The guardian panel
The person who pays, and worries. Built to replace anxiety with calm, evidence-based reassurance — a real window into how someone is doing, without ever crossing into surveillance. Everything here is derived signal: mood, themes, safety. Never the conversation.
Everything that matters, at a glance.
One calm overview, led by a live presence dot and four clickable counters — today's mood, days logged, themes this week, open alerts. One period control — Today / 7d / 14d / 30d — drives every card behind it, and the window is named on every line, so no two numbers ever describe different weeks. Pairing lives here too: a 30-day connection code with copy and regenerate — and a QR code to scan instead of typing.
- Live presence — a green dot when the person was active in the last couple of minutes.
- Pairing code + QR — the person's app links in a minute; linking another caregiver's account works the same calm way.
- Quick actions put "send context", the weekly report and the companion editor one tap away.

An AI writes the read — honestly.
The dashboard's centrepiece. An analytical agent reads the period's aggregates only — mood trajectory and theme labels, never the words — and writes plain-language wellbeing observations with a graded, colored mood status and a single gentle next step. It is deliberately honest twice over: a stable average never papers over a safety signal or a quiet withdrawal, and a stretch too thin to read is called exactly that — honest when there's not enough signal, instead of a confident story built on three messages.
- One colored mood status — steady · difficult · very difficult. The same scale the clinician sees.
- Direction is reported separately from the level — "difficult, but improving" is a different sentence from "difficult and declining", and the panel treats them differently.
- One source of truth — a single computation feeds the status, the chart and the reports, so nothing ever contradicts itself.

The shape of the week, not the words.
Mood lands as one entry per day on a five-level scale and charts as a trend — with an intraday "Today" view that plots each reading by time. A graded status pill sits up top, a distribution shows where the days fell, and any window — today / 7d / 14d / 30d or a custom range — exports to CSV.
- Consent, all the way down — mood notes the person hasn't agreed to share never reach the panel at all. Not hidden on a chart: absent.
- Consent-gate notices instead of empty charts — when sharing is off, the panel says so in plain words, rather than showing a blank that reads like a bad week.
- A transient network blip keeps the last known data — it never flashes a false "all clear".

What came up — counted, not quoted.
Themes are the topics a week was made of, mapped to a fixed canonical taxonomy — "friends & relationships", "sleep & daily routine", "health & body" — each with a mention count, a sentiment, and how it shifted versus the period before. Filter by sentiment, sort by frequency. It tells you what someone has been living with, never a specific thing they said.
- Counts + positive / neutral / negative sentiment + new / intensified / faded deltas.
- Canonical labels only — never an example pulled from the chat.

Signals, never the conversation.
A worrying message becomes a graded safety alert in roughly 15–20 seconds. The guardian sees a severity, a type and a one-line, non-verbatim summary — never the chat. Open one for the full context paraphrase, the type and timestamp, and how the companion itself responded. Resolving keeps it as history; the companion's own behaviour is never flagged. Safety is the one thing consent can never switch off.
- Types: self-harm, crisis, manipulation, predator behaviour, data extraction, harm to others — and mood decline.
- Graded low / medium / high, with trend context so one hard day doesn't sound an alarm. This grading is our own and still being built — it is not a certified clinical instrument, it promises nothing, and it decides nothing on its own. A person always looks.
- One open alert per concern — the same worry can't re-fire days later as a duplicate; a more serious read raises the open alert in place.


Built to be heard — even when the panel is closed.
An alert nobody sees is not an alert. High- and medium-severity signals leave the panel: a web push reaches the caregiver's device even when the panel is closed, and an email carries the severity, the type and a privacy-safe one-line paraphrase — never the person's words. Inside the panel, a high-severity signal opens as a popup with an audible alarm — and a close button, because an alarm you can't silence teaches people to ignore alarms.
- Web push to a closed panel — the tab can be long gone; the alert still lands on the device.
- A push self-check in settings names the exact reason notifications aren't arriving — and re-subscribes automatically after a key change.
- No role can hide an alert — delivery is deliberately excluded from every permission preset.
Safety alert — high
A one-line, privacy-safe paraphrase. Never the person's words.
Severity · type · one line
Enough to act on, nothing to eavesdrop with.
A popup with an audible alarm
It interrupts on purpose — and it has a close button.
The week, already written up.
Every week (and month) is rolled into a report: an improving / stable / declining mood trend computed first-half versus second-half, the themes that recurred, the alerts by severity, and an AI-written narrative in a warm, plain voice. Open one to read the full "paper", or export to PDF straight from the browser — no plugins, no data leaving the page.
- Auto-generated by a weekly cron and cached — opens instantly, flagged when new.
- One-tap PDF for a doctor's visit or a case file.


Built for a whole circle, not one login.
One person can have several caregivers — a parent, a sibling, a social worker. Link another caregiver's account and pick a preset: Co-caregiver, Viewer or Limited view. The presets are enforced server-side — they genuinely gate what each account can see and do, not just what the screen shows. And one thing sits deliberately outside every preset: safety. No role can hide an alert.
- Co-caregiver / Viewer / Limited view — role presets gate the panel, checked on the server on every request.
- Safety alert delivery is excluded from role gating by design — every linked caregiver hears the alarm.
- The privacy floor is the person's, not negotiable per-account: everyone sees the same honest aggregates; nobody gets the conversation.

Tune the friend, and quietly steer the day.
Rename the companion, regenerate or upload its avatar, and write a free-text knowledge base it absorbs into every session — with a live preview and an always-on honesty disclosure: it reminds the person it's an AI, refuses to pretend to be human, and shares safety signals. The person's profile is edited here too. Two careful tools live alongside: Send context — a quiet background note the companion keeps in mind but never raises first, expiring on its own — and Discuss now, where the companion drafts its own opener, in its own voice, and shows it to you before anything is said.
- Discuss now is preview-and-approve — you read the drafted opener first; nothing reaches the person without your approval.
- A sensitive-topic guard checks your topic against the person's trigger and forbidden topics before anything is drafted — deterministically, outside the model.
- Send context stays in the background and expires on its own — the companion never brings it up first.


If a switch does nothing, we delete the switch.
Trust in this product is built out of small, checkable honesties — in the settings as much as in the safety pipeline.
Honest settings
Controls with nothing behind them were removed rather than left as decoration. Every switch that remains does exactly what it says.
A privacy page in plain words
It states what a caregiver sees — mood, themes, safety signals — and what they never see: the conversation. No legal fog.
Real data export
Your data leaves with you — an actual export of what the panel holds, not a button that promises one.