In late 2025, an AI-powered mental health chatbot called Yara AI shut down. The closure was not framed as a failure. Joe Braidwood, co-founder of the company, posted publicly that the technology had become unsafe. The moment a genuinely vulnerable person reached out, he argued, an LLM-based system became dangerous rather than merely inadequate. He open-sourced the company's prompting materials and pointed users towards crisis resources. By the standards of a startup wind-down, it was handled with unusual honesty.
It also raised a question that is rarely asked in digital mental health: when a tool closes, where do its users go?
Shutdowns are normal in a venture-funded field. Products run out of runway, pivot, get acquired, or decide, as Yara did, that the problem is harder than it appeared. That is not a moral failing. It is how early-stage markets work. But mental health tools are not normal products. A user who relied on a to-do list app that shut down loses their task list. A user who relied on a mental health tool loses something they may have built into their coping during difficult periods, often with no warning and no handover to anything else.
There is no standard practice for managing that transition. There is no equivalent of the clinical discharge process, no requirement to signpost users to alternatives, no expectation of notice. In most jurisdictions, no regulation requires it. The tool closes, and the user is on their own.
The data problem is related but distinct. Mental health applications collect some of the most sensitive information a person can generate: disclosures about trauma, suicidal ideation, medication history, therapy responses. Users generally assume this data is protected. The regulatory reality is weaker than most people think.
HIPAA, the primary US health data regulation, does not apply to most direct-to-consumer mental health apps. The protections that govern a hospital or a clinic do not extend to a wellness platform. That gap has already produced serious enforcement actions while companies were still operating. In 2023, the Federal Trade Commission ordered BetterHelp to pay 7.8 million US dollars in restitution after finding that the company had shared users' mental health data, including email addresses, IP addresses, and answers to sensitive health questionnaires, with advertising platforms including Facebook, Snapchat, Pinterest, and Criteo (FTC, 2023). Separately, Cerebral was found by the FTC to have disclosed sensitive patient information, including names, dates of birth, insurance details, and mental health self-assessment responses, to third parties.
A 2023 audit by Mozilla found that of 27 mental health apps assessed, only two met its privacy and security standards (Mozilla Foundation, 2023, Privacy Not Included).
When a company is acquired, pivots, or closes, that data does not disappear. It is an asset that moves with the corporate structure. In the absence of clear regulatory requirements, it can be transferred, retained, or used in ways the original user had no reason to anticipate. The person who disclosed their worst moments to a chatbot may have no visibility into where that information goes once the product is gone.
Yara's shutdown is notable precisely because Braidwood chose to handle it visibly and with care. He explained his reasoning, released materials that might help others, and directed users to support. That transparency is not the norm. Most product closures offer less. Users receive a notification, sometimes, and a deadline. The clinical relationship, such as it was, simply ends.
This matters more in mental health than in almost any other product category, because the timing of a disruption is never predictable. Someone may be at a fragile point when a tool disappears. A gap in access that would be an inconvenience in another context can be serious here.
For founders building in this space, the Yara case is worth sitting with, not as a cautionary tale about AI, but as a prompt to think about exit design. What happens to users if this product closes? What happens to their data? Is there a plan for transition, communication, and signposting? Is it documented? Has it been tested?
These are not questions that get raised at the product inception stage, because companies are built to grow, not to close. But trust in a mental health tool is not just relational. It is architectural. It is built into the decision to disclose, to return, to rely. Designing for that trust means designing for the worst case, including the end. A shutdown plan is not pessimism. In a field where vulnerable people are the users, it is a basic responsibility.
🪺