DATA // LOCAL FIRST Personal by default

Your record stays with you.

PreCrisis is being designed so personal content—journal entries, assessments, files, preferences, plans, and continuity context—stays on your device by default. You deliberately choose and review each copy created for an employer, insurer, agency, coach, chaplain, or clinician.

01 // THE DATA MAP Plain before technical

What stays. What moves. Who chooses.

“On-device” establishes where personal data starts. Device locks, operating-system backups, current software, secure key storage, and careful handling of exports complete the security model.

STAYS LOCAL BY DEFAULT

Your personal record

Journal content, personal files, assessments, chosen support plan, preferences, and saved system memories remain on the device. A deliberate choice shares or moves a copy.

SHARED BY YOUR CHOICE

Exports and notifications

Before creation or delivery, the interface should show what will be included, the purpose, recipient, date range, and whether a permission continues or expires.

DISCLOSED SEPARATELY

Operational data

A plain-language map must disclose any diagnostics, crash reports, update checks, push services, or other operational information that leaves the device.

02 // PORTABILITY Your continuity, movable

Share or move a copy on your terms.

The intended export flow lets you choose content, date range, purpose, and recipient before a portable package is created.

  1. 01
    Select

    Choose journal entries, files, assessments, preferences, plans, support-network settings, or saved system memories.

  2. 02
    Review

    See exactly what the package will contain and confirm the set that belongs in it.

  3. 03
    Share or move

    Give a selected copy to a trusted recipient or move the package to another device you control.

  4. 04
    Validate and import

    The receiving device or authorized workspace verifies the package before rebuilding the selected continuity context.

Copies have their own life

Future sharing stops when permission ends. A delivered copy remains subject to the recipient’s access, privacy, retention, and recordkeeping duties.

03 // SECURITY TARGETS Security in layers

Security must survive the full lifecycle.

These intended engineering and governance requirements define the evidence required before any control, certification, or deployment authorization is claimed.

DEVICE

Protect local access.

Device lock, account separation, current software, secure key handling, and recoverable—but protected—backup choices.

EXPORT

Protect portable copies.

Clear contents, destination awareness, integrity checking, safe import, and tested encryption and recovery before those controls are promised.

IDENTITY

Match access to each role.

Purpose-specific access, least privilege, recipient verification, permission expiry, revocation for future sharing, and visible audit history.

MINIMIZATION

Collect and disclose with purpose.

Keep personal content on its local-first path. Organizational reports contain agreed numerical measures while journals and free text stay in the personal record.

INCIDENTS

Prepare for disruption.

Defined update, vulnerability-response, breach-notification, export-recovery, support, and restoration procedures are core product requirements.

EVIDENCE

Verify before claiming.

Architecture, contracts, testing, threat models, and deployment-specific review must support any security, privacy, or compliance statement.

Design grounding: NIST mobile-device security guidance, FTC mobile-health app practices, and HHS health-app resources.

04 // CONTROLLED PATHS When you choose to share

Different recipients, different boundaries.

Personal, clinical, and organizational pathways each require their own explicit authorization.