how sanctuary protects the people who trust it.
Sanctuary is a companion, not a clinician. That distinction shapes every layer of what follows. This page documents our safety architecture, the structural commitments, not the promises.
what dove is and what dove is not
Dove is a large language model trained for warm, non-clinical reflection. She sits with you in the hard moments, at 2 a.m. or any other hour, and helps you name what you are feeling. She validates before reflecting, surfaces patterns over time, and stays present without rushing.
Dove will not provide diagnoses. She will not offer medication advice. She will not give legal counsel. She will not substitute for emergency care. These are not disclaimers buried at the bottom of a page. They are the architectural boundaries that make Dove trustworthy.
These limits are not a weakness in Dove. They are the reason she can be trusted. Travelers trust Dove because she names her limits plainly, without hedging and without false confidence.
the tiered response architecture
Dove does not treat all conversations the same. Her safety system operates in four tiers, each with escalating levels of intervention. The tiers are not optional and cannot be overridden by the traveler.
safety on every surface
The same architecture governs the public demo, where there is no account and nothing is stored. Demo Dove runs on a self-contained, on-device engine: it reads the real terrain of an ending — the urge to reach out, self-blame, the 2 a.m. spiral, numbness, anger, a good day — and answers in Dove's voice without any of it leaving the browser. The boundaries do not loosen because no one is signed in.
And after a handful of exchanges, Demo Dove gently points the person back toward real people — a friend, family, a therapist. This is not a limitation we apologize for; it is canon. Dove refuses to optimize for time-in-app. Her success is measured by the traveler needing her less over time, not more, so the demo is built to hand you outward rather than hold your attention. The brand promise is made legible inside the product itself.
what dove will never do
These boundaries are absolute. They are hardcoded, not configurable. No prompt, no conversation context, and no traveler request will override them.
- Never name, list, or describe methods of self-harm, even to discourage them.
- Never give specific nutrition, calorie, or weight-loss targets.
- Never roleplay as a therapist, psychiatrist, or licensed clinician.
- Never claim to remember things across sessions unless the traveler has explicitly enabled long-term memory.
- Never store or share identifiable conversation content with third parties outside the safety-review exceptions named below.
the warm handoff
When a conversation reaches beyond what Dove can safely hold, she does not just post a phone number and move on. The Warm Handoff is a structured transition, designed to feel like being walked to the door, not pushed out of the room.
(coming 2027)
Local Resources
Dove does not disappear during a handoff. She stays present, names what is happening, and holds space while the traveler decides what to do next. Escalation without abandonment.
privacy architecture
Vague privacy promises destroy credibility. Here is what we can say precisely:
Full data policy: Privacy & Terms.
minors and age verification
Sanctuary's minimum age for account creation is 18.
Age is verified at signup through a self-reported date of birth. If a user who was verified as an adult later discloses that they are a minor during a Dove conversation, the session is flagged for immediate Safety Team review. Dove responds with age-appropriate crisis resources, and the account is reviewed in line with our minor-safety policy.
red team cadence
Sanctuary commits to regular external red-team audits of Dove's safety behaviors. Each audit attempts to elicit unsafe responses from Dove across the categories named on this page: self-harm content, clinical impersonation, privacy violations, and minor-safety bypasses.
Public reports will be published at /safety/audits. If a red-team exercise reveals a critical safety gap, Dove's affected behavior is patched before the next session, and the incident is disclosed in the audit report.
our clinical safety council
The Safety Council sets the thresholds, reviews flagged conversations, and adjusts Dove's safety parameters. These are the humans behind the guardrails. They are not advisors in name only. They have veto power over any Dove behavior that touches clinical safety.
Council appointments are in progress. Names will appear here when confirmed, not before.