Privacy Policy
Third Eye analyzes a WhatsApp chat export and turns it into relationship insights. This policy explains exactly what happens to your data. The one-line summary: nothing is uploaded until you say yes, sender names are replaced with aliases on your device first, we store no chat content anywhere, and your results live only on your phone.
01What the app does
You choose a chat and export it using your messaging app's own export feature (WhatsApp's "Export chat", or LINE's "Export chat history"). Third Eye reads that export on your device and produces insights about the conversation — for example, who tends to start conversations, reply times, patterns of unanswered messages, and how the tone changes over time. