Skip to main content
๐Ÿ†˜ In crisis right now?  Call 999  ยท  Samaritans 116 123 (free, 24/7)  ยท  text SHOUT to 85258  ยท  Mind urgent help โ†—

Privacy & Trust

Trust Centre ยท Last updated: 2026-09-16

Mental-health software is full of claims nobody ever checks. This page is the opposite: a single place that states plainly what Healing Space UK has, what it does not yet have, and where the evidence lives. If we cannot support a claim, we do not make it โ€” and our build pipeline fails if unsupported claims appear on our public pages.

Privacy, as something to earn

Vulnerability is not a commodity. The version of privacy worth having is not a promise in marketing copy โ€” it is what the architecture actually enforces, and what we are prepared to be held to:

  • Private by default. Shared deliberately. Reflections are private unless the patient shares them, per item and reversibly. An answer about whether something helped inherits the privacy of the item it is attached to, so an answer on an unshared reflection never reaches a clinician โ€” nor does the fact that one exists.
  • Captured is not shared. Writing something down and handing it over are two separate decisions, and the second one belongs to the patient. Some information is part of the clinical record and is not held back โ€” appointments, medications, and measures a service administers โ€” and we say which is which rather than implying everything is private.
  • No data farming. No advertising against therapeutic data, no sale of it to advertisers, insurers or data brokers, and no revenue anywhere that depends on how long someone stays in the app. Clinics pay a per-clinician licence; that is the entire model.
  • No casual staff access. Access runs through one central authorisation policy across every patient route, developers hold no standing access to clinical data, and sensitive reads are logged so there is an answer to who looked at what and when.
  • Data minimisation. The AI provider is not told who the patient is, who their clinician is, or what else is in their record; only the message being replied to is sent.
  • Named processors, not vague reassurance. They are listed below and in the privacy policy.
  • The direction of travel. We intend to move more processing to local or Healing-Space-controlled infrastructure where that is feasible. That is an intention, not a current capability, and it is listed here as one.

What we will not tell you: that nobody except you and your clinician can ever access your data. Hosting, email delivery and the AI conversation involve third-party infrastructure, staff with operational access exist in any real system, and a sentence that ignores both would be marketing rather than truth. What we will tell you is exactly who those parties are, what they see, and what is done to keep that set as small as possible.

Who processes what

ProcessorWhat it handles
RailwayCloud hosting of the application and its database.
GroqProcesses the text of a conversation message to generate the reply, and to identify candidate structured items within that same message. Model training on patient conversations is disabled and would require separate governance and consent before it could ever be enabled.
Email delivery providerSends transactional email โ€” password resets, notifications โ€” where configured.

The privacy policy sets out lawful bases, retention and your rights, including how to make a subject access request or ask for erasure.

Where AI is, and what governs it

  • It is not a therapist and not a companion product. A language model powers a supportive conversation informed by CBT principles. It does not diagnose, does not prescribe, does not treat, and is not a crisis service.
  • The continuity record is computed, not generated. Session intervals, counts, dates, comparisons between two points in time, goal history and the Therapeutic Memory and Session Prep surfaces are retrieval and calculation over what was recorded โ€” not model output.
  • A model may propose; the application decides; the patient confirms. Where a conversation contains something the patient clearly stated โ€” a mood rating, hours slept, an item for the next session โ€” it can be offered back as a suggestion. Deterministic application logic validates it against the patient's own message (a mood value must be a rating they actually gave; hours must be hours they actually stated; an agenda item is a verbatim excerpt of their own words), and nothing is written until the patient confirms it. Inferred, rounded or rephrased values are discarded, and an agenda item keeps the patient's wording rather than being rewritten into clinical language.
  • No automated decision is made about anyone's care. Where a model drafts anything for a clinician it is advisory and requires their review before any clinical use.
  • We do not interpret your history. The platform helps patient and clinician revisit the record. It does not diagnose, infer causation, judge whether therapy is working, or decide that separate experiences are the same recurring issue.

Voice: being developed, not offered

Speaking rather than typing is a direction we are developing and evaluating. The prototype in the development build uses the browser's own speech recognition, which on some platforms sends audio to an external vendor's service. That is not a foundation we are prepared to build a private product on, so it has been rejected as the intended production architecture rather than quietly shipped. We are investigating on-device or Healing-Space-controlled speech processing instead. Until that exists and has been tested, typing does the same job in the same conversation โ€” and wherever voice appears in the product it states plainly how it is being processed.

