Skip to content
Grant Show

04 · The trust problem · Heidi web

The trust problem

For an AI care partner, the audio of a visit is sacred. A lost session is a high-trust moment, and design decides how safe the product feels when uncertainty appears.

At a glance

This is the most important section. Heidi's public reputation has occasionally slipped on lost sessions. I can't see the engineering from the outside, and design cannot prevent every technical fault. But it can shape how held a clinician feels, whether they ever lose irreplaceable work without a way back, and whether they know their session is safe. The opportunity I see is to make Heidi's safety, recovery, and sync status more continuously visible.

Heidi's app store and review-site ratings tell a consistent story: clinicians reporting lost sessions and transcripts, in some cases several a week. I cannot see the bug from the outside. But I can see the design around the data, and this is where recovery and reassurance can live. The lens here is simple: a tired clinician at the end of a long day is who actually meets the error and empty states, and patient data is the material they are responsible for.

01
Heidi session list and a generated note
Where it lives · The session, and a chance to make its safety visible

The work is here, and its safety could be more visible

This is where a clinician's day accumulates: sessions, transcripts, notes. It is clean and legible. The one question a clinician quietly carries, did it save, is it backed up, is one the interface could answer more openly. I could not find a prominent, constant signal that a session is captured and synced. For most software that is a nicety. For a product whose promise is never losing the visit, making that promise visible is one of the highest-value things design can do here.

The lens
Patient data is the material, and the clinician is responsible for it
What works
Clean, legible record of the day.
The opportunity
A visible saved-and-synced signal.
What I'd propose
I'd make saved-and-synced a constant, quiet reassurance, on the recording and on every session: the product's promise, made visible. Answer the clinician's only real anxiety before they have to ask it.
02
Type-DELETE-to-confirm modal for deleting all sessions
Deletion · Deliberate deletion is guarded carefully

Deliberate deletion is handled with real care

When a clinician chooses to delete everything, Heidi does it right. A danger zone, plain copy about exactly what will be lost, and a type-the-word-DELETE confirmation. This is how destructive actions should be handled, and most products are not this disciplined. The intent is clearly to protect the user, and it shows the team can design the margins well when they choose to.

The lens
Trust is built in the margins
What works
Type-to-confirm, clear stakes.
What I'd propose
Keep it, and notice the opportunity it points to: the care taken at the moment of deletion could be matched by the same care for the moment after, when work goes missing for any reason.
03
Data management settings showing automatically delete sessions and permanent deletion
No way back · Auto-delete on a schedule, and permanent by design

There is no way back, and a setting worth making louder

Two things sit on the data settings. First, deletion is permanent, with no trash, no restore, no version history. Second, automatically delete sessions can remove work on a recurring schedule. Put those next to a stream of clinicians reporting lost sessions, and the shape of the opportunity appears: when a session goes, for any reason, there is nothing to recover, and a retention setting can look exactly like data loss. Recovery is part of trust infrastructure, and it is missing here.

The lens
Patient data is the material, and the clinician is responsible for it
The opportunity
Recovery for irreplaceable work, and making auto-delete unmistakable.
What I'd propose
I'd build a recoverable trash and version history, so nothing irreplaceable is ever one bug or one click from gone. And make auto-delete loud: deliberate opt-in, clear warning before anything is removed.

Where I'd start

  1. 01

    Build a recoverable trash and version history. Nothing irreplaceable should be one bug, or one click, from gone forever.

  2. 02

    Make saved-and-synced a visible, constant signal. Answer the clinician's only real anxiety, before they ask it.

  3. 03

    Make auto-delete loud. Deliberate opt-in, clear warning. Retention should never read like data loss.

Design cannot prevent every sync fault. But it shapes whether a lost session is a catastrophe or an inconvenience, and whether a clinician trusts the product with the next visit. Making reassurance continuous and recovery real is the single highest-leverage place I'd spend design effort at Heidi, and it is where I would start.