Privacy Policy
Third Eye analyzes a WhatsApp chat export and turns it into relationship insights. This policy explains exactly what happens to your data. The one-line summary: your participants' names never leave your device in identifiable form, we store no chat content anywhere, and your results live only on your phone.
01What the app does
You choose a chat and export it using your messaging app's own export feature (WhatsApp's "Export chat", or LINE's "Export chat history"). Third Eye reads that export on your device and produces insights about the conversation — for example, who tends to start conversations, reply times, patterns of unanswered messages, and how the tone changes over time. Each analysis is called a "run." Runs are generated on demand and shown to you.
02How your data flows
- On your device — anonymization. Before any part of your chat is transmitted, Third Eye replaces participant names with neutral placeholders (P1, P2, and so on) locally on your phone. The text sent for analysis does not contain your real names.
- Our relay — no storage. The anonymized text is sent to a small relay we operate (Google Cloud Functions). The relay checks that the request comes from a genuine copy of the app and that a run is authorized, then forwards the text unchanged to the AI provider. It does not log or store your chat content, and we keep no database of chats or reads. The integrity check and the app's remote settings are provided by Google Firebase (App Check, Remote Config), which receives a Firebase installation identifier and basic technical data about the request — no chat content and no reads.
- At the provider — transient AI processing. The anonymized text is processed by the AI provider purely to generate your insights. It is not used by us to build a profile of you.
- Results stay on your device. The insights returned to the app are written to local storage on your phone only. They are not uploaded, backed up to our systems, or shared.
- What we do keep on our servers: a counter. To enforce how many runs your plan includes and how many credits you have left, we store a small ledger — your remaining allowance and credit balances — against the anonymous app user ID described in section 05. It holds no chat content, no results, no name, and no email.
03AI providers & retention
To generate insights, the anonymized text is relayed unchanged to one or more third-party AI providers:
- Google (Gemini API) — handling of data sent to the API is governed by Google's terms and privacy policy: Gemini API Additional Terms and Google Privacy Policy.
- DeepSeek — handling of data sent to its API is governed by DeepSeek's policy: DeepSeek Privacy Policy.
Because the text we transmit is anonymized on-device first, what reaches these providers is stripped of your participants' real names. Any retention or logging of API requests by these providers is governed by their policies, linked above, not by us.
04Analytics & attribution
Third Eye uses Amplitude (Amplitude, Inc.) to understand how the app is used so we can improve it. This collects:
- App-interaction events — for example, that a screen was opened or a run was started, with run metadata only (never the content of your chats, and never your participants' names).
- Device and app identifiers — an anonymous installation identifier and basic device/OS information.
We configure Amplitude not to store your IP address, so no IP-derived location is kept, and we do not collect precise GPS location. Amplitude analytics is not linked to a real-world identity — we have none to link it to — and it is not used for advertising. Amplitude's processing is described in its Privacy Policy.
Why the App Store label mentions location. Our privacy label lists Coarse Location under Analytics, and that can look like a contradiction, so here is the whole of it: Third Eye never asks for location permission, so iOS cannot grant it one, and we request no GPS position. The category is declared because the analytics and notification kits built into the app state in their own Apple privacy manifests that they are able to derive an approximate location. We would rather declare a category we may not use than under-declare one we do.
Install attribution, and the ad identifier. To learn which ad or link brought someone to Third Eye, we use AppsFlyer. This works in two layers, and they are not the same thing:
- Apple's SKAdNetwork. Aggregate, privacy-preserving install reporting built into iOS. It identifies no individual and needs no permission from you.
- Your device's advertising identifier (IDFA) — only if you allow it. On first launch iOS shows you the App Tracking Transparency prompt. If you allow tracking, AppsFlyer may use the IDFA to attribute your install to an ad campaign, and that identifier is shared with AppsFlyer as an advertising partner. Under Apple's definition this is tracking, which is why the app's App Store privacy label says Data Used to Track You.
Choosing Ask App Not to Track costs you nothing: no feature changes, and SKAdNetwork attribution is unaffected. You can change the answer any time in iOS Settings → Privacy & Security → Tracking. We never use the IDFA to read, analyze, or link anything about your chats. AppsFlyer's own processing is described in its Privacy Policy.
You can turn all of this off inside the app: You → Share usage analytics. The switch stops both Amplitude and AppsFlyer on your device. Once it is off, the attribution SDK does not start on later launches, so the tracking prompt is not shown again.
05Purchases
Subscriptions and credits are billed by Apple through your App Store account; we never see your payment details. To verify purchases and unlock what you bought we use RevenueCat, which processes your purchase and transaction history for the app together with an anonymous app user ID — never your name, email, or chat content. Apple's handling of purchase data is governed by Apple's Privacy Policy; RevenueCat's by its Privacy Policy.
About that anonymous app user ID. It is a random identifier created on your device the first time you open the app. It is not an account, you never choose it, and it is tied to no name, email or phone number. The same value is used as the user identifier in Amplitude, in our server-side allowance ledger, and for notification delivery, so that a purchase, a run and a push all line up as coming from one install. We also pass your AppsFlyer install identifier to RevenueCat so a purchase can be matched to the campaign that led to the install, and purchase events are forwarded from RevenueCat to Amplitude as revenue analytics.
06Notifications
If you allow notifications, Third Eye uses OneSignal to deliver them — for example, telling you a read is ready. OneSignal receives your push token, an identifier it assigns to the install, the anonymous app user ID from section 05, and two non-identifying tags: whether you have reminders on, and when your last analysis happened. It receives no chat content, no reads, and no name.
iOS asks your permission before any notification is sent, and you can withdraw it at any time in iOS Settings → Notifications → Third Eye. OneSignal's processing is described in its Privacy Policy.
07No accounts
Third Eye has no sign-up, no login, and no user accounts. We do not ask for your name, email, or phone number to use the app. (The one optional exception is the launch-notification email below — collected on this website, never required to use the app.)
08Launch-notification email
If — and only if — you submit the "Notify me at launch" form on our home page, we store the email address you type so we can send you one message: a single notification when Third Eye is available on the App Store.
- It lives in Cloudflare KV (our infrastructure) — never sold, never shared, and never used for anything but that one launch email.
- No tracking pixels, no marketing platform, no third-party list.
- Want it removed before then? Email [email protected] and it's deleted.
09Children
Third Eye is rated 16+ and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has used the app in a way that raises a concern, contact us and we will help.
10Your controls
Because your results live only on your device, you control them directly:
- Delete an individual run inside the app to remove that analysis and its results.
- Delete the app to remove all Third Eye data stored on your device.
We have no copy of your chats or results to delete on your behalf, because we never stored them.
11Changes to this policy
We may update this policy as the app evolves. When we do, we will revise the "Effective" date at the top of this page. Material changes will be reflected here before they take effect.
12Contact
Questions about privacy? Email [email protected] and we'll get back to you. Common questions — including how to delete a read and how purchases work — are answered on the Support page.