For a busy founder, an AI meditation app can sound like a sensible shortcut: a five-minute breathing session between meetings, a mood check-in after a difficult client call, or a chatbot that offers a personalised wind-down routine. These tools may be useful additions to an everyday wellbeing routine. But they can also invite people to disclose some of their most personal information, while making health-related promises that deserve a closer look.
That is why the Medicines and Healthcare products Regulatory Agency (MHRA) has published practical advice for people choosing digital mental health tools. Its central message is straightforward: before relying on an app, understand what it claims to do, who it is designed for, the evidence behind it, how it handles data and whether it is regulated as a medical device. The MHRA stresses that digital mental health tools are not a replacement for professional healthcare. Read the MHRA’s January 2026 guidance announcement.
For UK small business owners, this matters twice. You may be choosing an app for yourself while under pressure, and you may also be tempted to offer subscriptions as part of a staff wellbeing package. In either case, a glossy app-store listing, an influencer recommendation or an AI label is not a safety assessment. Use the five checks below before downloading, paying for or recommending an AI meditation, mood-tracking or wellbeing app.
Why a mindfulness app needs due diligence
Not every meditation app is a medical product. A simple timer, library of relaxation recordings or journal can sit comfortably in the general wellbeing category. That does not make it worthless or automatically risky; it means its purpose is different. The level of scrutiny should rise when the app goes further and claims it can identify a condition, assess symptoms, prevent relapse, treat anxiety or depression, manage a diagnosed condition, or tell someone what clinical action to take.
The distinction is especially important with AI. An app may use AI simply to recommend a shorter audio session after you say you slept badly. Another may analyse mood entries, free-text diaries, voice recordings or wearable data and produce an apparent risk score or treatment-style recommendation. Both may look conversational and reassuring. Their intended purpose, evidence needs and potential consequences are very different.
The MHRA’s digital mental health technology guidance explains that intended purpose and functionality are key to deciding whether a product qualifies as software as a medical device. Complex technologies with a medical purpose must meet medical-device requirements and demonstrate safety and effectiveness against recognised standards. See the MHRA’s guidance on qualification and classification.
Think of this article as a buyer’s checklist, not a diagnosis tool. It can help you make a more informed consumer or procurement decision. It cannot establish whether an app is right for a particular person or situation.
Check 1: Start with the claim, not the branding
Ask exactly what the app says it will do
Begin with the wording on the app’s website, app-store page, onboarding screens, paid advertising and social channels. Do not rely only on its name. “Calm”, “mindful”, “resilient” and “wellbeing” are marketing language. The useful question is: what outcome does the developer say the product delivers?
General wellbeing claims might include helping users practise breathing, build a meditation habit, reflect on their day, improve relaxation or access educational content. These claims still require honesty, thoughtful design and decent privacy practice, but they are not necessarily medical claims.
Put the app in a higher-scrutiny category if it says, or strongly implies, that it can diagnose, treat, prevent, monitor or manage a mental health condition. Examples include statements such as “detects depression from your journal”, “clinically treats anxiety”, “reduces PTSD symptoms”, “identifies suicidal thinking”, “replaces therapy”, or “manages your bipolar disorder”. A disclaimer buried in the terms will not neutralise a prominent medical-style promise elsewhere.
This is not merely a wording exercise. A founder exhausted by cash-flow worries may see “AI detects burnout” and interpret it as a meaningful assessment. An employee may take a chatbot’s confident reply as clinical advice. When an app makes health claims, the potential harm from an inaccurate, delayed or inappropriate response is greater.
- Low-claim example: “Choose a guided breathing session to help you pause before a presentation.”
- Higher-claim example: “Our AI identifies your anxiety disorder and prescribes the right daily intervention.”
- Practical action: Screenshot the claims you are relying on before you subscribe. If the promise is unclear, inflated or changes from page to page, treat that as a reason to pause.
The MHRA advises users to distinguish between general wellbeing support and products that claim to diagnose, treat or manage a mental health condition, and to expect medical-benefit claims to be clearly explained and supported by evidence. Its five public-facing checks are a useful starting point.
Check 2: Confirm who it is actually for
“Personalised” does not mean suitable for everyone
Good products state their intended users clearly. Look for the target age group, the setting in which the app is meant to be used, whether it is designed for general wellbeing or for people with a particular condition, and whether clinician involvement is expected. Also look for exclusions, contraindications and warnings.
