The logic is straightforward. Digital abuse happens on phones. Messages arrive on phones. Screenshots are taken on phones. So the tool that analyses those messages should live on the phone too.
Several AI tools for detecting manipulation and documenting coercive behaviour have now launched as mobile apps, and that logic is sound as far as it goes. The problem is where it stops.
For a significant proportion of the people these tools are designed to help, the phone is not a neutral device. It is a site of monitoring and control. And a detection app on a monitored phone is not simply a resource. It is a piece of information about what the person was questioning.
What coercive control does to device access
One of the documented tactics of coercive control is the gradual erosion of privacy. It rarely begins with an explicit demand. It begins with a partner who checks your phone casually, who asks who you were texting, who frames access to your device as a sign of trust or the absence of it as evidence of something to hide.
Over time, in many coercive relationships, the phone becomes a shared object in practice even if not in name. Account credentials are known. Location sharing is enabled. Notifications are visible. The expectation of access is established, and the cost of resisting it has been made clear.
In this context, a detection app on the device is not simply a tool. It is a record. The app icon. The history of what was submitted for analysis. The results stored within it. The browser searches made whilst using it. If the results are synced to a cloud account whose credentials are shared or guessed, the evidence extends further still.
The person who downloaded the app to understand what is happening to them may have inadvertently created the most dangerous document in the relationship.
The conversation practitioners are not yet having
Most tool recommendations in the coaching and therapeutic space focus on capability: does this tool accurately detect what it claims to detect? That is a necessary question, and as I have written elsewhere, it deserves considerably more scrutiny than the headline accuracy figures suggest.
But capability is not the only question, and in this context it may not even be the first one.
Before recommending any digital tool to a client navigating a coercive relationship, a practitioner needs to understand the device context that client is operating in. That means asking, not assuming.
Does the client have private access to their phone? Is there an expectation of device access in the relationship? Are account credentials shared? Is location sharing enabled? Does the client have a second device, or access to a device that is genuinely theirs alone?
These questions are not a checklist to run through mechanically. They are the basis of a clinical judgement about whether a digital tool is appropriate for this client in this situation, or whether using it creates a risk that outweighs the benefit.
Some tools have been designed with these considerations in mind. They include disguise modes that make the app appear to be something else, local-only storage that does not sync to a cloud account, and explicit safety guidance for users in monitored device situations. Others are consumer wellness products that were built for the general relationship market, where device monitoring is not assumed, and where the safety calculus is entirely different.
The practitioner recommending a tool has a responsibility to know which kind of tool they are recommending, and to have the clinical conversation that determines whether using it is safe.
What safe tool use actually looks like
For a client in a monitored device situation, the safest approach to AI detection tools may not involve their primary phone at all. A public library computer. A friend’s device. A new account on a device the relationship has no access to. These are not elegant solutions, but elegance is not the priority.
The priority is that the process of seeking clarity does not create new exposure.
This is one of the reasons Validate AI was built with EU hosting, GDPR compliance by default, and deliberate decisions about what data is retained and where. In a forensic context, the infrastructure is not a technical detail. It is a safety consideration. The person submitting the most sensitive communication of their life deserves to know where it goes and who can access it.
Practitioners working in this space are increasingly expected to be fluent not just in the clinical frameworks for coercive control, but in the digital landscape their clients are navigating. The phone is no longer just where the messages are. It is where the evidence is, and sometimes where the risk is too.
Understanding the difference is now part of the work.



