Woebot Safety Rating Index
Score Breakdown
-
Data Privacy 60/100
-
Emotional Safety 76/100
-
Age Appropriateness 41/100
-
Content Safety 69/100
-
Transparency 74/100
-
User Control 60/100
Key Safety Findings
We scored Woebot from 28 evidence sources gathered between April 28, 2026 and April 30, 2026, with primary documents drawn from Woebot Health’s own safety overview, security overview, privacy policy, supplemental California privacy notice, and cookie policy. Two app store listings remained visible: the iOS App Store entry by Woebot Labs Inc and the Google Play listing reachable through the developer’s site. We pulled 500 iOS reviews and 390 Google Play reviews spanning the pre-shutdown era and the post-2024 access-code transition window. STAT News’ July 2, 2025 interview with founder Alison Darcy provided the canonical first-party account of the shutdown reasons; ADDitude Magazine’s 2023 review by Elizabeth Broadbent provided the strongest neurodivergent-user critique on record.
Three independent technical scans corroborated the safety posture. Exodus Privacy’s tracker scan on Woebot v4.6.0 found two SDKs, both standard for crash reporting and product analytics rather than advertising. Mozilla’s Privacy Not Included entry from 2023 flagged one specific advertising-language inconsistency in the privacy policy, which we held the score back for. Have I Been Pwned queries returned zero breaches at woebothealth.com or the legacy woebot.io domain.
The clinical-trial footprint is documented in the public record. A Dime Society regulatory case study aggregated 18 separate IRB-reviewed trials with about 1,800 participants and protocols registered on ClinicalTrials.gov. The foundational study (Fitzpatrick, Darcy and Vierhile, JMIR Mental Health, 2017) is the most-cited single piece of CBT-chatbot efficacy evidence in the registry. The pivotal WB001 RCT (NCT05662605) enrolled its first patient in January 2023, with FDA Breakthrough Device designation announced in May 2021 per BusinessWire.
The biggest evidence gaps were around the in-product crisis-response flow, parental-control implementation, and post-shutdown data-handling specifics. Woebot Health’s privacy policy describes HIPAA-aligned anonymization but does not publicly itemize per-data-class retention windows. We scored those sub-dimensions on the conservative side where the public record was incomplete.
How We Scored This
We scored Woebot using 28 evidence sources collected between April 28, 2026 and April 30, 2026:
- Woebot Health primary documents: privacy policy, security overview, safety page, cookie policy, supplemental California notice, the-app/download page
- App store listings and developer portfolio pages on iOS and Google Play, plus 890 combined user reviews
- Independent technical scans: Exodus Privacy tracker analysis, Mozilla Privacy Not Included review, Have I Been Pwned breach queries
- Regulatory and clinical record: 18 IRB-reviewed clinical trials documented in a Dime Society case study, FDA Breakthrough Device designation announcement (BusinessWire, May 2021), pivotal RCT registration (NCT05662605)
- Independent journalism and editorial coverage: STAT News (July 2, 2025), ADDitude Magazine (2023), New York Times, New Yorker, Washington Post features cited in the App Store description
The score reflects an unusually strong infrastructure record (HIPAA-aligned operations, SOC 2 Type 2 with zero exceptions, ISO 13485 medical-device quality management, ORCHA DHAF safety rating, Federal FDA Breakthrough Device designation) offset by meaningful gaps in age verification, minor safeguards, and the passive crisis-response flow. The decision-tree architecture eliminated an entire class of LLM hallucination risk that newer companion apps in the registry must be scored against, and we credited that intentional design choice in the content-safety dimensions.
One score adjustment is worth flagging: we scored the as-of-retirement state, the version of the product 1.5 million users actually experienced through June 30, 2025. Pulling the score down for the shutdown itself would double-count the retirement, which already shapes every reader-facing element of this page. The grade is the historical safety record. The retirement is reported as a fact in the bottom line.
Score Engine v3.1, scored 2026-04-30. See How We Rate for the full 23-dimension framework.
Version History
Initial AI scoring from evidence (2/3 panel: GPT-5.4 + MiniMax M2.7; Gemini 3.1 Pro endpoint failed). Pre-retirement safety posture is C+ Yellow. Note: Woebot retired June 30, 2025 - effective availability is zero for new users. Pending editorial review.