A tool designed for adults with mild, self-reported stress may not be appropriate for a teenager, someone who is pregnant or recently postpartum, a person living with a serious mental illness, or someone in acute distress. The issue is not that those groups cannot use digital support. It is that an app’s evidence, safeguards and escalation routes may not cover them.
AI features make this question more pressing. Ask what the AI can and cannot do. Does it generate generic prompts from choices you make? Does it interpret written entries? Does it adapt from your past activity? Does it claim to spot signs of clinical deterioration? Is there a human professional behind any review, or is the interaction entirely automated?
Be wary of a product that makes broad claims but gives no boundaries. A responsible app should explain situations in which it is not appropriate, direct users towards help when needed and avoid presenting itself as an always-available substitute for human judgement.
- For your own use: Match the app to the purpose you actually have. A meditation library may be enough if you want a calming routine; it is not the same thing as treatment for persistent symptoms.
- For a staff benefit: Do not assume a consumer app is suitable for every employee just because it is popular. Offer it as optional support, make clear that use is voluntary and do not expect staff to disclose mood data, journal entries or app activity to a manager.
- For younger users: Check age limits, parental information, safeguards and whether the product has been evaluated for that age group before sharing it with employees’ families or young apprentices.
The MHRA specifically notes that a product built for adults may not be suitable for children or teenagers, and that the intended users should be stated clearly. Review the MHRA’s user guidance summary.
Check 3: Look for evidence that matches the promise
Testimonials are not the same as evaluation
A long list of five-star reviews can tell you that people enjoyed an app’s interface. It cannot, by itself, show whether the product safely improves the outcome it promises. The same goes for claims that an app is “science-backed” or “built with psychologists”. Ask what has actually been tested.
Start with three simple questions. Is there a public evidence page? Does it name the app and the feature being promoted, rather than relying on research about meditation in general? And does it explain the people studied, the comparison used, the outcomes measured, the limitations and who funded the work?
Evidence should be proportionate to the claim. An app that offers optional, general relaxation content may reasonably point to clear content sources, qualified contributors, user testing and safety information. A product that claims to treat a condition, assess risk or guide clinical decisions needs much stronger and more directly relevant evidence. Research on an earlier version of the app may not validate a newly introduced AI chatbot or mood-scoring feature.
Watch for a common leap in logic: “mindfulness can help some people” does not establish that every AI meditation app works, that its personalisation is accurate, or that it is safe for every user. Likewise, a trial conducted with supported users in a structured service may not prove that an unsupervised consumer version will work in a founder’s late-night bedroom or during an employee’s crisis.
NICE’s Evidence Standards Framework is aimed primarily at developers and health-and-care decision makers, but it gives buyers a helpful benchmark: good digital-health evidence should help decision makers judge likely benefits, safety and value. NICE also makes clear that meeting its framework does not itself amount to regulatory approval or NICE endorsement. Explore the NICE Evidence Standards Framework.
- Green flag: The developer links to product-specific studies or an independent evaluation, explains what was measured and acknowledges limitations.
- Amber flag: The evidence is about a broad technique, not the app, or applies only to a non-AI feature.
- Red flag: Big clinical promises, but no accessible evidence beyond testimonials, celebrity endorsements or vague references to “proprietary science”.
If you are buying licences for a team, ask the supplier for its evidence pack, safety policy, product version history and an explanation of how it tests changes to AI features. A short procurement email now is easier than explaining later why staff were directed to an unsuitable tool.
Check 4: Treat mood and journal data as highly sensitive
Read the data journey before completing onboarding
Mood-tracking and AI wellbeing apps can collect far more than an email address. Depending on the product, they may receive check-in scores, sleep patterns, notes about relationships, journal text, recorded voice, wearable information, medication reminders, location signals or information inferred from how and when the app is used. A free-text message to an AI chatbot can be particularly revealing because users often write as if they are confiding in a person.
Under UK data-protection law, data concerning health is special category personal data and receives extra protection. The Information Commissioner’s Office explains that health data can cover information revealing an individual’s past, current or future health status, including data from medical devices and fitness trackers. Read the ICO’s explanation of special category data.
You do not need to be a privacy lawyer to ask sensible questions. Find the privacy notice before creating an account, not after you have typed a detailed journal entry. The ICO says privacy information should be concise, transparent, intelligible, easily accessible and written in clear, plain language. See the ICO’s guidance on the right to be informed.
