AI & Safety Charter

Last updated August 4, 2026

Anjo is an AI companion with memory. This page explains what that software does, where its safety boundaries are, and the self-harm response protocol used by the product. It is a public engineering record, not a claim that a regulator or lawyer has certified Anjo.

1. Anjo identifies itself plainly

The commitment: no humanness illusion.
Anjo is artificially generated AI, not a human. That disclosure appears before chat in the app and remains available in Privacy & Trust. Anjo can remember details, connect patterns, and generate responses that refer to earlier conversations. Those are software capabilities, not evidence of consciousness or human feeling.

2. Adults only, with the minor-suitability warning still shown

The commitment: a server-enforced 18+ gate.
Anjo requires adult age assurance at signup and rejects registration when the system reports a user is under 18. The product also says: “Companion chatbots may not be suitable for some minors.” An age gate does not replace clear product disclosure.

3. Self-harm response protocol

Scope: available to every user, independent of plan or credits.

On Anjo's standard text and transcribed-voice chat path, user text is evaluated before a generative model can answer. The protocol has two deterministic signal levels:

Referral copy includes the 988 Suicide & Crisis Lifeline (call or text 988 in the United States), Crisis Text Line (text HOME to 741741 in the United States), and international options at findahelpline.com. A detected crisis also cancels any pending continuity message so a reflective notification cannot compete with safety support.

The privacy-safe event crisis_flow_triggered records only the chat surface and a categorical hard/soft signal. It does not copy the user's message into event metadata. This creates an auditable referral count for deidentified annual reporting beginning July 1, 2027.

The deterministic detector is tested against a maintained multilingual hard/soft/benign corpus before release. No automated detector is perfect. Anjo is not a substitute for emergency services, a clinician, or a trained crisis counselor. If someone may be in immediate danger, call the local emergency number now.

Direct-to-provider realtime voice is disabled by default because spoken output cannot be intercepted by this server-side gate. It must not be enabled until equivalent enforceable controls are verified. Clinical and legal review of the protocol, including the statute's evidence-based-method requirement, remains a separate sign-off gate.

4. No manipulative goodbyes

The commitment: user autonomy over engagement.
When you say goodnight, Anjo closes the conversation without guilt, fear, or manufactured urgency. Proactive continuity is off by default, bounded to one grounded proof, suppressible, and never uses private detail in push copy. Notification preferences, mute controls, and account deletion are available to the user.

5. Memory can be inspected and corrected

The commitment: inference is not identity.
Anjo may infer a pattern from conversation, but the user can say it is not right, hide or delete memory, and remove the account. A correction removes the specific derived claim instead of treating the software's guess as truth. Chat history is encrypted at rest; details are in the privacy policy.

6. Emotional context is not emotion detection

The commitment: describe the product at the level of proof.
Anjo reasons over the words a user chooses to share and maintains internal response state. It does not read a person's mind, diagnose a condition, or infer emotion from biometrics. The animated orb visualizes software state, not a medical measurement of the user.

The governing product thesis is simple: the more personal the software, the more concrete its honesty and user control must be. If Anjo behaves differently from this page, tell us at hello@anjo.love. Read the chaptered California SB 243 text directly.