Renata Individual Mode private data planning

Renata Individual Mode Private Data and Consent Model, Planning Only

Protected-preview planning artifact for future private data labels, consent, user control, and cross-mode separation.

Purpose

Phase 11.6 defines the private data and consent model that must exist before any future Individual Mode account, storage, chat, AI, billing, or protected runtime work begins. The page records no consent, stores no private data, and creates no runtime path.

Current Boundary Status

Future Private Data Categories

These categories are planning labels only. They are not collected, stored, shared, exported, downloaded, processed by AI, or made visible to Organization Mode.

Consent and User-Control Model

  • explicit opt-in before collection
  • plain-language notice before collection
  • purpose limitation
  • data minimization
  • user-controlled visibility
  • no default Organization Mode access
  • revocation / opt-out
  • deletion rights
  • export/access rights
  • retention limits
  • consent versioning / consent receipt as future concept only
  • separate consent for cross-mode sharing
  • separate consent for AI processing
  • separate consent for crisis/escalation resource handling, if ever applicable
  • separate consent for marketing/research/analytics, default blocked

Data Minimization Rules

  • Do not collect more than needed for the user-owned recovery purpose.
  • Do not collect resident/staff/program identifiers in Individual Mode by default.
  • Do not collect organization affiliation unless a separate account/sharing model is approved.
  • Do not store crisis, medical, legal, or clinical details without separate legal/privacy/safety review.
  • Do not use private data for scoring, ranking, compliance, surveillance, marketing, or organization reporting.

Cross-Mode Boundary

  • Individual Mode private data is separated from Organization Mode by default.
  • Organization Mode cannot see direct-subscriber check-ins, reflections, relapse plans, memories, coach transcripts, support contacts, or private records by default.
  • No staff dashboard, review queue, analytics surface, tenant admin, or organization owner view can inspect Individual Mode private data.
  • Any future sharing requires separate explicit consent plus privacy, legal, product, and technical review.
  • No cross-mode bridge is implemented in this phase.

AI / Data Boundary

Blocked Now

  • no OpenAI processing for direct-subscriber content
  • no AI processing of private content
  • no prompt endpoint
  • no chat endpoint
  • no prompt/completion storage
  • no chat transcript storage
  • no memory storage
  • no risk scoring
  • no clinical judgment

Future Requirements

  • separate consent for AI processing
  • prompt/evaluation/privacy review
  • cost/budget gating
  • safety testing
  • data retention rules
  • deletion/export policy before activation

Crisis Boundary

  • No crisis detection is implemented.
  • No hotline lookup is implemented.
  • No crisis workflow is implemented.
  • No triage is implemented.
  • No dispatch is implemented.
  • No emergency routing is implemented.
  • No local emergency content is implemented.

Commercial Boundary

no billingno checkoutno Stripe/payment providerno trial signupno lead captureno CRMno marketing funnelno customer recordsno support recordsno subscriber storage

Stop Conditions

  • someone asks to collect consent in the app
  • someone asks to store check-ins, reflections, relapse plans, support contacts, memories, transcripts, prompts, completions, consent receipts, or crisis records
  • someone asks to create accounts, login, signup, identity capture, billing, checkout, lead capture, or CRM
  • someone asks to add chat, AI runtime, recovery coach runtime, OpenAI processing, prompt endpoints, chat endpoints, protected APIs, protected live routes, database reads/writes, or migrations
  • someone asks to make Organization Mode private-data visibility active by default
  • someone asks to use private data for scoring, ranking, compliance, surveillance, marketing, clinical judgment, or organization reporting
  • someone asks to implement crisis detection, hotline lookup, crisis workflow, triage, dispatch, emergency routing, or local emergency content

What Remains Blocked

no live accountsno loginno signupno identity captureno account storageno subscriber storageno consent captureno consent recordsno private reflection storageno check-in storageno relapse-plan storageno craving/trigger note storageno routine storageno support-contact storageno memory storageno chat transcript storageno prompt/completion storageno crisis record storageno sensitive storageno chat runtimeno AI runtimeno recovery coach runtimeno crisis runtimeno emergency-service runtimeno OpenAI processing for direct-subscriber contentno prompt endpointno chat endpointno protected live routesno protected APIsno database readsno database writesno migrationsno formsno inputsno buttonsno textareasno checkboxesno selectsno upload controlsno export controlsno downloadsno generated PDFsno generated ZIPsno billingno Stripe/payment providerno checkoutno lead captureno CRMno marketing funnelno organization visibility into Individual Mode private datano staff dashboard for direct-subscriber datano analytics / scoring / ranking / compliance metricsno clinical claimsno treatment claimsno diagnosis claimsno medication adviceno legal adviceno case-management claimsno patient monitoring

Recommended Next Phase