OPUS Chat Safety Protocol
- Last Updated:
- August 28, 2026
- Effective Date:
- August 28, 2026
OPUS Chat Safety Protocol
Last Updated: August 28, 2026
Effective Date: August 28, 2026
1. About OPUS Chat
OPUS Chat is a user-initiated AI typology guide for adults in the United States. It is designed to help users understand their OPUS type result and cognitive-function profile. It is not a human, therapist, healthcare provider, crisis service, emergency service, or continuously monitored support channel.
The beta includes general type chat and cognitive-function-specific chat. Relationship-chat functionality is outside the beta launch scope. OPUS Chat is provided only in English. All ordinary chat outputs, fixed safety screens, notices, and support macros are delivered in English; OPUS does not represent that it provides translated or multilingual chat or crisis assessment.
OPUS does not retain ordinary chat history as conversational memory. During an open conversation, the browser sends a bounded recent portion of that conversation together with the user's saved, fixed OPUS type and function profile. Closing or refreshing the conversation ends that session, and a later chat does not receive the prior conversation. A conversation voluntarily submitted for human product-access review is never reused as model context or future chat memory.
2. AI disclosures
Before the first chat turn, OPUS displays:
You're chatting with OPUS, an AI typology guide — not a human. OPUS doesn't remember prior conversations. It uses your saved OPUS profile and the messages in this open conversation to respond. It isn't a therapist or emergency service.
For a continuing chat, OPUS displays the following reminder at three hours and every three hours thereafter:
Reminder: You're chatting with an AI, not a human. You've been chatting for three hours or more — consider taking a break. OPUS isn't a therapist or emergency service.
3. Automated safety protocol
OPUS applies an automated safety check to user messages. The protocol is intended to prevent ordinary generative responses from continuing when language may indicate suicide, self-harm, an immediate emergency, relationship violence, present serious harm to another person, or another defined high-risk situation.
When a defined safety route is triggered:
- the ordinary generative response is suppressed for that turn;
- OPUS displays one complete, fixed, prewritten safety screen rather than asking the AI to improvise a crisis response;
- immediate support information appears before administrative review or data-sharing choices;
- explicit suicide or self-harm risk, medical emergency, immediate physical danger, and present serious harm to another person pause chat while unrelated OPUS features remain available;
- genuinely ambiguous first-person self-harm language receives one fixed, closed-ended meaning-confirmation screen; and
- current relationship violence without stated immediate danger stops that topic and provides advocate and device-safety information, but does not disable unrelated typology chat. Immediate danger still pauses chat.
OPUS does not treat an automated safety result as a diagnosis, clinical conclusion, proof of current danger, or judgment about the user. Automated checks can be wrong.
4. Resources
Depending on the detected situation, fixed safety information may direct a user to resources such as:
- 911 or an appropriate local emergency service for immediate danger or a medical emergency;
- the 988 Suicide & Crisis Lifeline;
- Crisis Text Line; or
- the National Domestic Violence Hotline.
Resource information is verified from first-party sources before release and is not generated dynamically by the AI. OPUS does not control third-party availability, confidentiality practices, response times, or services.
5. Product-access reconsideration
When OPUS chat is paused, the user may choose among three options: request a product-access review without the conversation, request a review with the conversation, or not request review at that time. Neither review route guarantees restoration, and the reviewer is not making a clinical assessment.
For a review without the conversation, OPUS does not collect a transcript for human review. The review uses only the minimized account and access record permitted by OPUS policy.
For a review with the conversation, the user affirmatively chooses to submit both sides of the recent exchange, up to the verified 21-message limit including the triggering message. OPUS removes the transcript from its active review system when the user withdraws, seven days after a completed review, or 45 days after the request if no review is completed, whichever occurs first. Applicable consumer-health-data rights and disclosures are described in the Washington Consumer Health Data Privacy Policy and Nevada Consumer Health Data Privacy Policy.
6. Data handling
For each ordinary chat turn, Anthropic processes the bounded current conversation, the user's saved fixed OPUS type and function profile, and OPUS system instructions. Ordinary chat history remains locally available in the browser and is not ordinarily stored in Supabase as account chat history or cross-session memory. Supabase stores authentication, the saved profile, generic category-free chat-access state, content-free review metadata, and a transcript only when the user affirmatively selects review with the conversation. Temporary routing-category and event-linkage evidence is maintained separately and removed or generalized under the approved schedule.
OpenAI is limited to the onboarding-memory embedding path and does not process ordinary chat, chat-safety, or product-access-review content. If a user separately sends a support or reconsideration email, Google Workspace processes and stores that communication through the applicable restricted OPUS communications channel. Google Workspace does not receive ordinary in-product chat merely because a safety route appears. OPUS does not send ordinary chat, chat-safety, reconsideration, or support content to PostHog, advertising, session replay, or an error-monitoring provider. Additional details, applicable rights, provider limitations, and deletion procedures are described in the OPUS Privacy Policy, Subprocessor List, Washington Consumer Health Data Privacy Policy, and Nevada Consumer Health Data Privacy Policy.
7. Important limitations
OPUS does not monitor chat or support channels continuously, determine whether a user is safe, dispatch emergency assistance, conduct welfare checks, or guarantee that any message will receive human review. Users should contact an appropriate emergency or crisis resource when immediate assistance is needed.
OPUS may revise this protocol as its safety system, legal obligations, clinical guidance, or product scope changes. Any addition of cross-session conversational memory, proactive emotional engagement, relationship-chat functionality, or materially different safety behavior requires renewed legal, clinical, privacy, and technical review before release.