Privacy & Trust
Trust Centre ยท Last updated: 2026-09-16
Mental-health software is full of claims nobody ever checks. This page is the
opposite: a single place that states plainly what Healing Space UK has, what it
does not yet have, and where the evidence lives. If we cannot support a claim,
we do not make it โ and our build pipeline fails if unsupported claims appear on
our public pages.
Privacy, as something to earn
Vulnerability is not a commodity. The version of privacy worth having is not
a promise in marketing copy โ it is what the architecture actually enforces, and
what we are prepared to be held to:
- Private by default. Shared deliberately. Reflections are private unless the patient shares them, per item and reversibly. An answer about whether something helped inherits the privacy of the item it is attached to, so an answer on an unshared reflection never reaches a clinician โ nor does the fact that one exists.
- Captured is not shared. Writing something down and handing it over are two separate decisions, and the second one belongs to the patient. Some information is part of the clinical record and is not held back โ appointments, medications, and measures a service administers โ and we say which is which rather than implying everything is private.
- No data farming. No advertising against therapeutic data, no sale of it to advertisers, insurers or data brokers, and no revenue anywhere that depends on how long someone stays in the app. Clinics pay a per-clinician licence; that is the entire model.
- No casual staff access. Access runs through one central authorisation policy across every patient route, developers hold no standing access to clinical data, and sensitive reads are logged so there is an answer to who looked at what and when.
- Data minimisation. The AI provider is not told who the patient is, who their clinician is, or what else is in their record; only the message being replied to is sent.
- Named processors, not vague reassurance. They are listed below and in the privacy policy.
- The direction of travel. We intend to move more processing to local or Healing-Space-controlled infrastructure where that is feasible. That is an intention, not a current capability, and it is listed here as one.
What we will not tell you: that nobody except you and your
clinician can ever access your data. Hosting, email delivery and the AI
conversation involve third-party infrastructure, staff with operational access
exist in any real system, and a sentence that ignores both would be marketing
rather than truth. What we will tell you is exactly who those parties are, what
they see, and what is done to keep that set as small as possible.
Who processes what
| Processor | What it handles |
| Railway | Cloud hosting of the application and its database. |
| Groq | Processes the text of a conversation message to generate the reply, and to identify candidate structured items within that same message. Model training on patient conversations is disabled and would require separate governance and consent before it could ever be enabled. |
| Email delivery provider | Sends transactional email โ password resets, notifications โ where configured. |
The privacy policy sets out lawful bases, retention and
your rights, including how to make a subject access request or ask for erasure.
Where AI is, and what governs it
- It is not a therapist and not a companion product. A language model powers a supportive conversation informed by CBT principles. It does not diagnose, does not prescribe, does not treat, and is not a crisis service.
- The continuity record is computed, not generated. Session intervals, counts, dates, comparisons between two points in time, goal history and the Therapeutic Memory and Session Prep surfaces are retrieval and calculation over what was recorded โ not model output.
- A model may propose; the application decides; the patient confirms. Where a conversation contains something the patient clearly stated โ a mood rating, hours slept, an item for the next session โ it can be offered back as a suggestion. Deterministic application logic validates it against the patient's own message (a mood value must be a rating they actually gave; hours must be hours they actually stated; an agenda item is a verbatim excerpt of their own words), and nothing is written until the patient confirms it. Inferred, rounded or rephrased values are discarded, and an agenda item keeps the patient's wording rather than being rewritten into clinical language.
- No automated decision is made about anyone's care. Where a model drafts anything for a clinician it is advisory and requires their review before any clinical use.
- We do not interpret your history. The platform helps patient and clinician revisit the record. It does not diagnose, infer causation, judge whether therapy is working, or decide that separate experiences are the same recurring issue.
Voice: being developed, not offered
Speaking rather than typing is a direction we are developing and evaluating.
The prototype in the development build uses the browser's own speech
recognition, which on some platforms sends audio to an external vendor's
service. That is not a foundation we are prepared to build a private product on,
so it has been rejected as the intended production architecture rather than
quietly shipped. We are investigating on-device or Healing-Space-controlled
speech processing instead. Until that exists and has been tested, typing does
the same job in the same conversation โ and wherever voice appears in the
product it states plainly how it is being processed.
