The Business Model at the Bottom of the Fear
Safety apps are designed to make people feel safer—but what happens when anxiety becomes part of the business model? Explore dark patterns, subscriptions and the incentives shaping digital safety products.

Let's get the awkward part out of the way first. We build a safety app, and this article is about how safety apps make money by making you anxious. You should read the rest of it with that firmly in mind, and you should hold us to everything in it.
We're writing it anyway, because in 2023 a team of researchers did something nobody in this industry had properly done before. They took a popular safety app, interviewed its users, pulled apart its interface, and published what they found in a peer-reviewed venue. The conclusion was not subtle. The app increased people's anxiety about their safety while steering them towards paid features that promised to relieve it.
That's a specific, evidenced, documented finding about a real product. And the mechanism they describe isn't unique to one app. It's what happens by default when the thing you sell is peace of mind, so it's worth understanding whichever safety tool you end up using, including ours.
Key Takeaways
- The study: Researchers interviewed 15 users of the Citizen app in Atlanta and analysed its interface, published at CHI 2023.
- The core finding: Citizen "heightens users' anxiety about safety while encouraging the use of profit-generating features which offer security".
- A documented tactic: The premium Citizen Protect feature was advertised with a hidden "Skip" button, a deceptive pattern the researchers classify as obstruction.
- Two new harms named: The team argued the field needs to recognise "emotional load" and "social injustice" as categories of design harm.
- No villain required: When revenue depends on subscriptions and the product is safety, the incentives point one way on their own.
- Now a UK regulatory issue: Online choice architecture is one of the CMA's three named consumer enforcement priorities.
- Real penalties: Under the Digital Markets, Competition and Consumers Act 2024, the CMA can fine up to 10% of global turnover directly.
What the Researchers Actually Did
A bit of background first, because Citizen isn't well known in the UK.
Citizen is a US app that sends people alerts about safety incidents near them, largely drawn from emergency service radio, along with live video from users at the scene. It operates in a number of American cities and has been controversial for years. Until this study, though, most of the criticism was journalistic rather than empirical.
The research team, led by Ishita Chordia with colleagues from the University of Washington and elsewhere, took a different approach. They bounded their study to Atlanta, a racially diverse mid-sized American city, and interviewed fifteen Citizen users who lived there. Then they triangulated what those users told them against a systematic analysis of the app's own interface, looking specifically for deceptive design patterns.
That combination is what gives the work its weight. Interviews alone tell you how people feel. Interface analysis alone tells you what a designer built. Putting them together lets you connect a documented design choice to a documented effect on a real person.
The Finding, In One Sentence
Here's how the researchers summarised what they found:
"Citizen heightens users' anxiety about safety while encouraging the use of profit-generating features which offer security."
Read that as a sequence rather than a description, because that's what makes it damning. The anxiety comes first. The offer of relief comes second. And the relief costs money.
It's worth being precise about what is and isn't being claimed. The researchers are not saying anyone sat in a meeting and decided to frighten people for profit. They're describing an observed pattern in a shipped product, in which the emotional state the app produces and the commercial offer it makes are pointing in complementary directions.
That's a harder problem than malice, because malice can be fired and incentives can't.
The Specific Trick They Documented
The paper gives a concrete example, and it's a useful one because it's so ordinary.
Citizen's premium tier, Citizen Protect, was advertised inside the app with a hidden "Skip" button, which made the advertisement difficult to get past. In the taxonomy of deceptive design, that pattern has a name: obstruction. You aren't prevented from declining. You're just made to work for it, and the friction is doing the persuading.
Obstruction is everywhere once you know the word for it. The greyed-out decline button next to a bright accept button. The cancellation flow that runs four screens deep. The cookie banner where "Accept All" is one tap and "Reject All" is three.
What makes it worse in a safety product is the context it arrives in. Friction is annoying when you're buying trainers. When you've just been told something happened near your home and you're being asked to pay for protection, that same friction is landing on someone whose judgement is already compromised by alarm. The researchers' point is that the design and the emotional state have to be assessed together.
Nobody Has to Be a Villain

This is the part we'd most like people to take away, because it's the part that generalises.
Picture the incentives honestly. A safety app makes money from subscriptions. Subscriptions convert best when the user feels at risk. Engagement, the number everyone reports to investors, also rises when the user feels at risk. Meanwhile the app's cost of sending an alert is close to zero, and there's no penalty anywhere in the system for sending one that turns out not to matter.
Now imagine a competent team doing nothing more sinister than A/B testing. They test two notification wordings and keep the one with the better open rate. They test two upsell screens and keep the one that converts. They do this a hundred times over two years, with no bad intentions at any point.
Where does that product end up?
It ends up frightening. Not because anyone chose it, but because every local optimisation pointed the same way, and nothing in the feedback loop was measuring whether users ended up calmer or more anxious. The research on this, as we've written elsewhere, is consistent: negative and threatening content reliably outperforms on every engagement metric anyone bothers to track.
The incentive gradient does the work. That's why the answer has to be structural rather than a matter of good intentions.
Two Harms the Field Didn't Have Words For
The most useful contribution of the paper isn't the criticism of one app. It's a suggestion about vocabulary.
Existing taxonomies of design harm mostly cover financial loss, privacy invasion and wasted time. Those are the harms that are easy to count. The researchers argued that safety technologies produce two more that the field hasn't been naming properly, and proposed adding them.
Emotional load. The cumulative cost of being made anxious, repeatedly, by a product you installed in order to feel safer. It doesn't show up in a refund, a data breach or a churn number. It shows up in how you feel walking home.
