Renata Individual Mode memory boundary planning

Renata Individual Mode Memory and Continuity Boundary Plan, Planning Only

Protected-preview planning artifact for future memory, continuity, user control, deletion, export, hidden-memory prohibition, and cross-mode visibility boundaries.

Purpose and No-Go Status

Define memory and continuity boundaries before any future Individual Mode memory-like support, AI, chat, storage, accounts, billing, protected API, protected live route, database behavior, migration, or runtime work exists.

Public Packet Mode remains the only current live-static mode. This page creates no memory, profile, preference store, transcript, prompt/completion record, embedding, retrieval, AI, chat, account, billing, protected API, protected live route, database behavior, migration, or runtime.

Current Boundary Status

Future Memory-Like Category Labels

These are planning labels only. They do not imply storage, account records, hidden personalization, transcript memory, retrieval memory, or Organization Mode visibility.

What Must Never Be Hidden Memory

  • no unstated personalization
  • no invisible memory
  • no automatic memory creation
  • no memory inferred from crisis language
  • no memory inferred from relapse-risk language
  • no memory inferred from sensitive relationship disclosures
  • no raw transcript memory by default
  • no support-contact details by default
  • no crisis records by default
  • no legal, medical, or clinical details by default
  • no organization-visible memory by default
  • no cross-mode memory bridge
  • no staff-visible direct-subscriber summaries by default
  • no ranking, scoring, or compliance memory
  • no hidden analytics profile for marketing

Future Consent and User-Control Requirements

All requirements are future gates only. This phase creates no consent capture, consent record, memory preference, account profile, storage adapter, or runtime.

  • memory off by default
  • separate explicit opt-in before any memory
  • plain-language notice before storage
  • purpose limitation
  • granular memory categories
  • review before save
  • view all memory
  • edit memory
  • delete individual memory items
  • delete all memory / forget me
  • export/access rights before storage
  • retention limits
  • revocation and opt-out
  • no dark patterns
  • no continued personalization after revocation
  • separate consent for AI processing
  • separate consent for memory/continuity
  • separate consent for cross-mode sharing
  • separate consent for crisis/escalation handling if ever applicable
  • separate consent for research, analytics, or marketing; default blocked

Data Minimization Rules

  • Do not store raw transcripts if a smaller user-approved summary can serve the purpose.
  • Do not store crisis, legal, medical, or clinical detail without separate safety, legal, and privacy review.
  • Do not store support-contact details unless absolutely necessary and explicitly consented.
  • Do not store organization or program identifiers in Individual Mode by default.
  • Do not use memory for scoring, compliance, surveillance, ranking, marketing, or organization reporting.
  • Do not create permanent sensitive recovery records by default.
  • Do not keep memory longer than needed.
  • Do not use memory to pressure or shame the subscriber.

AI and Prompt Boundary

Crisis and Human-Support Boundary

Organization Mode Separation

  • Individual Mode memory and continuity data is hidden from Organization Mode by default.
  • No staff dashboard, tenant admin, organization owner, review queue, analytics surface, or cross-mode bridge can inspect Individual Mode memory or continuity data.
  • No organization-visible memory, direct-subscriber summary, private recovery history, or staff-facing continuity profile exists by default.
  • Future sharing requires separate explicit consent plus privacy, legal, product, and technical review.
  • No cross-mode memory bridge is implemented in this phase.

Commercial and Support Boundary

Stop Conditions

  • someone asks to add memory runtime
  • someone asks to store preferences, goals, values, routines, check-ins, reflections, relapse plans, transcripts, prompts, completions, support contacts, crisis records, or profiles
  • someone asks to add automatic memory
  • someone asks to add hidden memory
  • someone asks to add embeddings, vector storage, or retrieval memory
  • someone asks to add AI calls or prompt memory injection
  • someone asks to add chat runtime
  • someone asks to add OpenAI processing
  • someone asks to add accounts, login, signup, or identity capture
  • someone asks to add billing, checkout, Stripe/payment provider, lead capture, or CRM
  • someone asks to add protected routes or protected APIs
  • someone asks to add database reads, database writes, D1 access, or migrations
  • someone asks to make Individual Mode memory visible to Organization Mode
  • someone asks to use memory for scoring, compliance, ranking, surveillance, marketing, clinical judgment, relapse prediction, crisis triage, or staff reporting
  • someone frames memory as therapy, treatment, diagnosis, patient monitoring, case management, emergency support, sponsor replacement, clinician replacement, or clinical outcome improvement

What Remains Blocked

no memory runtimeno memory storageno hidden memoryno automatic memoryno profile storageno preference storageno routine storageno values storageno goals storageno check-in storageno reflection storageno relapse-plan storageno support-contact storageno crisis-record storageno prompt storageno completion storageno transcript storageno embedding/vector storageno retrieval memoryno background jobno OpenAI processing for direct-subscriber contentno AI provider configurationno prompt endpointno chat endpointno streaming endpointno chat runtimeno AI runtimeno recovery coach runtimeno crisis runtimeno accountsno loginno signupno identity captureno account storageno subscriber storageno protected live routesno protected APIsno database readsno database writesno migrationsno active migrationsno billingno checkoutno Stripe/payment providerno lead captureno CRMno support ticketsno formsno inputsno textareasno buttonsno checkboxesno selectsno upload controlsno export controlsno downloadsno generated PDFsno generated ZIPsno analyticsno scoringno rankingno compliance metricsno organization visibility into Individual Mode memoryno staff dashboard for direct-subscriber memoryno clinical claimsno treatment claimsno diagnosis claimsno medication adviceno legal adviceno emergency-care claimsno sponsor replacementno clinician replacementno case-management claimsno outcome guarantee

Recommended Next Phase