noor
Effective 25 August 2026

Our crisis protocol

noor is a journal with an AI companion. It is not an emergency service, and it cannot contact anyone on your behalf. This page sets out exactly what noor does when something you write suggests you may be in danger — what looks for it, what happens next, what we do not do with that signal, and where it still falls short. If you need help right now, please contact your local emergency services or a crisis line; the SOS screen in the app lists one for your country.

Published because California SB 243 requires an operator of a companion chatbot to publish its crisis protocol. It describes what the app already does — it is a description of behaviour, not a promise about a service.

What noor is not

noor does not monitor your journal in real time, and no person at Radaydeh (Pty) Ltd reads your entries. Sofia is a software program, not a licensed therapist, psychologist, or counsellor, and nothing noor produces is medical advice, diagnosis, or treatment.

noor cannot call anyone for you, cannot alert a contact, and cannot dispatch help. If you are in immediate danger, the app is the wrong tool — contact your local emergency number.

Two layers, and neither replaces the other

The first layer runs on your phone. It is a list of phrases, in several languages, checked against what you write before anything is sent anywhere. It works offline, it runs instantly, and it runs on every entry and every message to Sofia, whatever your settings say.

The second layer asks an AI model the same question about the same words. It exists because the first layer is blind to any phrasing nobody thought to write down: an adversarial test in August 2026 got 42 of 43 plausible disclosures past the word list simply by avoiding the obvious words. The model layer catches indirect language, metaphor, and the dozens of languages the word list does not cover.

The model layer is deliberately the second line, never the only one. It needs a network connection and a working AI provider, and a safety net that stops working when an API call fails is not a safety net. Whenever the model layer cannot run, the on-device word list still does. Neither layer may be removed on the grounds that the other exists.

How the judgement is made

The model is asked as a separate question, not as part of writing your reflection. That is deliberate: a model instructed to be warm and non-alarming will talk itself out of raising a flag, and the same quality that makes a good companion makes a poor screen. It answers at zero variability, so the same words get the same answer every time.

There are three levels: nothing there, possible, and acute. "Possible" is the level the screen is told to use when it is unsure — and "possible" acts. Uncertainty resolves toward showing you help, because the cost of being wrong in that direction is a screen you can dismiss.

A missing or unrecognised answer counts as "not screened", never as "screened and safe". The screen judges your own words about yourself: a film you watched, a lyric you quoted, or a worry about someone else is not treated as a disclosure about you.

Ordinary sadness, stress, grief, exhaustion and frustration are not crises, and are not treated as any. Treating every hard day as an emergency would teach you to ignore the one time it matters.

What happens when either layer fires

noor opens its SOS screen, which puts a crisis line and your local emergency services in front of you, one tap from dialling. Nothing you were doing is interrupted or deleted, and your entry is still saved. The screen can be dismissed.

Your reply — the reflection, or Sofia's answer — still arrives, and it is written to acknowledge what you said rather than to hand you a technique. No exercise, no reframing, and no breathing session is offered as an answer to a disclosure of self-harm.

Which crisis line you are shown

The number comes from a single table of national crisis lines, resolved to your country. Both the SOS screen and anything the AI says in prose read that same table, so the two can never name different organisations.

When noor cannot tell which country you are in, it is instructed to name no specific number at all and to point you to your local emergency services instead. This is a rule learned the hard way: an earlier version let the model choose, and it offered a United States number to a user in Johannesburg — a line that does not answer from South Africa, at the worst possible moment, with no way for them to know why.

What we do not do with the signal

The result is used to decide whether to show you the SOS screen, and for nothing else. It is not kept as a profile about you, not used for advertising, not sold, and not shared with anyone. We do not build a risk score, and there is no watchlist.

We do not contact you about it, and we do not contact anyone else about it.

Where this still falls short

The word list has known gaps that were left in on purpose, because each would fire constantly on ordinary writing: sentences like "what's the point of any of this", "I want it to stop", or a goodbye at the end of a grateful entry. Widening it that far would bury the signal in false alarms. The model layer is what covers these, and it is not perfect either.

The non-English phrase patterns were written without first-language speakers of those languages, and a safety net nobody fluent has read is a promise we cannot yet fully keep. They only add to the English coverage — nothing about them narrows it — and having them reviewed is on our pre-launch list.

Both layers can miss. noor is not a monitoring service, and it should never be relied on as one.

If something went wrong

Every AI-written reply in noor carries a "Report this reply" control, and we read what comes through it. If noor missed something it should have caught, or showed you a crisis screen when nothing was wrong, please tell us — it is the most useful thing we receive. noor@noorlife.ai

Questions about this document?

Radaydeh (Pty) Ltd (South Africa) operates noor.

noor@noorlife.ai