Social injustice. The uneven distribution of that harm. A stream of "suspicious person" alerts doesn't land equally on every neighbourhood or every reader, and in a racially diverse city it can reinforce exactly the assumptions a safety product should be careful about.
We'd argue both belong in the design review of any product in this category, including the ones we run internally. If your review process can only catch harms that have a monetary value, it will pass a product that makes people frightened for a living.
In the UK, This Isn't Just Distasteful Any More
Everything above is American, and a British reader could reasonably file it under interesting-but-elsewhere. That would be a mistake, because the regulatory position here has changed recently and significantly.
The Competition and Markets Authority published a report in 2024 on online choice architecture, which is the umbrella term for how design shapes user decisions. Deceptive patterns are a subset of it. More importantly, online choice architecture is now one of the CMA's three named consumer enforcement priorities, alongside drip pricing and fake reviews.
Then the powers changed. Under the Digital Markets, Competition and Consumers Act 2024, with the direct enforcement regime live from April 2025, the CMA can now decide that consumer law has been broken and impose penalties itself, without first going to court. The maximum is 10% of global turnover. Subscription traps, where signing up is easy and cancelling isn't, and manufactured urgency, such as countdown timers or scarcity claims that aren't grounded in reality, are both explicitly in scope.
So a UK safety app that alarms people into a paid tier and then makes cancelling difficult isn't just doing something we'd disapprove of. It's operating inside a regulator's stated priority area, with a penalty regime that has real teeth.
How to Spot It in Any Safety App
Here's the practical part. You don't need a research team to run these checks on anything you've installed, and they take about ten minutes.
Start with the notifications. Look at the last ten you received and ask what each one actually asked you to do. If the answer for most of them is "open the app and feel worried", rather than "here's something you can act on", that's your first signal. Then check whether the app has ever told you that a period was quiet. A tool that only ever speaks when something is wrong is giving you a systematically distorted picture, however accurate each individual alert is.
Next, look at the paywall. The question isn't whether there's a paid tier, which is fine and normal. It's what sits behind it. If information relevant to your physical safety is the thing being withheld until you pay, the product has aligned its revenue against your wellbeing, and everything downstream of that gets harder to trust.
Then try to leave. Not permanently, just find the cancellation route and count the taps. Compare that to how many taps it took to subscribe. A large gap is the clearest single indicator of intent in the entire product.
Finally, watch for urgency you can't verify. Countdown timers, "X people near you", limited-time framing on a safety feature. If a claim is designed to make you act now and you can't check it, treat it as marketing rather than information.
The Fair Challenge to Us
We opened by saying you should hold us to this, so let's be specific about what that means.
Everything above describes a set of temptations we are exposed to just as much as anyone else. We will have a paid tier eventually. We send notifications. We watch engagement numbers. The honest position isn't that we're immune, it's that we've tried to close off the specific routes in advance, while it's still cheap to do so.
That means safety information never sits behind a payment. It means quiet weeks get reported as quiet weeks, even though that is measurably worse for engagement. It means cancelling happens in one tap on the screen where you subscribed. And it means no countdown timers, no manufactured scarcity, and no notification whose job is to worry you rather than to tell you something you can use.
We've written those commitments out properly in a separate piece, with dates, so they can be checked rather than just admired. If we break one, the right response is to point at it.
Your Questions, Answered
Is this just an attack on a competitor?
Citizen doesn't operate in the UK and isn't a competitor of ours. We're writing about it because it's the only product in this category that's been studied properly and published in a peer-reviewed venue. The pattern matters more than the company.
Are all safety apps like this?
No, and the paper doesn't claim that. It's a case study of one app in one city. What generalises isn't the verdict, it's the incentive structure, which every subscription-funded safety product shares.
Isn't some fear useful? I want to know if something happened.
Absolutely, and that's the distinction worth holding onto. There's a difference between information that helps you decide something and alarm that just raises your baseline. The test is whether an alert gives you an action. "A burglary was reported on your street last night" is useful. A constant drip of ambient threat with nothing to do about it is not.
How would I know if Glome starts doing this?
Run the four checks above on us. The cancellation-taps one is the hardest to fake.
What to Take From This
The uncomfortable truth in this research isn't that one company behaved badly. It's that the default settings of this entire product category point somewhere none of us should want to go, and that avoiding it takes deliberate decisions made early, against your own short-term interest.
We think the useful response is to be specific in public about which decisions those are, before there's any commercial pressure to reconsider them. That's harder to walk back than a value statement, which is rather the point.
And if you're evaluating any safety tool, ours included, the single most revealing question is still the simplest one. What does this product need me to feel in order to make money?
If you'd like to read the research yourself, the paper is open on the ACM Digital Library and the full citation is below. We'd encourage it. It's better than our summary of it.
References
1: Chordia, I., Tran, L.-P., Tayebi, T.J., Parrish, E., Erete, S., Yip, J. and Hiniker, A. (2023) 'Deceptive Design Patterns in Safety Technologies: A Case Study of the Citizen App', Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems, Hamburg, Germany, 23 to 28 April 2023. Fifteen interviews with Citizen users in Atlanta, triangulated with an analysis of the user interface. https://doi.org/10.1145/3544548.3581258
2: Competition and Markets Authority (2024) Online Choice Architecture: how digital design can harm competition and consumers, and the direct consumer enforcement regime under the Digital Markets, Competition and Consumers Act 2024, in force from April 2025, with penalties of up to 10% of global turnover. https://competitionandmarkets.blog.gov.uk/2026/04/17/direct-consumer-enforcement-one-year-on/
