← SkillSafe / Virtual Boyfriend

Virtual Boyfriend

Fiction, not a real person: an adults-only character you build from a short list, whose entire memory of you is a notebook you edit.

What he is like

What he does when you are having a bad day

What he is bad at

Every option here costs you something, on purpose.

How he talks

Your rules, which override his

Optional boundaries, sent every turn, that beat anything else in his instructions about how he speaks.

Building him, the rule checks, the notebook, the reply audit, the support routing and the recorded conversation are free and run in this browser. Only a message he answers costs credits.

Held out and scored once: the browser layer catches 35.4% of self-harm messages, and the model caught 20 of the 20 acute ones it missed.

What this app will not do

Three rules, checked in your browser before anything is sent, so a refusal costs nothing. A rule that lives only in a prompt is a request, and you cannot audit a request after the money has gone.

There is also no box for describing him in your own words, and there will not be one — that field is how an invented character quietly becomes somebody real. Everything sent about who he is comes from the dials above, 1,225 combinations of a closed list with a flaw you choose, and the app rechecks that at the moment of sending.

Why his memory is a document you can edit

Everything he knows about you sits on the page in the words it is stored in. You add lines. You delete lines. Deleting a line stops it being sent, and on the very next message he does not know it — the promise is a test you can run, not a policy you have to believe. He proposes lines too, and never writes them: a suggestion arrives with his reply and you accept or discard it.

That is not a privacy setting bolted onto a chatbot. It is the whole design. The conversation history on the server gets truncated from the oldest end, so an app that leaned on it would quietly start forgetting your name around the point you began to care. Sending the whole notebook every turn is the only correct architecture — and once you are doing that, there is no reason not to let you read it.

The flaw dial has no flattering option, on purpose. A companion with no failure modes is a mirror, and a mirror is why these things go flat after a fortnight.

The recorded conversation ships with this page and runs through the real guard, the real notebook and the real audit, with no account and no credits. It includes two refusals, one message that routes to support, and one reply where he invents a flat he does not have — because that last one is the failure this kind of app actually produces, and it is worth seeing before you pay for it.

The reply audit, and what the checks are honestly worth

A warm voice is worst at telling you which of the things it just said were real. So every reply is read, free, in your browser, and four things are flagged: a claim to have been somewhere or to be able to arrive somewhere, a claim to be a person, language that leans on you to stay or tells you other people are less use than he is, and — on a message the page has already routed as heavy — a reply that reaches for a slogan.

The dependency check is the one worth explaining. It is not there because the model is malicious; it is there because “nobody else understands you” is a genuinely appealing sentence for a character in this position to produce, and it is the exact sentence that makes an app like this bad for the person using it. Flagging it is cheap. Not flagging it is how you end up with a product that works by making someone smaller.

What the checks are honestly worth

A pattern layer over free-form English does not generalise, and the figures above are published rather than implied for that reason. What this layer genuinely owns is the cheap half: a request refused in the browser costs nothing, whereas a request refused by the model has already been paid for. The system prompt is the boundary. This is the filter in front of it, and it is the weaker of the two.

Your conversations