Trust Centre
Safeguarding, honestly
Quiet Space is used by parents and carers of neurodivergent children, often at the hardest moments of the day. Safeguarding isn't a feature we bolted on — it's how the product is built. This page is maintained by the Quiet Space team and explains the controls that exist today, what Iris is and isn't, and how to raise a concern.
This is app-owned content, not an independent certification. In an immediate emergency in the UK, call 999.
What Iris is (and isn't)
- Iris is an AI companion inside Quiet Space. It is not a person, a clinician, a therapist, or a crisis service.
- Iris offers psychoeducation and reflective conversation — general information about neurodivergence, regulation, and parenting strategies.
- Iris does not diagnose, does not prescribe or dose medication, and does not replace your GP, paediatrician, SENCO, or safeguarding lead.
- A parent can always see what their child said in Kid Mode. Iris is not a private confidant for a child.
Our safeguarding framework
Every message a parent or child sends to Iris passes through a safeguarding layer before the model replies. The layer is fail-closed: if it detects a high-risk signal, Iris does not hand off to the model — it responds with a warm, validating message, signposts UK support (Samaritans 116 123, NSPCC 0808 800 5000, Childline 0800 1111, and 999 for immediate danger), and files the moment for a human reviewer.
A fast pattern-based scan runs on every user turn. It flags suicide risk, self-harm, abuse, medical emergencies, medication dosing, role confusion, and prompt-injection attempts.
For blocking categories, Iris uses a warm, prewritten reply with UK signposting instead of asking the model to improvise.
Every trigger writes to a service-role-only safety events table with a scrubbed excerpt, the category, the surface, and the action taken.
Medium and higher severity events create a ticket with an SLA. Critical events are flagged for review within an hour.
Iris is scoped to psychoeducation and reflective conversation. Diagnosis, treatment, and medication dosing are outside intended use and are blocked at both the rules layer and the system prompt.
In Kid Mode, adult-topic detection and role-confusion detection run on the child's turn, and any safeguarding flag notifies the parent.
Categories we treat as blocking
When any of the following are detected in a message, Iris stops, validates, and signposts — the model never generates a free-form reply on top of these:
Human-in-the-loop
- Every safeguarding trigger creates an append-only audit event and, for medium+ severity, a ticket in a review queue with an SLA (critical 1 hour, high 4 hours).
- Reviewers can see the category, the surface (parent chat, parent voice, Kid Mode voice, Kid Mode talk, proposals, trust report), and the fail-closed reply Iris sent.
- For a child safety flag, the parent is notified so a real conversation can happen off the app.
Data governance
- Child data is scoped to the parent's account with row-level security.
- Safeguarding audit rows store a scrubbed excerpt (phone numbers, emails, and street addresses redacted), not the full message.
- We do not use family data to train third-party AI models. Iris uses Lovable's AI gateway with our system prompts and safeguarding layer.
- Full details are in the privacy policy.
Report a concern
If Iris said something that felt wrong, if you're worried about a child's safety, or if you have a privacy or accessibility concern, tell us. Reports go to a real person.
This form is not a crisis service. In a UK emergency call 999. For mental health support, Samaritans 116 123. For child protection concerns, NSPCC 0808 800 5000.