Renata Individual Mode UX planning

Renata Individual Mode Reflection and Check-In UX Plan, Planning Only

Protected-preview planning artifact for future non-interactive reflection and check-in anatomy.

Purpose and No-Go Status

Phase 11.7 defines a future Individual Mode reflection and check-in UX model before any account, consent capture, private storage, chat, AI, billing, protected API, protected live route, or runtime work begins. The page shows static UX anatomy and boundary rules only.

No reflection is captured. No check-in is captured. No prompt runs. No answer, draft, consent, account, private data, or workflow record is created.

Current Boundary Status

Future UX Principles

  • participant/subscriber-owned reflection
  • consent-aware before any storage
  • non-clinical language
  • user autonomy
  • non-coercive structure
  • no scoring or ranking
  • no surveillance
  • no hidden memory
  • no organization visibility by default
  • no app-only crisis pathway
  • no claims of treatment, diagnosis, therapy, or emergency support

Future Non-Interactive Check-In / Reflection Surfaces

These are static planning labels only. They are not real prompts, forms, response fields, check-ins, reflections, submissions, or stored records.

Future Prompt / Anatomy Language Boundaries

  • Static example prompt labels may be used only as non-interactive specimens.
  • Do not render answer placeholders, response fields, submit/save/start/skip/continue controls, sliders, toggles, uploads, chat boxes, or forms.
  • Use reflective, choice-oriented language rather than commands, compliance language, clinical labels, or staff-facing assessment language.
  • Avoid therapy, treatment, diagnosis, relapse prediction, patient monitoring, medication advice, legal advice, sponsor replacement, clinician replacement, or case-management framing.
  • Future prompts must include consent, privacy, crisis, and human-support boundaries before any runtime is considered.

User Autonomy and Non-Coercion Rules

  • Reflection must remain subscriber-owned.
  • Future structure should support choice without pressure, shame, punishment, scoring, ranking, or compliance framing.
  • Future UX must let the subscriber decline, opt out, delete, export, and control visibility before storage is considered.
  • No organization owner, tenant admin, staff dashboard, review queue, analytics surface, or cross-mode bridge may inspect Individual Mode private data by default.
  • No hidden memory, hidden tracking, hidden analytics, or organization reporting is allowed.

Privacy and Consent Reminders

Phase 11.6 remains the controlling private data and consent boundary. Future labels remain labels only until separate consent, storage, retention, deletion, export, security, and user-control gates are approved.

  • explicit opt-in before collection
  • plain-language notice before collection
  • purpose limitation
  • data minimization
  • user-controlled visibility
  • no default Organization Mode access
  • revocation / opt-out
  • deletion rights
  • export/access rights
  • retention limits
  • separate consent for AI processing
  • separate consent for cross-mode sharing
  • separate consent for crisis/escalation handling, if ever applicable
  • separate consent for marketing, research, or analytics, default blocked

Crisis and Human-Support Boundary

  • Future runtime must stop normal coaching or reflection for urgent-risk situations.
  • Future urgent-risk handling must route through a separately reviewed safety flow.
  • Renata must not be the sole crisis pathway.
  • Future UX must include human-support reminders without simulating emergency response.
  • No crisis triage, risk scoring, clinical judgment, emergency dispatch, or local hotline lookup exists in this phase.

AI / Prompt Boundary

Blocked Now

  • no AI runtime
  • no OpenAI processing for direct-subscriber content
  • no prompt endpoint
  • no chat endpoint
  • no streaming endpoint
  • no saved prompts
  • no saved completions
  • no transcript storage
  • no memory storage
  • no risk scoring
  • no clinical judgment
  • no diagnosis or treatment advice
  • no hallucinated resource behavior

Future Requirements

  • separate consent for AI processing
  • prompt/evaluation/privacy review
  • red-team and safety testing
  • cost/budget gating
  • data minimization
  • retention, deletion, and export policy before storage
  • transparent limitations and escalation-aware behavior

Organization Mode Separation

  • Individual Mode private reflection and check-in content remains hidden from Organization Mode by default.
  • No organization owner, tenant admin, staff dashboard, review queue, analytics surface, or cross-mode bridge can inspect direct-subscriber private data in this phase.
  • No staff-supported workflow can consume Individual Mode private reflections, check-ins, relapse plans, routines, support-contact records, memory records, prompts, completions, or transcripts by default.
  • Any future sharing requires separate explicit consent plus privacy, legal, product, and technical review.
  • No cross-mode bridge is implemented in this phase.

Stop Conditions

  • someone asks to add answer placeholders, response fields, forms, inputs, textareas, selects, checkboxes, buttons, submit/save/start/skip/continue controls, uploads, downloads, exports, or chat boxes
  • someone asks to collect or store check-ins, reflections, relapse plans, routines, support contacts, memories, prompts, completions, transcripts, consent records, or private data records
  • someone asks to create subscriber accounts, login, signup, identity capture, billing, checkout, lead capture, CRM, protected APIs, protected live routes, database reads/writes, or migrations
  • someone asks to add OpenAI processing, AI runtime, prompt endpoints, chat endpoints, streaming endpoints, recovery coach runtime, memory runtime, or risk scoring
  • someone asks to implement crisis detection, hotline lookup, local emergency content, triage, dispatch, emergency routing, crisis workflow, or crisis runtime
  • someone asks to make Organization Mode, tenant admins, staff dashboards, review queues, analytics surfaces, or organization owners able to inspect Individual Mode private data
  • someone frames the reflection/check-in UX as therapy, medical treatment, diagnosis, emergency support, sponsor replacement, clinician replacement, case management, medication advice, legal advice, relapse prediction, patient monitoring, compliance scoring, or clinical outcome improvement

What Remains Blocked

no live accountsno loginno signupno identity captureno account storageno subscriber storageno tenant storageno consent captureno consent recordsno private data recordsno check-in recordsno reflection recordsno relapse-plan recordsno routine recordsno support-contact recordsno memory recordsno chat transcript storageno prompt/completion storageno private reflection storageno live reflection captureno live check-in captureno chat runtimeno AI runtimeno recovery coach runtimeno crisis runtimeno emergency-service runtimeno OpenAI processing for direct-subscriber contentno prompt endpointno chat endpointno streaming endpointno protected live routesno protected APIsno database readsno database writesno migrationsno active migrationsno formsno inputsno textareasno buttonsno checkboxesno selectsno upload controlsno export controlsno downloadsno generated PDFsno generated ZIPsno billingno checkoutno Stripe/payment providerno lead captureno CRMno marketing funnelno organization visibility into Individual Mode private datano staff dashboard for direct-subscriber datano analytics / scoring / ranking / compliance metricsno clinical claimsno treatment claimsno diagnosis claimsno medication adviceno legal adviceno case-management claimsno patient monitoring

Recommended Next Phase