Your messages are personal.
Here is exactly what happens to them.
Effective: [EFFECTIVE DATE] · Controller: [LEGAL ENTITY NAME] · Contact: [CONTACT EMAIL]
What we collect
When you upload or paste a conversation, we receive its message text, dates, and participant labels. The conversation includes another person’s messages. We compute derived metrics and patterns from that content, such as message rhythm, response timing, language markers, and changes between time periods.
If Supabase authentication is configured and you create an account, Supabase stores your email and account identifier. If you buy a one-time report unlock, Stripe processes the payment and the app may keep a report-unlock record tied to your account. Stripe handles your card details. The app never sees or stores your full card number or security code.
How analysis works
The core analysis is deterministic. It runs on the app’s server without sending message content to a third-party model. It identifies measurable communication patterns. It does not predict a breakup or infer anyone’s intentions.
If the optional OpenAI narrative feature is enabled, OpenAI receives aggregate metrics only. It never receives raw messages. The request uses store:false. Conversation data is never used to train models.
Where data lives and how long we keep it
In demo mode, the derived report and import name live only in your browser session. A local report normally disappears when the browser session ends, or sooner if you delete it. A local report unlock may remain in this browser until you use “Delete all my data.”
Raw conversation content is held in the upload screen and sent to the analysis endpoint for processing. The current app does not write raw imports to its database. The server processes them in memory and discards them after the analysis request. This is the default raw-import deletion behavior.
When Supabase is configured, account email, profile data, derived analysis records if saving is enabled, and report-unlock records may remain until you delete all your data. Stripe keeps its own payment and transaction records under Stripe’s retention obligations and policies.
Why we use the data
We use conversation content only to produce the analysis you request. We use derived metrics to display your report. We use account data to authenticate you and associate saved records with you. We use payment records to unlock a purchased report, prevent duplicate charges, and handle payment support.
Subprocessors
- Vercel hosts and delivers the web app.
- Supabase provides database and email authentication when configured.
- Stripe processes payments and keeps payment records.
- OpenAI receives aggregate metrics only when the optional narrative feature is enabled. It does not receive raw messages.
Your rights and choices
You can delete the current browser report or delete all app data tied to you. Open Account & privacy and use “Delete this analysis” or “Delete all my data.” In demo mode, the second control clears browser data because no server data exists. When Supabase is configured and you are signed in, it also deletes your report unlocks, analysis records, conversation records, profile, and auth account.
To ask for access, correction, deletion help, or a copy of account data, email [CONTACT EMAIL]. We may need to verify that the account is yours.
Third-party messages
Uploads contain another person’s communications. You promise that you are a participant in the conversation or have permission to use it. Do not upload communications obtained unlawfully. Do not use this service to surveil another person.
Security
The production site uses HTTPS in transit. Supabase tables use row-level security policies that limit signed-in users to their own rows. Sensitive Supabase and Stripe keys stay on the server. Stripe webhook signatures are verified before an unlock is recorded. Raw messages are not sent to OpenAI. The app also limits accepted import types and size in the upload interface.
No service can promise perfect security. We do not claim independent security certification, end-to-end encryption, or security controls that are not implemented.
Age and geography
You must be at least 18 years old. The service is currently offered only in the United States. It is not offered to residents of the European Union or United Kingdom.
Changes
We may update this policy when the product or its data practices change. We will update [EFFECTIVE DATE] before the revised policy takes effect.