What we will never pretend

  • This is not an emergency service. Nobody is watching a screen waiting for you, and there is no continuous clinical monitoring. If you are in danger: 999, Samaritans 116 123, or text SHOUT to 85258.
  • It is not therapy and not a therapist. It is designed to work alongside a clinician โ€” never instead of one.
  • Screening is not diagnosis. PHQ-9, GAD-7 and C-SSRS-derived items are implemented as screening support; a score is a conversation prompt, never a label.
  • We do not monitor for concerning patterns. Healing Space does not watch a patient's activity for emerging risk on a clinician's behalf, and does not present a pattern-derived risk picture. Safety monitoring remains with the clinician and service. What deterministic alerting does do is described below.
  • It is not an EHR. It is a lightweight continuity layer around existing clinical work, not a replacement for a records or practice-management system.
  • We have no outcome evidence. We have not shown that preserving therapeutic context improves therapy, and we do not claim it. Healing Space is currently being developed with input from practising therapists to understand where it is most useful in real practice; those are conversations, not endorsements, and no organisation or individual is named here for credibility.

External assurance status

None of the following has been obtained yet. Each is on the roadmap, and we will state it here the day it changes โ€” not one day before.

AssuranceStatus
NHS approval / assessment (DTAC)Not held
Clinical safety cases (DCB0129 / DCB0160)Not held
Data Security & Protection Toolkit (DSPT)Not held
Completed Data Protection Impact AssessmentIn preparation
Independent penetration testNot held
Independent accessibility auditNot held
Independent clinical validationNot held
Research ethics approvalNot held
Medical device certificationNot held โ€” not currently claimed to be a medical device

Engineering controls we have built

These are implemented and tested by us. Implemented means the control exists and our automated tests exercise it โ€” it does not mean independently verified, and we do not claim that it does.

  • Every state-changing API route carries an authorisation guard, verified by a generated route matrix that fails our build if a route regresses.
  • A public-claims gate: our build fails if prohibited claims (e.g. "NHS-approved", "clinically validated") appear on public pages โ€” including this one.
  • Automated accessibility (axe-core, WCAG 2.1 A/AA rules) scans of core pages in a real browser on every change; we design against WCAG 2.1 AA but do not claim conformance until independently audited.
  • Session-bound CSRF protection, strict security headers, rate limiting on sensitive and expensive endpoints, and audit logging of accountable actions.
  • Sensitive fields encrypted at rest where applied (Fernet/AES-128-CBC); all traffic encrypted in transit (TLS).
  • Deterministic alerting: a crisis-keyword layer and the scored screening instruments can raise an alert, and that layer can only ever escalate, never downgrade. A scoring failure is reported as a failure rather than as low risk. Escalation of unacknowledged alerts depends on the deployment enabling the scheduled job and maintaining a duty rota; Healing Space is not a staffed emergency service and makes no response-time promise.
  • Honest failure states: if a clinician alert cannot be delivered, the patient and clinician interfaces say so rather than pretending it was.
  • Attributable records: treatment-plan goal history is append-only and the database refuses updates to it; reflections are private unless the patient shares them, per item and reversibly; a patient's answer about whether something helped inherits the privacy of the item it is attached to, so an answer on an unshared reflection never reaches a clinician โ€” nor does the fact that one exists.
  • Governed capture from conversation: model output is treated as untrusted. A proposal is accepted only if deterministic validation finds the value in the patient's own message, is written only on the patient's explicit confirmation, and leaves a private provenance record on the patient's side โ€” it is not a clinician route back into the conversation.
  • A differential privacy harness: every clinician-facing surface is rendered, undisclosed patient data is inserted, the surface is re-rendered, and the test asserts nothing changed โ€” with guards proving the test can detect change when there is some.
  • No third-party scripts, fonts or trackers load on any page โ€” no analytics, no advertising, no data sale.

Documents

Talking to us

If you are a therapist in private practice and would like to look at this properly โ€” including to tell us the premise is wrong โ€” you can book a walkthrough or write to cs@healing-space.org.uk. For research or academic collaboration: research@healing-space.org.uk.

Reporting a security concern

Please report vulnerabilities privately to dev-team@healing-space.org.uk with "SECURITY" in the subject line. Do not open public issues for security or patient-data concerns. We will acknowledge your report and keep you informed.