Privacy Policy
Effective September 4, 2026
What we collect
We collect the account information you provide, including your name, email address, birthday, gender selection, and whether you have previously used a counselor. We use the demographic answers for eligibility and aggregate product research; they are not included in prompts sent to the coaching AI. Passwords are stored only as secure hashes. The service stores your private reflection messages, the shared topics and agreements you explicitly approve, account and device session information, subscription status, support requests you submit, and limited product-usage and reliability records. A signed-in support request is linked to an account snapshot such as subscription status, app version, device model, recent activity counts, and an approximate market you previously chose to share. Conversations and saved private themes are not attached to support requests. Product records may include a broad age band and your onboarding demographic selections, your selected onboarding intention, how you say you found the app, whether your first Guide reply felt helpful, an optional return check-in, measured foreground-session duration, messages sent, voice-entry use, invitation and share actions, accepted invitations, shared-room participation, and agreement responses. These activation records do not include what you wrote about. If you separately opt in, the app may also store your country and broad region for aggregate market research. Network addresses from consumer requests are used transiently for abuse prevention and converted to a keyed one-way rate-limit value rather than retained as a raw address in the consumer account record. For the separate, protected administrator console, the source address and a sanitized request identifier are retained with administrator audit actions for security and accountability.
How coaching content and voice are used
Private coaching is kept separate from your partner’s account. Content enters a shared room only after you review and approve the proposed wording. When you consent to AI coaching, the conversation context needed to answer you is sent securely to OpenAI to generate a response. Provider-side storage is disabled in our API requests. Voice entry uses the speech-recognition service supplied by your phone, preferring on-device recognition when available; the resulting transcript is handled like a typed message. Spoken replies use your phone’s text-to-speech service. Relationship Coach does not upload or retain the microphone audio. If you separately turn on private pattern suggestions, we may save brief, tentative themes derived from your private conversations so your private coach can suggest something useful to revisit. Those patterns are not shown to a partner, placed in a shared room, or made available in ordinary administrator views. We do not use your coaching content for advertising or sell it.
Invitations and optional location insights
The app uses your phone’s native sharing screen when you choose to send an invitation. Your operating system may suggest people or apps locally, but Relationship Coach does not request, read, upload, or store your address book. Location insights are optional and off by default. If you enable them, the phone uses location only long enough to derive a country and state or broad region; precise coordinates are discarded on the device and are never sent to or stored by Relationship Coach. We use the resulting broad location for aggregate product research, market prioritization, and marketing campaign planning—not to personalize coaching or target advertising to an individual.
Safety review
Automated guardrails stop ordinary mediation when content indicates immediate danger or a direct threat. Only threat-level messages are copied into a restricted safety-review record containing the exact triggering text and the account identity available when it was detected. Authorized administrators may annotate and export that record, with access and exports recorded in an audit log. Automated flags are not verified threat assessments and are reviewed under applicable law and policy.
Service providers
We use service providers to host the application and database, generate AI coaching responses when you consent, process subscriptions through Apple or Google, and operate security and reliability functions. They may process only the information needed to provide those services and are required to protect it.
Retention and deletion
You can request account deletion in Settings or through our web deletion page. The request immediately revokes sessions and disconnects any linked relationship, closing shared rooms and current agreements while notifying the former partner without message content. Private coaching data is deleted or anonymized by the background deletion process. Contributions already placed in a two-person shared room may remain in deidentified form so the other person retains their independent record. Support requests may be retained as reasonably needed to resolve the request, document the service provided, prevent abuse, and meet legal obligations. We may retain billing, security, audit, or threat-review records when reasonably necessary for legal, fraud-prevention, or safety obligations.
Your choices
You can decline AI processing, turn private pattern suggestions on or off, dismiss or forget an individual saved pattern, keep coaching content private, choose whether a neutral summary enters the shared room, turn broad location insights on or off, reset your password, sign out devices, restore or cancel a store subscription, and delete your account. Turning location insights off deletes the stored country and broad region. Turning pattern suggestions off deletes the saved derived patterns. The service does not track you across other companies’ apps or websites.
Security and contact
We use encryption in transit, encrypted mobile credential and unsent-draft storage, hashed passwords and refresh tokens, keyed one-way network rate-limit values, role-restricted administration, and request-attributed access to threat records. Conversation records are stored in the service database and are not end-to-end encrypted. They are not exposed in ordinary administrator screens, but authorized infrastructure operators may technically access stored records when required to operate, investigate, or secure the service, and restricted safety reviewers may access threat-level records as described above. No system is perfectly secure. For privacy questions or requests, contact tom.mcirish@gmail.com.
Private goals and check-ins
When you choose to track a private theme, we store the goal wording, the improvement measure you enter, the check-in rhythm you select, and the dates of scheduled and completed check-ins. These records stay in your private space and are deleted when you forget the source theme or turn off saved theme suggestions.