The most revealing test of an AI support app happens before the first intimate message: can you understand what the product will do with it?
People often compress privacy into “Is it encrypted?” and safety into “Does it show a crisis number?” Both matter. Neither is enough. A responsible review also asks what is collected, whether conversations train models, who receives data, what memory retains, whether deletion works, how the system behaves when it is wrong, and whether the product encourages you to rely on it too much.
Use this checklist for any AI companion, “AI therapist,” wellness chatbot, or general assistant you use for emotional conversations.
First: decide whether this conversation belongs in an app
No privacy policy can make every disclosure necessary. Before typing, ask whether the product needs the identifying detail.
You can often remove:
- full names, addresses, workplaces, schools, and exact dates;
- account numbers, passwords, legal documents, and medical-record identifiers;
- identifying details about a child, partner, patient, client, or colleague;
- information that could put someone at risk if exposed;
- a full document when a short, anonymized summary would answer the question.
This is data minimization at the personal level: share enough for the task, not everything available.
The ten-minute privacy check
Open the current privacy policy and product settings. Search for these questions.
1. What data is collected?
Look beyond messages. The app may also process audio, transcripts, device identifiers, diagnostics, account details, subscription status, approximate location, contacts you mention, or analytics events.
A vague phrase such as “information you provide” is less useful than a concrete inventory. Voice deserves special attention: is raw audio retained, or only a transcript? For how long? For what purpose?
2. Are conversations used to train models?
Separate three different uses:
- producing the reply you requested;
- reviewing or analyzing conversations to operate and improve the service;
- training a model for future users.
Those are not the same. Check whether training is on by default, whether it can be disabled, and whether the rule differs between a standard chat and a specialized health surface.
For example, OpenAI says standard ChatGPT users can disable “Improve the model for everyone”. It also says Temporary Chats do not train models or create memories and are deleted after a 30-day safety-retention period. OpenAI’s 2026 Health experience has separate rules for connected health data. This illustrates why you must read the policy for the exact feature you use.
3. Who else receives the data?
Look for cloud hosts, AI model providers, speech services, analytics tools, customer support platforms, advertising networks, and legal disclosures. “We do not sell data” is valuable, but it does not answer every sharing question.
The U.S. Federal Trade Commission’s BetterHelp enforcement action is a useful warning: the agency’s final order addressed sharing sensitive health data for advertising despite privacy promises. The lesson is not that every app behaves this way. It is that marketing pixels and analytics architecture belong in a mental-health privacy review.
4. What is remembered?
Memory may include full transcripts, summaries, extracted facts, inferred preferences, or embeddings that help retrieve earlier context. Ask:
- Can memory be turned off?
- Can I see what was saved?
- Can I correct an inaccurate memory?
- Does deleting a chat also delete derived memory?
- How long do backups persist?
Continuity is helpful only when the user can understand and control it.
5. Can you delete the data and the account?
Find the actual flow, not just the promise. Note whether deletion is immediate, delayed, or subject to security, legal, payment, or backup retention. Check whether you can export data first.
Take screenshots of important settings if the information is highly sensitive. Policies and interfaces change.
HIPAA is not a synonym for private
In the United States, people often ask whether a mental-health app is “HIPAA compliant.” The more basic question is whether HIPAA applies to that data relationship at all.
The Department of Health and Human Services explains that information entered into a personal-use mobile app usually is not protected by HIPAA unless the app is provided by a covered entity or its business associate. Other consumer-protection, health-data, breach-notification, and state laws may still apply.
Do not interpret this as “unregulated means unsafe” or “HIPAA means perfectly secure.” It means you should identify the actual promise, law, and responsible company instead of trusting a familiar acronym.
The FTC provides a health-app developer guide explaining how the FTC Act and Health Breach Notification Rule may apply outside HIPAA.
The safety check
Privacy asks who can access the conversation. Safety asks what the conversation may cause.
Clear identity and limits
The system should say it is AI. It should not claim to be licensed, conscious, uniquely able to understand you, or a replacement for care. The APA health advisory emphasizes the fundamental difference between chatbots and qualified providers.
Uncertainty instead of false confidence
An emotionally fluent answer can still be wrong. Watch for diagnosis, certainty about another person’s motives, strong medical instructions, invented memories, or advice that escalates conflict. Safer systems ask for context, acknowledge uncertainty, and encourage verification when stakes rise.