- What is collected? List the data requested at sign-up and the permissions requested later, including microphone, contacts, photos, location, health-platform connections and notifications.
- Why is it needed? Can you use the core meditation content without granting every permission? Does the explanation make practical sense?
- Where does it go? Identify the developer, relevant cloud or AI providers, third-party analytics firms and any partners that receive data.
- Is AI chat used to train or improve models? Look for an explicit answer. Check whether this is optional, whether entries are de-identified, and whether you can opt out.
- How long is it kept? Look for retention periods, account-deletion steps and whether deletion removes journal content, backups and associated identifiers.
- Can you control it? Check settings for export, correction, deletion, marketing preferences and withdrawal of optional permissions.
Do not confuse a privacy policy with a clean bill of health. A detailed policy may disclose practices you do not want. Conversely, a vague or hard-to-find policy is a warning sign because you cannot make an informed choice. If the app will be offered through work, keep employer access separate from personal wellbeing information. Aggregate, genuinely anonymous uptake figures may be enough for a benefits review; a small business rarely needs individuals’ mood scores, journal content or session history.
Check 5: If it makes medical claims, check regulation and the safety route
Look for evidence of proper medical-device status, not just reassurance badges
Where a digital mental health product claims to diagnose, treat or manage a mental health condition, it may be regulated as a medical device. The MHRA says such products must meet relevant safety standards and display a CE or UKCA mark; the agency also advises users to check whether the product is registered. This is a meaningful extra check, but it is not a reason to stop asking questions about evidence, suitability or privacy.
Use the MHRA’s Public Access Registration Database to search for a medical device name or manufacturer. Search the legal manufacturer rather than only the consumer-facing brand, and ask the supplier for the exact name if you cannot find it. Importantly, the database itself says that registration does not equal MHRA accreditation, certification, approval or endorsement. It is one reassurance signal, not a blanket guarantee.
Also be precise about what is regulated. A company may have a regulated product, but the particular AI feature you plan to use may be a later addition or may fall outside the stated medical purpose. Compare the claimed feature with the product’s published intended use. If a sales page says “medical-grade AI therapy” but the supplier cannot explain its device status, intended purpose and evidence, do not fill the gaps with optimistic assumptions.
For general wellbeing tools that are not medical devices, regulation may not apply in the same way. That does not automatically make them unsafe. It does mean you should lean harder on the other four checks: modest claims, a suitable audience, credible evidence, transparent data handling and clear routes to human support.
Know when to step away from the app
Stop using a tool and seek advice if it leaves you more distressed, pressured, confused or isolated; if an AI response seems inappropriate; if it discourages you from speaking to a professional; or if it gives urgent-sounding health advice without a safe escalation route. Keep a record or screenshot of concerning interactions, particularly where an app made a medical claim or appeared to cause harm.
Concerns about a regulated medical device can be reported through the MHRA Yellow Card scheme. The MHRA encourages users to report concerns so potential problems can be identified and acted on. For urgent mental health help in England, use NHS urgent mental health support: call 111 and select the mental health option, or call 999 or go to A&E if someone’s life is at risk or they cannot keep themselves or someone else safe.
A five-minute founder checklist before you press download
Use this final pass for any AI meditation, mood-tracking or wellbeing app. If several answers are unclear, choose a simpler alternative or wait until the supplier answers them in writing.
- Claim: Is this general wellbeing support, or does it diagnose, treat or manage a condition?
- User: Is it designed and tested for someone like me or the employees I am considering it for, with clear limitations?
- Evidence: Can the developer show credible, product-specific support for the benefit it claims?
- Data: Do I understand what it collects, who receives it, whether AI uses it for training, how long it is retained and how I delete it?
- Safety: If it makes medical claims, can I verify its device information and does it offer a clear route to human help and problem reporting?
Choose support, not false certainty
AI meditation and mood-tracking apps can be helpful tools for building a pause into an overfull day. The best products are candid about that role: they explain what they do, who they are for, what supports their claims, how they protect sensitive information and where their limits lie.
For small business owners, the commercially sensible approach is also the human one. Do not buy confidence through branding alone. Ask for evidence, protect personal data, avoid turning workplace wellbeing into employee surveillance and give people a clear message that an app is optional support, not therapy or diagnosis. Before the next download, run the five checks. If the answers do not stand up, your best decision may be to close the app-store page and choose a more transparent route to support.





















