Renata Individual Mode safety planning

Renata Individual Mode Safety Model, Planning Only

Protected-preview safety model for a possible future direct-subscriber, non-clinical recovery structure companion.

Purpose

Define safety boundaries for future Individual Mode before any direct-subscriber account, subscription, chat, recovery coach runtime, AI runtime, crisis flow, or sensitive storage planning continues.

Individual Mode remains a future planning track. Public Packet Mode is still the only live-static current mode.

Current Boundary Status

Future Individual Mode Purpose

private recovery structure supportdaily check-in supportreflection supportroutine buildingrelapse-prevention planning aidaccountability supportvalues/commitment remindersnon-clinical recovery coach companion framing

Individual Mode Is Not

not therapynot medical treatmentnot clinical diagnosisnot emergency servicenot crisis-only supportnot sponsor replacementnot clinician replacementnot case managementnot medication advicenot legal advicenot surveillancenot compliance scoringnot clinical outcome guarantee

Safety Model Domains

Crisis and Emergency Boundary

This phase does not implement crisis detection, local hotline lookup, country-specific emergency content, or crisis workflow.

  • Future Individual Mode runtime must not handle emergencies as normal coaching.
  • Future runtime must stop reflective/coaching behavior when self-harm, overdose, withdrawal emergency, violence, or immediate danger is detected.
  • Future runtime must direct users to emergency services or verified crisis resources through a separately reviewed safety flow.
  • Future runtime must avoid making AI the sole crisis pathway.
  • Future runtime must avoid app-generated clinical triage claims.
  • Future runtime requires separate safety, legal, clinical, privacy, and product review before launch.
no crisis detection implementationno local hotline lookupno country-specific emergency contentno crisis workflow

AI and Recovery Coach Boundary

Future AI coaching remains planning-only. No AI runtime, prompt endpoint, chat endpoint, coaching route, saved transcript, memory, check-in, relapse plan, or private reflection storage is added.

Current Blocked Runtime

no AI runtimeno OpenAI processing for real submissionsno OpenAI processing for direct-subscriber contentno prompt endpointno chat endpointno coaching routeno saved chat transcriptsno saved memoriesno saved check-insno saved relapse plansno saved private reflections

Future Requirements

  • non-clinical
  • source-aware where appropriate
  • transparent about limitations
  • escalation-aware
  • privacy-reviewed
  • user-controlled
  • opt-out/deletion-aware
  • never framed as therapy, medical treatment, diagnosis, or emergency response

Organization Mode Separation

The Organization Mode Tenant and Role Model is a separate protected-preview planning page. Organization Mode cannot view Individual Mode private reflections, check-ins, relapse plans, saved memories, or coach transcripts by default; no cross-mode sharing exists.

Direct-Subscriber Commercial Boundary

Individual Mode may later support direct subscriptions, but this phase adds no commercial or subscriber runtime.

no subscriber accountsno loginno identity captureno payment providerno Stripe/payment integrationno checkoutno trial signupno lead captureno marketing funnelno CRMno billing recordsno customer support recordsno subscriber storageno sensitive recovery data storage

Stop Conditions Before Implementation

  • someone asks to activate accounts, subscriptions, chat, or recovery coach runtime from this page
  • someone asks to capture check-ins, reflections, chat transcripts, relapse plans, memories, or private recovery data
  • someone asks to add crisis detection, local hotline lookup, or crisis workflow in this phase
  • someone asks to add protected APIs, protected live routes, database reads, database writes, or migrations
  • someone frames Individual Mode as therapy, medical treatment, diagnosis, emergency response, sponsor replacement, clinician replacement, case management, surveillance, or compliance scoring
  • someone asks to add billing, payment provider integration, checkout, lead capture, CRM, or subscriber storage

What Remains Blocked

no live accountsno loginno identity captureno account storageno subscriber storageno tenant storageno actor storageno draft storageno private reflection storageno check-in storageno chat transcript storageno relapse plan storageno submissionsno recovery coach runtimeno AI runtimeno crisis runtimeno emergency-service runtimeno protected live routesno protected APIsno database readsno database writesno active migrationsno OpenAI processing for real submissionsno OpenAI processing for direct-subscriber contentno clinical claimsno treatment claimsno diagnosis claimsno formsno inputsno buttonsno textareasno checkboxesno selectsno chat boxesno exportsno downloadsno generated PDFsno generated ZIPsno billingno payment provider integrationno Stripe integrationno lead captureno CRM integration

Recommended Next Phase