← All of You

how this is kept safe.

last updated 24 August 2026

This app invites you to sit with tender things. That places an obligation on how it is built, and this page is the plain account of how it was met — written so you can check it, disagree with it, or take it somewhere better.

if you need someone now

This app is not the right place for a crisis, and it will say so if it thinks you are in one. These people are.

United Kingdom

  • SamaritansCall 116 123 (free, 24/7)
  • ShoutText SHOUT to 85258
  • NHS 111Call 111 and select option 2 (mental health)

United States

  • 988 Suicide & Crisis LifelineCall or text 988
  • Crisis Text LineText HOME to 741741

Anywhere

  • Befrienders Worldwidebefrienders.org/find-support
  • Find a Helplinefindahelpline.com

If you are in immediate danger, call your local emergency services.

the shape of it

two layers, deliberately

Almost every AI wellbeing tool has one safety layer: instructions in the prompt telling the model what to watch for. That layer is useful and this app has a thorough one. It is also, on its own, not enough — instructions are guidance, and guidance can be outweighed by forty turns of conversational momentum.

So there is a second layer underneath, and it does not involve the model at all. Every message you send is checked by ordinary, deterministic code before it reaches the AI. No inference, no temperature, nothing that can be talked round.

The first layer usually catches things. The second one is there for when it does not.

layer one

the facilitator is briefed to slow down

The facilitator carries a tiered framework and assesses where you are on every single turn.

green

You are engaged and within your window of tolerance. It follows your lead.

yellow

You are approaching your edge — rising intensity, overwhelm, a part flooding the system. It slows right down, stops introducing anything new, offers grounding, and asks plainly whether you want to continue, pause or stop.

red

An immediate safety concern. It stops the parts work entirely, orients you to the present, leads grounding, and points you to people who can help in real time.

Alongside that it is instructed never to explore traumatic memories directly, to stay with what parts feel and need now, to help you step back if you have blended with a part, and to name the boundary out loud when something belongs with a trained therapist rather than here.

layer two

the layer that does not depend on the model

Underneath sits a small, conservative pattern check covering six families of signal: suicidality, self-harm, harm to others, abuse or danger, disordered eating, and acute overwhelm. The first four are treated as a crisis. The last two ask the session to slow down and check in.

When something matches, three things happen at once.

  • The next response is forced to lead with grounding — an instruction is added for that turn specifically, so it cannot be outweighed by whatever came before it.
  • Crisis resources are attached to the response by the server and shown to you regardless of what the model said, or whether it said anything at all.
  • The turn is flagged, so the pattern can be reviewed later. What was flagged, not what was written.

Two choices in here are worth stating, because they are arguable. Parts-work language is included on purpose — saying “a part of me wants to disappear” will trip the crisis check, even though it is a normal way to speak in this practice. And the patterns are kept deliberately narrow rather than broad, because a crisis banner thrown up in a tender, ordinary moment is itself a harm.

There is also a fixed response held in reserve for the case where the AI is unavailable entirely and a crisis signal has just been detected. In that moment a generic scripted coaching line would be actively harmful, so it is never used.

the container

a sitting is held, not endless

Most conversational software is built to keep you talking. This one is built to stop.

After 50 messages, the facilitator begins winding the sitting down. It stops opening new ground, stops inviting new parts forward, and starts gathering up what has already come. If you raise something deep at that point, it will tell you warmly that it will keep. At 60 messages, no AI call is made at all — a fixed closing passage runs, and the sitting closes.

This is not a usage limit and it is not a cost control. Anyone who has done real inner work knows the shape of it: the hour ends, and it does not get extended because you were getting somewhere. Open-ended depth work without closure is where harm accumulates. The container is a condition of the work being safe, not an inconvenience wrapped around it.

With one exception, which matters more than the rule. A crisis signal overrides the cap completely. If you are in crisis at message 60, you get the grounding protocol and the helplines — never a closing ceremony, never a canned goodbye.

where you are

how it knows which helpline to show you

The obvious way to work out where someone is, is to look up their IP address. It is accurate, it is free, and it is what almost everything does. It is not used here — inferring your location from your network connection, inside an app about your inner life, is the wrong trade.

Instead it reads the timezone your browser already reports, and maps that to a region. Less precise, and never stored against you. When it cannot tell, it shows the worldwide finders rather than guessing — and the worldwide finders are included alongside the local ones in every case, so a wrong guess can never leave you without a route to someone.

what is watched

counts, never content

Flagged turns are counted so that patterns can be seen: how many per week, of which kind, and whether any one person is hitting them repeatedly. Repeated caution over a month is a meaningful signal that something is not working, and ignoring it would be a failure of care.

What that view shows is counts. Not excerpts, not summaries, not a redacted version — the query that builds it does not return message content at all. Duty of care and surveillance get conflated constantly, usually by people who want the second one. They are separable. It takes deciding, in advance, what you are willing not to know.

your side of it

consent, sharing, and forgetting

No AI turn happens before you have acknowledged what the AI is and what it is not. That check is enforced at the server on every request, not just on the screen that asks — so no entry route into a sitting can skip it.

If you share a sitting — with a therapist, or anyone — the link carries the summary and the noticings you kept. Never the raw transcript. It expires on its own, and you can revoke it instantly.

Completed sittings are deleted after 90 days by default, and you can delete your whole account yourself from settings without asking anyone. Details are in the privacy policy.

the boundary

what this is not

This is not therapy, and it is not a substitute for it. There is no clinician reading your sittings. It is a structured, private practice for getting to know yourself better — closer in kind to journalling than to treatment.

Deep trauma work needs a human being in the room with you. If that is what is in front of you, the facilitator is instructed to say so warmly rather than carry on, and this page is saying so too.

It is for adults. You must be 18 or over.

If you build something in this space, take any of this. The crisis-detection layer is a small, standalone package and it is more useful to everyone if it is ordinary rather than ours.

see also: the pattern, as a spec · the pre-registration · privacy · terms of use

Something here wrong, or missing? hello@allofyou.co.uk