Behavision: face recognition for retail, edge to head office

Five components that ship as one product:

- behavision/  the recognition engine. RTSP ingest, YuNet detection, IoU
               tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
               FastAPI dashboard. Identity is decided once per TRACK from an
               average of at least three embeddings, never per frame.
- agent/       the Go edge agent: supervises the engine, holds a durable
               spool, and drains it to MQTT. Nothing is acked before the
               broker confirms.
- desktop/     the shop PC application (Wails + React + tray).
- server/      the cloud API, MQTT consumer, reports and assistant.
- web/         platform.loyaly.ai, the head-office app, embedded in the
               server binary.

The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.

CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
This commit is contained in:
2026-09-04 11:14:18 +05:30
commit dad04e8cda
216 changed files with 40473 additions and 0 deletions

59
web/src/views/Login.jsx Normal file
View File

@@ -0,0 +1,59 @@
import { useState } from 'react'
import { api } from '../api.js'
export default function Login({ onSignedIn }) {
const [email, setEmail] = useState('')
const [password, setPassword] = useState('')
const [error, setError] = useState('')
const [busy, setBusy] = useState(false)
const submit = async (e) => {
e.preventDefault()
setBusy(true)
setError('')
try {
await api.login(email.trim(), password)
onSignedIn(await api.me())
} catch (err) {
// The server's own wording. It says the same thing for an unknown address
// and a wrong password on purpose - telling them apart turns this form
// into a way to find out who works at a customer.
setError(err.message)
setBusy(false)
}
}
return (
<div className="signin">
<form className="card" onSubmit={submit}>
<span className="mark big" aria-hidden="true" />
<h1>Behavision</h1>
<p className="sub">Sign in to your company account.</p>
<label>
Email
<input
type="email" value={email} autoComplete="username" autoFocus required
onChange={e => setEmail(e.target.value)} placeholder="you@company.com"
/>
</label>
<label>
Password
<input
type="password" value={password} autoComplete="current-password" required
onChange={e => setPassword(e.target.value)}
/>
</label>
{error && <p className="error" role="alert">{error}</p>}
<button className="primary" disabled={busy || !email || !password}>
{busy ? 'Signing in…' : 'Sign in'}
</button>
<p className="foot">
Accounts are created by Loyaly. Ask your account manager if you need one.
</p>
</form>
</div>
)
}