].toUpperCase()).join('') || '?'
return (
<div className="avatar none" role="img" aria-label={`No photo of ${name}`}>
<span>{initials}</span>
</div>
)
}