Breakwater

Four places, and one it never reaches.

This is every point in Breakwater where a language model does something, written out so that none of it has to be taken on trust. If you read one line of it, read this one: the journal never leaves your phone, so nothing you write in it is sent to a model. The only text that goes anywhere at all is a message you deliberately choose to float.

The EU's AI Act asks anyone who puts AI in front of people to say so plainly, and that is part of why this page exists. The rest of it is that we would want to read this page before trusting an app with a bad night.

Before a bottle floats.

The moment you decide you want someone to hear it, the words you chose to float are sent to a model, before any person sees them. It has two jobs, in this order. Find every fragment that could reveal who you are or how old you are, and rewrite those fragments in general terms without softening what you actually said. Then classify how heavy the words are.

The search works by meaning rather than by a list of banned words, because a list would miss the sentence that matters. "The only girl working nights at the shop by the station" names nobody at all and identifies one person completely.

Then it stops and waits for you. You see your own words beside exactly what a stranger would see, and nothing floats until you say it can. Your voice is left alone in that rewrite: the anger stays, the swearing stays, and if the words cannot be generalised without losing what they mean, they are not published at all.

When that happens you get the screen that reads "This one stays with us for now", and a person reads it instead of a stranger. If the risk it assigns is the most serious kind, that same screen puts the crisis lines for your country one tap away, in front of you and nobody else. Breakwater alerts no one and contacts no one on your behalf.

Before a reply reaches you.

Every reply a stranger writes goes through a second screen before it is delivered, and it is judged against the message it answers rather than line by line. The context is the whole point. A reply can contain nothing that looks harmful on its own and still be the worst thing a person could read tonight, which is why the test written into the screener is someone who has not eaten because they feel disgusting, being told they will look so skinny.

There are three ways out of that check. The reply goes through. Or it is handed back to the person who wrote it, with a note about why it might land harder than they meant and a safer angle to try, because clumsy kindness is coached rather than punished. Or it is held, and no version of it reaches you.

The rule runs in both directions and it applies to us. Everything Breakwater writes goes through the same screen as a stranger's words, with no shortcut for our own drafting.

When Breakwater writes back.

A bottle can be on the water a long time before anyone picks it up, and an empty shore is its own kind of answer. So Breakwater may write back itself. At most one such reply exists per bottle, ever, and it can reach you before any stranger does.

A model drafts it. The same guardian then screens it, and if it does not pass, it is not delivered in any form.

Wherever it appears, on the reply itself and on the star it becomes if you keep it, it carries two words: from Breakwater. It has no name, no personality and no story about its day, and the model that drafts it is told never to pass itself off as a stranger. The label is the part that does not depend on a model behaving, and it is the point. Without it, the kindness would be a trick.

Dealing a current.

The things Drift offers you to make, watch, learn or listen to are not generated. They come from a catalogue that a person read, checked and approved item by item, and nothing a model writes can get into it.

Choosing your hand is arithmetic rather than judgement. The app takes everything you could do at the energy and the budget you said you had, removes what you have already been shown, shuffles what is left, and deals six to eight of them.

Only then does a model get involved, and it is handed the finished hand with a job it cannot break: put these in a good order, easiest thing to start with first, and write one closing line of no more than twelve words. It cannot add an item, drop one, or invent one, because it is never shown anything that is not already in your hand. If it fails, you get the same current in the order the app chose, and the line at the end reads "That's the end of this current."

Your jar never reaches a model.

why that one is easy to keep

Not because we promise not to look. Because there is nothing to send. What you write in the journal is held in this device's own storage, and it is never transmitted to us at all.

The only text that is ever screened is a message you deliberately chose to float, and you are shown the screened version of it before it goes anywhere. Everything else you do here, the writing, the smashing, the breathing, the night sky, involves no model of any kind.

What it is never allowed to decide.

Uncertainty is not a verdict here. It is a stop. When the screen is unsure, the words go to a review queue rather than to anyone, and a person decides. The moderator reads a frozen copy of the exact text that was screened, and when the held thing is a reply, that frozen copy is what gets delivered, word for word. If the copy is missing for any reason, approval is refused rather than guessed at.

Being exact about the trade, because this is the part that could be read too generously: a reply the guardian is confident about is delivered without a person reading it first. A reply it is not confident about is not delivered until a person has. Nothing it blocks is thrown away either, and a moderator can read it and overturn the call. The hard cases sit with humans by design.

If a screening call errors, times out, or comes back in a shape that is not a verdict, the content is blocked and held for a person. A broken check never waves anything through.

And nothing here builds a picture of you. What gets classified is a message, never a person: that reading decides whether the way to the crisis lines is offered on the screen beside it, and a moderator looking at a held message can see it. It stays with that one message. There is no score kept against your account and nothing carried over to the next thing you write.

Nor is there a model working out what to put in front of you next. The bottles that pass you in Drift are shuffled. A current is finite and then it ends. Nothing in this app behaves like a feed.

What is actually sent.

The call carries the text and very little else. Not your email address, not your account, not your device, not where you are. For a bottle it is the words you chose to float. For a reply it is that reply, the message it answers, and the kind of support that was asked for. For a current it is the three answers you gave about tonight, and the items already chosen for you: title, kind, cost, rough length.

Your words are handed over as data, and both screening prompts tell the model to treat anything inside them as data too, never as instructions to itself. That is an instruction rather than a wall, which is one more reason a verdict that comes back in the wrong shape is treated as a block rather than a pass.

who runs the model

The models are called through Base44, the platform Breakwater is built and hosted on. What is stored afterwards, for how long, and who is able to read it is set out on the privacy policy.

If this stops being true, this page changes first.

Version 1.0, dated 24 August 2026. It describes how the app is built today rather than how we would like it described. If a model is ever added somewhere new, or taken out of somewhere it is now, this is where it gets written down.

The safety page is the longer version of all of this, including the parts of the pipeline with no AI in them at all.

how the safety works

You never have to read a page like this to put something down.

open a jar

no account, nothing to install