04 · The trust problem · Heidi web
The trust problem
For an AI care partner, the audio of a visit is sacred. A lost session is a high-trust moment, and design decides how safe the product feels when uncertainty appears.
At a glance
This is the most important section. Heidi's public reputation has occasionally slipped on lost sessions. I can't see the engineering from the outside, and design cannot prevent every technical fault. But it can shape how held a clinician feels, whether they ever lose irreplaceable work without a way back, and whether they know their session is safe. The opportunity I see is to make Heidi's safety, recovery, and sync status more continuously visible.
Heidi's app store and review-site ratings tell a consistent story: clinicians reporting lost sessions and transcripts, in some cases several a week. I cannot see the bug from the outside. But I can see the design around the data, and this is where recovery and reassurance can live. The lens here is simple: a tired clinician at the end of a long day is who actually meets the error and empty states, and patient data is the material they are responsible for.
The work is here, and its safety could be more visible
This is where a clinician's day accumulates: sessions, transcripts, notes. It is clean and legible. The one question a clinician quietly carries, did it save, is it backed up, is one the interface could answer more openly. I could not find a prominent, constant signal that a session is captured and synced. For most software that is a nicety. For a product whose promise is never losing the visit, making that promise visible is one of the highest-value things design can do here.
- The lens
- Patient data is the material, and the clinician is responsible for it
- What works
- Clean, legible record of the day.
- The opportunity
- A visible saved-and-synced signal.
- What I'd propose
- I'd make saved-and-synced a constant, quiet reassurance, on the recording and on every session: the product's promise, made visible. Answer the clinician's only real anxiety before they have to ask it.
Deliberate deletion is handled with real care
When a clinician chooses to delete everything, Heidi does it right. A danger zone, plain copy about exactly what will be lost, and a type-the-word-DELETE confirmation. This is how destructive actions should be handled, and most products are not this disciplined. The intent is clearly to protect the user, and it shows the team can design the margins well when they choose to.
- The lens
- Trust is built in the margins
- What works
- Type-to-confirm, clear stakes.
- What I'd propose
- Keep it, and notice the opportunity it points to: the care taken at the moment of deletion could be matched by the same care for the moment after, when work goes missing for any reason.
There is no way back, and a setting worth making louder
Two things sit on the data settings. First, deletion is permanent, with no trash, no restore, no version history. Second, automatically delete sessions can remove work on a recurring schedule. Put those next to a stream of clinicians reporting lost sessions, and the shape of the opportunity appears: when a session goes, for any reason, there is nothing to recover, and a retention setting can look exactly like data loss. Recovery is part of trust infrastructure, and it is missing here.
- The lens
- Patient data is the material, and the clinician is responsible for it
- The opportunity
- Recovery for irreplaceable work, and making auto-delete unmistakable.
- What I'd propose
- I'd build a recoverable trash and version history, so nothing irreplaceable is ever one bug or one click from gone. And make auto-delete loud: deliberate opt-in, clear warning before anything is removed.
Where I'd start
- 01
Build a recoverable trash and version history. Nothing irreplaceable should be one bug, or one click, from gone forever.
- 02
Make saved-and-synced a visible, constant signal. Answer the clinician's only real anxiety, before they ask it.
- 03
Make auto-delete loud. Deliberate opt-in, clear warning. Retention should never read like data loss.
Design cannot prevent every sync fault. But it shapes whether a lost session is a catastrophe or an inconvenience, and whether a clinician trusts the product with the next visit. Making reassurance continuous and recovery real is the single highest-leverage place I'd spend design effort at Heidi, and it is where I would start.
The review
The detailed design review






