All work

Review & Manage Attachments

Launched the Review & Manage Attachments capability in 2025 to help customers confidently view, find, and delete the attachments they’ve shared with Alexa+.

Role
Lead UX Designer - Privacy & Trust
Timeline
Oct 2024 – Mar 2025
Team
Product · Eng · UX Research · Legal
Surfaces
Mobile app · Echo devices
What I owned
  • Owned the complete design of the feature, end to end.
  • Ran user research with our research partners: moderated usability studies and RITE sessions.
  • Defined the privacy framework and plain-language system across the review, retention, and deletion flows.
When sharing outpaced control

Alexa was becoming more than a voice assistant.

In late 2024, Alexa began moving out of the command-and-response era and into the age of large language models - a ground-up reinvention that became Alexa+.

The old Alexa took one-off commands. Alexa+ became something customers converse with and hand documents to: it could read an attachment, summarize a file, refer back to what they'd shared. So Alexa+ began holding customers' documents along with the context of why they were shared. A folder has no memory of the conversation around a file; this did.

That was a net-new design problem for our team. Sharing a file with Alexa+ is intentional: an invoice, a form, an itinerary, handed over because there's a reason to come back to it. So those documents needed a home of their own. Somewhere to find them without digging through chats, to see what's kept and for how long, and to remove what's no longer wanted. That cluster of small things is what earns trust. That trust is the feature.

The reframe

But shared files disappeared into the conversation.

Once a customer shared an attachment, finding it again meant going back through long conversation histories.

That worked poorly for the files people most wanted to revisit later - an invoice, an itinerary, a home document, a recipe, a school form.

Across moderated usability studies and RITE sessions - 50 participants in all - the same pattern repeated. Customers struggled to locate files, felt uneasy without a way to delete, and were unsure what Alexa retained after a conversation ended. Three recurring anxieties. Each one became a commitment.

Invisible
Make it visible
70%+
struggled to find a specific file quickly, often taking over 20 seconds or failing the task entirely.
Permanent
Make it controllable
75%+
said sharing files without a way to remove them made Alexa feel incomplete.
Unclear
Make it reassuring
60%+
were unsure what Alexa kept after a conversation ended, or for how long.
Designing for the file, not the chat

Rewrite the model.

The first version rolled out as a measured experiment, dialed up to 50% of customers, and the model got sharper across two deliberate revamps.

The first release just made attachments available - customers could see what they'd shared, but not delete it, and the list was rendered in a webview, so it leaned on old, off-platform components. The next revamp added deletion, but every file was still grounded in the conversation it arrived in: the metadata told them who shared it, when, and which chat it belonged to. That model broke on a simple fact - the same file gets referenced across many conversations. A document shared once and pulled up three more times doesn't belong to any single chat, and listing every conversation it had touched was neither scalable nor useful.

So I flipped the model: organize around the file, not the conversation. The UX research and RITE sessions said the same thing: people recognize a file by its name and who shared it, not by the chat it arrived in. I dropped the chat metadata entirely and surfaced file size in its place. The earlier per-row delete didn't scale either - more file actions were coming, and an always-exposed button was too easy to tap by accident - so I moved deletion into a deliberate swipe.

Starting point · view only
Earliest Review Attachments - deletion not yet supported, rendered in a webview

Rendered in a webview, so the components looked off-platform. No way to act on a file.

Revamp 01 · profile + chat name
First revamp - each file labelled with the profile who shared it and the chat it arrived in, with a per-row delete icon

Deletion capability arrives. Files are still labelled by the chat they came from, not by the file itself.

Revamp 02 · profile + file size
Shipped Review Attachments - redesigned around the file, with thumbnails, file size in place of the chat name, search, filters and file-level actions

What shipped: thumbnails, file size in place of the chat, filters, file-level actions.

In practice · Siya · runs a small baking business

A customer asks about a cake order from February. Siya opens Review Attachments, filters to her own profile, and - within seconds - she has the invoice open, the detail checked, the payment confirmed.

Now · all profiles
Shipped Review Attachments - a list organized by file across every profile, grouped by date, with thumbnails and file size as metadata

Every attachment across the household, grouped by date.

