Privacy by design
Privacy and boundaries
The MVP can run in mock mode. After model integration, chats are sent to the model provider you configure. In production, user conversations should not train the global model by default.
Sensitive memories require per-item confirmation. Users can delete, export or disable long-term memory.
The product does not diagnose, treat or replace clinicians. Crisis situations must switch to safety-first flows.
Recommended production defaults
- User conversations do not train the global model by default.
- Each sensitive long-term memory asks for per-item confirmation.
- Users can delete, export and disable long-term memory.
- Crisis scenarios switch to safety-first flows instead of deeper exploration.