A real crisis exit
The app should make clear that it is not emergency support and point toward human help. But a banner is not proof that every risky message will be detected.
A 2025 study in Psychiatric Services tested major chatbots on hypothetical suicide-related questions and found more consistent behavior at very low and very high risk than at intermediate levels; see the indexed study abstract and methods. Models change, but the underlying lesson remains: do not make a chatbot the only link in a crisis plan.
If you or someone else may be in immediate danger, contact local emergency services or a crisis service. In the United States, call or text 988. Move to human help even if the app tells you to keep talking.
Protection against emotional dependence
A companion should not guilt you for leaving, imply that only it understands you, discourage human relationships, sexualize a vulnerable exchange, or reward longer and more intense disclosure for its own sake.
Use outcomes outside the app as the test. Did the conversation help you sleep, make a plan, contact someone, set a boundary, or prepare for care? Or did it mainly create another hour of scrolling?
Independent evidence and monitoring
Ask whether safety claims were tested by people outside the company, with realistic edge cases and a stated model version. The World Health Organization’s guidance on generative AI in health stresses governance, stakeholder involvement, transparency, accountability, and continuing oversight—not a one-time launch review.
A safer-use protocol
You do not need to perform a legal audit every time you journal. A few habits cover much of the everyday risk.
- Set the job. “Help me organize what I want to say” is safer than “Tell me what disorder I have.”
- Set the boundary. Ask the system not to diagnose, make medical decisions, or pretend certainty about other people.
- Minimize identifiers. Use roles or initials when names do not matter.
- Keep important decisions human. Verify medical, legal, financial, employment, and safety-related advice with an appropriate person.
- Review the artifact. Correct summaries before saving or sharing them.
- End deliberately. Write one offline next step and close the app.
- Recheck settings after major updates. Memory, model training, and product surfaces can change.
Red flags that should stop the conversation
Pause and seek a different source of support if the app:
- claims to diagnose you or guarantees a result;
- tells you to change medication or ignore a professional;
- validates a frightening belief as fact without checking context;
- asks for unnecessary identifying, financial, or medical information;
- hides training or deletion controls behind vague language;
- discourages you from telling people in your life;
- pressures you to keep chatting or frames leaving as betrayal;
- responds poorly when you mention immediate danger.
Report harmful behavior through the product’s feedback channel when it is safe to do so. Do not continue a risky exchange just to test the system.
How Mind approaches the checklist
Mind is a voice-and-text reflection companion with session summaries and long-term context. It is not licensed therapy, diagnosis, medical treatment, or emergency support.
Mind’s current Privacy Policy states:
- personal information is not sold;
- ordinary conversations are processed by AI providers and monitored in Raindrop;
- incognito content is excluded from saved chat history and Raindrop monitoring;
- general product analytics excludes conversation and wellbeing text; and
- the app can delete first-party chat and file data, while processor-side deletion may require a separate privacy request.
Those statements are commitments, not a reason to share more than a conversation requires. The policy is the source of truth and should be reviewed whenever it changes. Questions can be sent to the contact listed there.
For product fit beyond privacy, see our AI therapist market guide or the Mind vs ChatGPT comparison.
Frequently asked questions
Are AI therapist conversations confidential?
They are governed by the app’s policy, technical design, contracts, and applicable law—not automatically by therapist-client confidentiality. Check providers, human review, training, retention, legal disclosure, and deletion. Avoid assuming that marketing language creates a professional privilege.
Does encryption mean no one can read my chats?
No. Encryption in transit and at rest protects data during transmission and storage, but an authorized service may still need to process plaintext to provide the feature. Encryption does not answer retention, access-control, training, analytics, or legal-disclosure questions.
Is it safe to tell an AI about trauma?
Consider your stability, privacy, and available support before approaching traumatic material. An AI can respond unpredictably and cannot monitor you like a qualified professional. If discussing trauma feels destabilizing, stop and contact an appropriate human support or professional.
Should I turn memory off?
Turn it off when continuity is not worth the additional retained context, or use a temporary mode when available. If you keep memory on, review it periodically and delete or correct information that is wrong, overly sensitive, or no longer useful.
How often should I reread the privacy policy?
Check before first use, after a major feature or ownership change, and whenever the app asks for a new permission or introduces memory, health-data connections, advertising, or a new AI provider.
This article provides general education, not legal, security, or medical advice. Laws, product settings, and policies change by location and over time.