Filter by profile · who shared it
Profile filter bottom sheet - All profiles, Dan, Siya (checked), Matt; Siya selected

She narrows by the dimension she remembers: who shared it.

Narrowed to Siya · just her files
Review Attachments filtered to Siya, showing only her files including invoice_Lucas.pdf

The list collapses to just her files.

The invoice, found · quick view
invoice_Lucas opened in a quick view, showing a paid cake-order invoice

Quick view, on tap. Without scrolling a single chat.

Customers remember the file, not the chat.So I built retrieval around the file itself - filters and quick views.

Making deletion feel safe

But visibility alone wasn't enough.

Seeing attachments closed the transparency gap. It didn't close the trust gap.

Customers didn't just want to see their files - they wanted to remove the ones that felt sensitive, outdated, or no longer useful. Deletion became the core trust action.

The interaction had to be quick enough for everyday cleanup, but deliberate enough to prevent accidental removal. So I designed the deletion flow around confidence: act on the file directly, one plain-language confirmation before it goes, and a clear message confirming it's gone. For customers, this changed the experience from passive visibility to meaningful control - they could decide what stayed and what went.

In practice · Siya · gardening in her downtime

Siya keeps a stack of gardening manuals in Alexa+ to chat through her plants. She notices she's been leaning on an old guide, so she swipes to delete it - confirms once, and a message tells her it's gone for good. No second-guessing, no clutter.

Swipe to delete · file-level
Review Attachments - swiping the old gardenmanual.pdf row reveals download and delete actions

The swipe reveals delete, right where she's looking.

Confirm once · deliberate
Delete Attachment confirmation sheet asking Siya to confirm, with a Learn more link and Cancel / Yes, Delete buttons

One plain-language confirmation, with a “learn more” for what deletion means.

Gone for good · confirmed
Review Attachments after deletion - a confirmation message reads 1 attachment deleted and the manual is gone from the list

A message confirms it, and the manual is gone from the list.

Control had to feel fast, deliberate, and safe.Quick to reach. Hard to trigger by accident. And a clear, reassuring confirmation the moment a file is gone.

Words people could trust

Privacy messaging needed restraint.

Privacy experiences tend to fail in one of two ways - too vague to build trust, or too heavy to feel usable.

It needed to explain enough without turning into a wall of legal or technical language. I kept the interface to plain-language clarity: what the file was, who shared it, when it was added, where it could be managed, and what deletion actually meant.

In practice · Matt · just finished his taxes

Matt shared W-2s and receipts weeks ago and couldn't remember what Alexa still had. He opens privacy settings, reads in plain language exactly what's retained and for how long - and when he asks Alexa about an old upload, it tells him it was auto-deleted on his terms. No legal fine print, no second-guessing.

Settings · what's retained
Manage Your Alexa Data - plain-language privacy settings showing each data type and its retention, including Attachments set to auto-delete in 48 hours

Every data type spells out what's kept and for how long. Attachments auto-delete in 48 hours.

In conversation · honest answers
Documents query transcript - Alexa tells the customer their attachments were auto-deleted within 48 hours, and offers to review attachment settings

Alexa says what happened to a file, and offers the settings behind it.

The goal was to make privacy feel understandable, not alarming.

The decision I drove

Delete, or just archive?

The most important call on this work stream was deciding which privacy feature to build first.

As we scoped the first management action, the question went all the way up. Senior leadership was split between letting customers archive files or delete them.

Archiving only hides a file from view. The data, and its references inside conversations, stay, so Alexa could still reference an archived file and draw inferences from it in conversation. Legal pushed hard on exactly this. If a customer “removes” something but the model can still pull it back up, what does removal even mean? Deletion removes it everywhere, including every conversation that touched it.

So the design team pushed back on starting with archive. My argument was simple: customers only share sensitive documents when they believe they can truly take them back. I brought the research, the trust framing, and the customer scenarios to senior leadership and aligned them around deletion.

Deletion shipped first. Design didn't just inform that call. It drove it.

