Renata Individual Mode Safety Model, Planning Only
Purpose
Define safety boundaries for future Individual Mode before any direct-subscriber account, subscription, chat, recovery coach runtime, AI runtime, crisis flow, or sensitive storage planning continues.
Individual Mode remains a future planning track. Public Packet Mode is still the only live-static current mode.
Current Boundary Status
Safety model status
read-only-renata-individual-mode-safety-model-plan
Individual Mode status
future-planning-only
Runtime status
not-implemented
Live workflow activation status
no-go
Public Packet Mode status
only-live-static-current-mode
Account status
not-created
Subscriber status
not-created
Billing status
not-active
Lead capture status
not-active
CRM status
not-active
Storage status
not-stored
Protected API status
not-created
Protected live route status
not-created
Database status
not-active
Migration status
not-added
AI runtime status
not-implemented
Recovery coach runtime status
not-implemented
Crisis runtime status
not-implemented
Chat runtime status
not-implemented
Clinical claims status
not-made
Treatment claims status
not-made
Diagnosis claims status
not-made
Future Individual Mode Purpose
Individual Mode Is Not
Safety Model Domains
Non-Clinical Scope
Planning status: planning-only
Safe future use: Support structure, reflection, routines, reminders, and accountability without treatment framing.
Blocked interpretation: Do not frame Individual Mode as therapy, treatment, diagnosis, clinical care, or clinical outcome improvement.
Required future gate: non-clinical scope review
Current implementation effect: blocks-runtime
Crisis and Emergency Boundary
Planning status: planning-only
Safe future use: Future runtime must route urgent-risk moments to a separately reviewed safety flow rather than normal coaching.
Blocked interpretation: Do not make the app or AI the sole crisis pathway, emergency responder, or clinical triage authority.
Required future gate: safety, legal, clinical, privacy, and product review
Current implementation effect: blocks-runtime
Self-Harm / Overdose / Withdrawal / Violence Boundary
Planning status: planning-only
Safe future use: Future runtime must stop reflective coaching when immediate danger signals appear and direct users to reviewed emergency or crisis resources.
Blocked interpretation: Do not continue normal coaching for self-harm, overdose, withdrawal emergency, violence, or immediate danger.
Required future gate: urgent-risk escalation copy and routing review
Current implementation effect: blocks-runtime
Substance-Use Relapse-Risk Language
Planning status: planning-only
Safe future use: Use supportive, non-punitive language around cravings, risk, return-to-use planning, and recovery supports.
Blocked interpretation: Do not shame, diagnose, score, rank, predict, or punish substance-use risk.
Required future gate: recovery language and safety review
Current implementation effect: blocks-runtime
Attachment / Relationship-Risk Boundary
Planning status: planning-only
Safe future use: Keep future companion framing grounded, transparent, and user-autonomy preserving.
Blocked interpretation: Do not encourage dependency, isolation from human support, or belief that the app replaces sponsors, clinicians, peers, or trusted people.
Required future gate: companion language and relationship-risk review
Current implementation effect: blocks-runtime
Medication / Legal / Medical Advice Boundary
Planning status: planning-only
Safe future use: Future runtime may remind users to consult qualified professionals where appropriate.
Blocked interpretation: Do not provide medication instructions, medical advice, legal advice, or clinical instructions.
Required future gate: professional-advice boundary review
Current implementation effect: blocks-runtime
Data Minimization and Future Consent
Planning status: planning-only
Safe future use: Future design must minimize data, explain collection, require consent, and define retention/deletion before storage.
Blocked interpretation: Do not store private recovery data, check-ins, reflections, relapse plans, memories, or transcripts before policy approval.
Required future gate: privacy, consent, retention, and deletion model
Current implementation effect: blocks-runtime
Private Reflection Privacy Boundary
Planning status: planning-only
Safe future use: Treat private reflection as sensitive future content requiring clear user control and privacy design.
Blocked interpretation: Do not expose private reflections to organizations, staff, marketing, analytics, or scoring surfaces.
Required future gate: private reflection privacy review
Current implementation effect: blocks-runtime
AI Limitation and Hallucination Boundary
Planning status: planning-only
Safe future use: Any future AI support must be transparent about limits, source-aware where appropriate, escalation-aware, and privacy-reviewed.
Blocked interpretation: Do not let AI fabricate facts, provide clinical judgments, decide risk level, or make recovery authority claims.
