HomeSafety and risk management
Safety and risk management
This page describes how Mind Guard 365 manages risk as a non-clinical self-help app. It is written for assessors, employers and anyone who wants to understand how safety is designed into the product. If you need urgent help now, go to our safety and crisis support page.
Who this app is for and who it is not for
Mind Guard 365 is designed for adults and young people aged 13 and over who want a low-risk, self-help tool for everyday mental wellbeing. Being explicit about audience helps us keep the risk model simple and helps assessors understand what we are and are not claiming.
- Intended audience. People looking for calm, plain-language self-help techniques such as breathing, grounding, CBT-style reflections, journalling and routine support.
- Not the right tool for. Anyone currently in acute crisis or who feels unsafe right now (see our safety and crisis support page), anyone whose primary need is medication management or a clinical diagnosis, anyone looking for therapy from a qualified professional and anyone expecting the app to monitor entries and respond in real time. The app does not do these things and is not designed to.
- Not a replacement. Mind Guard 365 sits alongside a GP, therapist, psychiatrist, crisis service or employee assistance programme; it does not replace any of them.
What Mind Guard 365 is (and is not)
Mind Guard 365 is a self-help and education app for everyday mental wellbeing. It is evidence-informed, not clinically validated, and it does not diagnose, treat, monitor or claim to cure any health condition. It is not a medical device under the UK Medical Devices Regulations 2002 or the EU MDR 2017/745. It is not therapy, not a crisis service and not monitored by clinicians. Our full posture on claims is in our approach and evidence page.
Scope and standards we operate under
Because Mind Guard 365 is a non-clinical wellbeing product, clinical risk-management standards intended for health-IT and medical devices do not apply. In particular:
- DCB0129 and DCB0160 (NHS clinical risk management for health IT deployed in care delivery) are out of scope. The app is direct-to-consumer self-help and is not deployed as clinical software.
- ISO 14971 (medical device risk management) is out of scope. The app has no medical device function.
- Clinical Safety Officer oversight is not required for a non-clinical product.
This is a reasoned out-of-scope position, not an omission. If the product ever adds a clinical function, this stance and the app classification would change and the relevant standards would be adopted. In the meantime we run the non-clinical safety controls set out below.
Risks we manage and how
The main risks a wellbeing app of this kind has to consider, and the controls we run against each, are:
- User in crisis using a wellbeing tool instead of a helpline. An SOS button (labelled "Help Me Now") is available on every main screen. The SOS landing screen lists crisis resources first, and tool completion screens do not push a distressed user back into the catalogue.
- User entering self-harm content into a journal. Journal text is never sent to analytics, advertising or the recommendation engine. Crash reporting (Sentry) is configured to scrub journal text and related fields before events are sent. We do not run AI detection on journal text (see rejected features below).
- Young person using the app. The app is store-approved without an age restriction. Copy is plain-language and non-clinical, and SOS resources include child and young-person services where relevant, for example Childline in the UK and Kids Helpline in Australia.
- User taking medical advice from copy. No diagnostic or medical-adjacent copy is used. Marketing and paywall copy is audited every release for words like "diagnose", "treat", "therapy", "cure" and "guarantee". The About screen carries an explicit disclaimer.
- Push notifications triggering distress. Reminders are local and configurable per phase. Quiet hours are respected and tone follows the user's chosen setting (gentle, balanced or direct).
- Ads showing harmful content. Ads run under Google AdMob with family-style filters where available. Ads are disabled in SOS, during exercises and on all crisis content. Premium disables ads globally.
- Loss of session during a tool. Tool state is local-first. Closing the app preserves the in-progress step.
SOS and "Help Me Now" hard rules
SOS is the safety net. It is reachable from every main screen. These rules are enforced in code, not just by convention:
- No ads in SOS. The ads service refuses to render anywhere in the SOS modal stack.
- No upsells in SOS. The paywall is not reachable from SOS. Premium gating cannot block any SOS content.
- No login gate on crisis content. Crisis resources render for signed-out users so that nobody is asked to sign up before they can see a helpline.
- No paywall on crisis content. Every helpline listing is available on the free tier.
- Region-aware resources. The user's profile country and device locale are used to pick the right region, with an international fallback.
Features considered and rejected
Some features have been considered and deliberately not built. We record these so it is clear what the product does not attempt to do:
- No crisis language detection in journals. Detection without a clinician in the loop risks false positives that escalate distress and false negatives that imply safety. We may revisit this only with proper clinical oversight.
- No in-app chat or peer messaging. Removes a large class of safeguarding risk.
- No AI-generated reflections or coaching responses. All wellbeing copy is curated and reviewed. We deliberately do not use AI to interpret personal mental health content.
- No outcome scoring. The app does not show a "you are X% better" number. Insights describe patterns, not progress against a clinical goal.
Content governance and review cadence
Wellbeing content is curated by the operator and reviewed against reputable, publicly available self-help and psychoeducation sources. Content changes are managed as follows:
- Source of truth in code. Content lives in JSON catalogues in the app repository. Changes go through pull requests with at least one reviewer.
- Automated guardrails. A validation script runs in CI to enforce schema and copy guardrails (allowed contexts, allowed durations, mandatory descriptions).
- Crisis-content review cadence. Crisis resources are reviewed at least every six months, and immediately when a helpline notifies us of a change.
- Release copy audit. Marketing, paywall and About copy is audited every release for medical-adjacent words.
Change control and incident response
- Release notes. Every shipped change has a versioned release note. Store listings, privacy policy and the compliance pack are kept in sync with the latest release.
- Architecture Decision Records (ADRs). Significant safety decisions are recorded as ADRs in the repository (for example the SOS posture and ads policy).
- Observability with scrubbed content. Errors flow to Sentry with wellbeing content and personal identifiers scrubbed before they are sent. Breadcrumbs cover authentication, purchases, sync and ads only.
- Hot-fix path for safety-critical bugs. Critical safety issues trigger a same-day hot-fix release and, where appropriate, a forced "What's new" message that surfaces the change to users on next open.
- Data breach process. Personal data incidents follow a documented lifecycle covering identification, containment, assessment, ICO notification within 72 hours where required, user communications and post-incident review.
Open items we are honest about
- We do not yet have a named clinical adviser on retainer. Introductions through an assessor's network are welcome.
- We do not have outcome-research data on the app itself. Insights track engagement and self-reported patterns, not validated clinical outcome scales.
- Crisis-resource localisation is limited to the regions we currently support. Users outside those regions see an international fallback rather than empty content, and expanding this remains on the roadmap.
Questions
If you are an assessor, employer or partner and want more detail on any of the controls above, contact us at privacy@mindguard365.com. For urgent personal support see our safety and crisis support page.