Trade-off
A confirmation step, by design
Early Alexa models had no deletion confirmation at all. Because deletion is permanent and the MVP shipped without undo, I defended adding a deliberate confirmation step - a moment of friction worth never compromising safety in a privacy-first flow.
What's nextAn undo action and “Recently Deleted” as lighter safety nets on top of it.
Trade-off
A dedicated page over inline
A single, dedicated management surface settled the “which chat owns this file?” ambiguity for good - and shipped faster than inline controls, which would have demanded real-time syncing across every thread and device.
The tradeManaging a file takes a quick step out of the chat - in exchange for one reliable place that scales.
The impact it had

Trust customers could feel.

Getting privacy right is what makes the whole document-sharing experience possible.

The experience launched in Early Access and is now full-fledged. People share more, and more sensitive, documents when the controls are honest and within reach.

6.25/7
CSAT score - exceeding our beta goals for the review and deletion experience.
+25%
improvement in customer trust score after the privacy controls shipped.
100M+
customers Alexa+ now serves, with privacy at the center of file sharing.
Building on the foundation

Where the experience goes next.

As Alexa+ takes on richer multimodal tasks, file management has to scale beyond review and deletion - toward more AI-native controls. Several of these directions came out of this work, and a few have already been green-lit into the roadmap.

Part of operational planning
Bulk actions
Select and remove multiple attachments at once - the same deliberate model, scaled to many files with a single confirmation.
Green-lit
Recently deleted recovery
A soft-delete window that lets customers recover removed content - speed balanced with safety.
Exploring
Voice-driven deletion
“Delete all my passport documents I shared yesterday” - Alexa surfaces the related files, confirms on-screen, and removes nothing until the customer says so. The same control, driven by voice on Echo.
Parked
Proactive cleanup
Alexa detects stale attachments and gently prompts a review. Promising, but not the priority yet.
Proactive cleanup
Lock-screen notification from Alexa: ‘Ready to clean up? Want me to clean up some attachments you haven’t used in a while? You can review attachments in settings before I delete anything.’

Alexa surfaces files you haven't used in a while and asks. Nothing is deleted without a review.

Recently deleted recovery
Recently Deleted folder with Attachments / Notes / Chats filters; items stay for 30 days before permanent deletion; a file row swiped open to reveal restore and delete-permanently actions.

Removed items wait 30 days, recoverable with a swipe.

Bulk actions · select & delete flow
Review Attachments list grouped by Today, Yesterday and date, with filter chips.
01
Open the attachment list.
Overflow menu sheet with Select and Delete all attachments options.
02
Tap the menu — Select, or delete all.
Selection mode with empty checkboxes on each file row; Cancel and a dimmed Delete in the header.
03
Selection mode — pick files to remove.
Two files checked; Delete now active in the header.
04
Check several at once; Delete activates.
Confirm deletion sheet asking to delete the selected attachments, with Cancel and Yes, Delete.
05
One confirmation before anything is removed.
Deletion confirmed banner; the removed files are gone from the list.
06
A clear confirmation, and the files are gone.

Multi-select scales the same deliberate model to many files at once.

Voice-driven deletion · on Echo
Echo Show screen: ‘Delete all my passport related documents that I shared with you yesterday.’ Alexa found 2 relevant documents - a passport image and a scanned form - shown as thumbnails, asking whether to delete both, with Yes / Delete passport image / Delete scanned form options.

The same controls follow the conversation onto Echo devices - natural voice, on-screen confirmation, nothing removed until the customer says so.

Part of a bigger shift

One of several initiatives moving Alexa into the age of AI.

Review & Manage Attachments was one of several I led and contributed to inside that shift.

A few others I contributed to
Conversation history
First designer from privacy to take it on - redesigning how multi-turn conversations appear in history, across Echo and mobile.
Privacy dashboard
Reworked a fragmented dump of settings into a clearer, more interactive place to understand and act on your data.
Personalization · “what do you know about me?”
A feature for how Alexa surfaces what it remembers about you - making personalization something you can see, not just something that happens.
What I'd carry forward

Designing trust into AI systems.

Privacy controls for AI aren't about adding more settings. They're about helping customers feel oriented and in control at the moment they need reassurance.

The strongest patterns were the simplest ones: clear entry points, plain-language explanations, and actions that felt deliberate without becoming heavy.

Next project - 01
Add to delivery
Back to top