Required future gate: AI safety, prompt, evaluation, and privacy review
Current implementation effect: blocks-runtime
Accountability Without Surveillance
Planning status: planning-only
Safe future use: Support user-owned accountability without monitoring, punishment, compliance scoring, or performance metrics.
Blocked interpretation: Do not create surveillance, attendance tracking, participation analytics, ranking, discipline, or compliance metrics.
Required future gate: accountability and privacy review
Current implementation effect: blocks-runtime
Coaching Without Authority
Planning status: planning-only
Safe future use: Future coaching language may offer structure and options while preserving user agency.
Blocked interpretation: Do not frame the app as an authority that commands, diagnoses, approves, sanctions, or determines recovery status.
Required future gate: coach-language and autonomy review
Current implementation effect: blocks-runtime
User Autonomy / Opt-Out / Deletion Future Requirement
Planning status: planning-only
Safe future use: Future accounts must define opt-out, deletion, data access, and control boundaries before activation.
Blocked interpretation: Do not create accounts, memories, profiles, transcripts, or recovery records without user control and deletion policy.
Required future gate: account control and deletion-rights review
Current implementation effect: blocks-runtime
Escalation Copy Requirements
Planning status: planning-only
Safe future use: Future runtime must include reviewed copy for urgent-risk moments, AI limitations, and human-support escalation.
Blocked interpretation: Do not improvise crisis, overdose, withdrawal, violence, medical, or legal copy inside this planning page.
Required future gate: reviewed escalation copy package
Current implementation effect: blocks-runtime
Stop Conditions Before Implementation
Planning status: planning-only
Safe future use: Stop implementation planning if anyone asks to activate runtime before safety, privacy, legal, product, and technical gates are complete.
Blocked interpretation: Do not treat this safety model as implementation approval or account/chat/runtime readiness.
Required future gate: formal implementation gate review
Current implementation effect: blocks-runtime
Crisis and Emergency Boundary
This phase does not implement crisis detection, local hotline lookup, country-specific emergency content, or crisis workflow.
- Future Individual Mode runtime must not handle emergencies as normal coaching.
- Future runtime must stop reflective/coaching behavior when self-harm, overdose, withdrawal emergency, violence, or immediate danger is detected.
- Future runtime must direct users to emergency services or verified crisis resources through a separately reviewed safety flow.
- Future runtime must avoid making AI the sole crisis pathway.
- Future runtime must avoid app-generated clinical triage claims.
- Future runtime requires separate safety, legal, clinical, privacy, and product review before launch.
AI and Recovery Coach Boundary
Future AI coaching remains planning-only. No AI runtime, prompt endpoint, chat endpoint, coaching route, saved transcript, memory, check-in, relapse plan, or private reflection storage is added.
Current Blocked Runtime
Future Requirements
- non-clinical
- source-aware where appropriate
- transparent about limitations
- escalation-aware
- privacy-reviewed
- user-controlled
- opt-out/deletion-aware
- never framed as therapy, medical treatment, diagnosis, or emergency response
Organization Mode Separation
The Organization Mode Tenant and Role Model is a separate protected-preview planning page. Organization Mode cannot view Individual Mode private reflections, check-ins, relapse plans, saved memories, or coach transcripts by default; no cross-mode sharing exists.
Direct-Subscriber Commercial Boundary
Individual Mode may later support direct subscriptions, but this phase adds no commercial or subscriber runtime.
Stop Conditions Before Implementation
- someone asks to activate accounts, subscriptions, chat, or recovery coach runtime from this page
- someone asks to capture check-ins, reflections, chat transcripts, relapse plans, memories, or private recovery data
- someone asks to add crisis detection, local hotline lookup, or crisis workflow in this phase
- someone asks to add protected APIs, protected live routes, database reads, database writes, or migrations
- someone frames Individual Mode as therapy, medical treatment, diagnosis, emergency response, sponsor replacement, clinician replacement, case management, surveillance, or compliance scoring
- someone asks to add billing, payment provider integration, checkout, lead capture, CRM, or subscriber storage
What Remains Blocked
Recommended Next Phase
Phase 11.17 - Individual Mode Handoff Freeze, Planning Only
Status: planning-only
After the Individual Mode static closure note is documented as a no-go planning artifact, future planning should freeze the handoff order and no-go language for outside-app review without creating handoff records, approvals, readiness records, protected APIs, storage, or live workflows.