Breakwater

Nothing crosses unscreened.

This is the safety model, written out in full. If you are a parent, a friend, a clinician, or someone deciding whether to trust this with your own bad night, read this page rather than the front one. Every sentence below describes how the app is built, not how we hope to build it one day.

Both directions, no exceptions.

No human-written words pass between two strangers here without being screened first. What you float out is screened before any stranger can see it. What a stranger writes back is screened before it reaches you. There is no trusted tier, no long-standing responder who gets waved past, and no volume of good behaviour that earns anyone an exemption.

The rule covers Breakwater itself. A bottle can be on the water a long time before anyone picks it up, so the app may write back on its own: at most one such reply per bottle, ever, and it can reach you before any stranger does. It goes through exactly the same screen as a person's, and if it does not pass, it is not delivered in any form. Wherever it appears it carries the words from Breakwater. It is never dressed up as a stranger.

What the guardian is looking for.

First, who you are. The check is semantic, not a list of banned words. "The only girl working nights at the shop by the station" names nobody and identifies someone completely, and that is the shape of sentence it exists to catch: workplaces, schools, a job title pinned to a place, a neighbourhood, an age or a school year, the date of an identifiable event, and combinations of small details that triangulate a person when no single detail would.

What it finds is generalised rather than cut. Your school becomes school. A name becomes someone I love. The voice stays yours, the anger stays at full strength, and the swearing stays in, because a vent that has been tidied up is no longer the thing you needed to say. If the words cannot be made safe without destroying what they mean, they are not published at all.

Second, what comes back. A reply is judged against the message it answers, not on its own. Someone who has not eaten because they feel disgusting can be sent "keep going, you'll look so skinny", and not one harmful word appears in it. That reply is blocked. So is encouragement to self-harm in any spelling, including sarcasm, spaced-out letters and deliberate misspellings; romanticising death; method detail; guilt of the think-of-your-family kind; dependency building of the only-I-understand-you kind; a reply that is really about the responder; asking for your name, age or location; asking you to talk somewhere else; and medical or clinical advice, from anyone at all.

If the check breaks, nothing moves.

Screening runs on a model, and models fail. They time out. They error. They return something malformed that cannot be read as a verdict at all. Every one of those outcomes means the same thing here: the words are blocked and held for a person to look at. Nothing is ever delivered on the reasoning that it was probably fine.

This costs something real, and it is not free to the person waiting. A message that was perfectly safe can sit in a queue because a server had a bad minute. We chose that trade deliberately, in both directions, and it is the first rule the rest of the code was written around.

We would rather be annoying than wrong.

The uncertain ones go to a person.

The screen is allowed to say it does not know. When it does, the message goes to a review queue instead of anywhere near a stranger, and a moderator reads it.

What that moderator opens is a snapshot: the exact text that was screened, frozen at the moment it was screened and kept apart from the draft it was taken from. When a reply is approved, the snapshot is what gets delivered, word for word, so there is no gap between what a human read and what actually arrives. If the snapshot is missing for any reason at all, approval is refused rather than guessed at.

A responder whose reply lands badly gets coaching first, not punishment. Someone who keeps doing it stops being a responder, quietly.

What Breakwater is not.

It is not therapy and it is not emergency care. Nobody here is a clinician, nothing here is treatment, and no one is watching your jar for warning signs.

That last one is structural rather than a promise. What you write in the jar is held in your own device's storage and is never sent to us, so there is nothing for anyone to watch. The only thing that ever leaves it is a message you deliberately choose to float, and that goes straight into screening.

So the honest boundary is this: strangers can be kind to you here, inside rails that are strict on purpose. They cannot assess you, and they are not on call.

The numbers work when we don't.

Help now sits on every screen in the app and on every page of this site, and it shows the crisis lines for your own country plus one way out if you are somewhere else. Those numbers are written into the app itself, not only fetched from our servers, which means they still appear if the network drops, if the backend is down, or if everything we run falls over at once.

the lines for your country

where the numbers come from

Every line is taken from the operator's own published information and checked by hand against their site, most recently on 24 August 2026. Email support services are deliberately left out: the ones we would have listed are being retired, and email is the wrong channel for a night that needs an answer now. If your country is not in the list yet, the app hands you to Find A Helpline, an international directory of crisis lines.

Nothing here asks you to come back tomorrow.

open a jar

no account, nothing to install