What we will never pretend
- This is not an emergency service. Nobody is watching a screen waiting for you, and there is no continuous clinical monitoring. If you are in danger: 999, Samaritans 116 123, or text SHOUT to 85258.
- It is not therapy and not a therapist. It is designed to work alongside a clinician โ never instead of one.
- Screening is not diagnosis. PHQ-9, GAD-7 and C-SSRS-derived items are implemented as screening support; a score is a conversation prompt, never a label.
- We do not monitor for concerning patterns. Healing Space does not watch a patient's activity for emerging risk on a clinician's behalf, and does not present a pattern-derived risk picture. Safety monitoring remains with the clinician and service. What deterministic alerting does do is described below.
- It is not an EHR. It is a lightweight continuity layer around existing clinical work, not a replacement for a records or practice-management system.
- We have no outcome evidence. We have not shown that preserving therapeutic context improves therapy, and we do not claim it. Healing Space is currently being developed with input from practising therapists to understand where it is most useful in real practice; those are conversations, not endorsements, and no organisation or individual is named here for credibility.
External assurance status
None of the following has been obtained yet. Each is on the roadmap, and we
will state it here the day it changes โ not one day before.
| Assurance | Status |
| NHS approval / assessment (DTAC) | Not held |
| Clinical safety cases (DCB0129 / DCB0160) | Not held |
| Data Security & Protection Toolkit (DSPT) | Not held |
| Completed Data Protection Impact Assessment | In preparation |
| Independent penetration test | Not held |
| Independent accessibility audit | Not held |
| Independent clinical validation | Not held |
| Research ethics approval | Not held |
| Medical device certification | Not held โ not currently claimed to be a medical device |
Engineering controls we have built
These are implemented and tested by us. Implemented means the control
exists and our automated tests exercise it โ it does not mean independently
verified, and we do not claim that it does.
- Every state-changing API route carries an authorisation guard, verified by a generated route matrix that fails our build if a route regresses.
- A public-claims gate: our build fails if prohibited claims (e.g. "NHS-approved", "clinically validated") appear on public pages โ including this one.
- Automated accessibility (axe-core, WCAG 2.1 A/AA rules) scans of core pages in a real browser on every change; we design against WCAG 2.1 AA but do not claim conformance until independently audited.
- Session-bound CSRF protection, strict security headers, rate limiting on sensitive and expensive endpoints, and audit logging of accountable actions.
- Sensitive fields encrypted at rest where applied (Fernet/AES-128-CBC); all traffic encrypted in transit (TLS).
- Deterministic alerting: a crisis-keyword layer and the scored screening instruments can raise an alert, and that layer can only ever escalate, never downgrade. A scoring failure is reported as a failure rather than as low risk. Escalation of unacknowledged alerts depends on the deployment enabling the scheduled job and maintaining a duty rota; Healing Space is not a staffed emergency service and makes no response-time promise.
- Honest failure states: if a clinician alert cannot be delivered, the patient and clinician interfaces say so rather than pretending it was.
- Attributable records: treatment-plan goal history is append-only and the database refuses updates to it; reflections are private unless the patient shares them, per item and reversibly; a patient's answer about whether something helped inherits the privacy of the item it is attached to, so an answer on an unshared reflection never reaches a clinician โ nor does the fact that one exists.
- Governed capture from conversation: model output is treated as untrusted. A proposal is accepted only if deterministic validation finds the value in the patient's own message, is written only on the patient's explicit confirmation, and leaves a private provenance record on the patient's side โ it is not a clinician route back into the conversation.
- A differential privacy harness: every clinician-facing surface is rendered, undisclosed patient data is inserted, the surface is re-rendered, and the test asserts nothing changed โ with guards proving the test can detect change when there is some.
- No third-party scripts, fonts or trackers load on any page โ no analytics, no advertising, no data sale.
Documents
Talking to us
If you are a therapist in private practice and would like to look at this
properly โ including to tell us the premise is wrong โ you can
book a walkthrough or write to
cs@healing-space.org.uk.
For research or academic collaboration:
research@healing-space.org.uk.
Reporting a security concern
Please report vulnerabilities privately to
dev-team@healing-space.org.uk
with "SECURITY" in the subject line. Do not open public issues for security or
patient-data concerns. We will acknowledge your report and keep you informed.