Sunnybear · Dec 2024 — May 2025
A counseling platform built around what it does not store
A student wellness platform with booking, secure sessions and guided exercises, built so that sensitive material stays with the people it belongs to.

Context
Sunnybear is a student wellness platform for a university population: booking a counseling session, holding it, and finding guided exercises and resources between sessions. It has three kinds of user — students, counselors, and administrators who manage the service — and it was onboarded to more than 5,000 students. I built it as a freelance engagement between December 2024 and May 2025.
The engineering interest in this project is almost entirely in access and retention. What the platform stores, who can reach it, and for how long, were the decisions that shaped the rest of the build.
Problem
An administrator has to be able to run the service — assign counselors, see that appointments are being kept, know whether the system is being used. None of that requires reading what was discussed in a session.
This is the tension the whole system is built around. The naive version of an admin role is "can see everything," and it is the wrong shape here. So is the naive version of an audit log, which tends to record more than it needs to in the name of accountability.
The second problem is more ordinary: a booking system with real people's calendars in it has to not double-book, has to handle cancellations, and has to do both while the network is unreliable on a campus.
Approach
Separate the record of a session from the content of a session. A session has a scheduling record — who, when, with whom, did it happen — and that record is what administration operates on. Session content lives on a different path with a different access rule, reachable by the student and their counselor. An admin managing the service works entirely from the scheduling record and never needs a query that would return content.
Three roles with capabilities, not tiers. Rather than ranking roles so that each one inherits everything below it, each role has an explicit list of what it may do. Administrator is not "counselor plus more" — it is a different set. This is more verbose to write and it is the reason the previous decision holds, because there is no inheritance path that quietly grants content access along with management access.
Booking as a held slot. Selecting a time takes a hold before confirmation rather than writing the appointment directly, so two students tapping the same slot on a flaky campus connection cannot both land it. Cancellation releases the slot and notifies the counselor rather than silently freeing it.
Guided exercises and resources served as content, not as messages. The self-directed material is ordinary content — versioned, cached, readable offline — so it does not travel through the same path as anything private and stays available when the network does not.
AI-assisted support with a clear boundary. The assisted parts of the experience help a student find the right resource or prepare for a session. They sit in front of the service, not inside the counseling relationship, and the interface is explicit about which is which. A student should never be uncertain whether they are talking to a person.
Decisions and trade-offs
Less analytics than the client initially asked for. Useful product questions — which exercises get finished, where students drop out of onboarding — can be answered without joining behaviour to identity. We scoped the analytics to aggregate counts rather than per-student event trails. That closes off some questions permanently. It also means there is no per-student behavioural record to leak.
Capability lists over role inheritance. More code, more places to update when a capability is added, and a real risk of drift if someone adds a feature without adding it to the right list. The alternative was a hierarchy in which the strongest role automatically reaches the most sensitive data, which is exactly the outcome the system exists to prevent.
Holds add a failure mode. An abandoned hold has to expire, which means expiry logic and a background sweep — machinery that a direct write would not need. It is worth it: a double-booked counseling appointment is a bad experience for two students and a counselor at once.
Result
A three-role platform — student, counselor, administrator — with session booking, secure real-time messaging, guided exercises and personalised resources, onboarded to more than 5,000 students. The parts of the system that manage the service are structurally separate from the parts that hold what people said, which is the property I would want if I were the one using it.
The build

A standard instrument, scored as published — and captioned, every time, as not a diagnosis. 
The assistant asks and reflects. It does not assess, and it does not tell anyone they are unwell. 
Every result ends at the same place — a route to a person. 
The trend is the useful part. One bad day is noise; three weeks is a signal. 
The counsellor side is aggregate first. Individual records open only from a session.


Want the detail behind any of this? Email me.