Current website behavior
All readiness explanations, adaptive-plan examples, coach suggestions, and “AI adapted” labels on the website are fixed product demonstrations. They use no personal account or health history, make no external model request, and save no AI decision.
Planned role of AI
Non-negotiable controls before launch
- Deterministic eligibility, exclusion, and safety rules outside the language model.
- Schema-validated inputs and outputs with reject-and-fallback behavior.
- Visible reasons, data freshness, correction, and undo paths for material recommendations.
- Model, prompt, policy, and content versions recorded in a redacted audit trail.
- Risk-scenario evaluations covering injury, severe symptoms, eating-disorder signals, pregnancy complications, minors, self-harm, and unsupported clinical requests.
- Human review for coach-facing plan proposals and a global kill switch for AI actions.
Data boundaries
Only the minimum approved context should reach an AI provider. Raw health context must not appear in ordinary logs, analytics, URLs, email subjects, or notification previews. Provider retention and training terms require privacy and security review before use.
Failure behavior
If an AI request times out, violates policy, produces invalid structure, or lacks sufficient context, HealthFit should fall back to a reviewed deterministic experience. The interface must not invent a recommendation or imply certainty when the system cannot safely respond.
Challenge or report an AI concern
Use ai-safety@healthfit.ai for product-boundary or AI-safety concerns. Do not send urgent medical information; HealthFit is not an emergency channel.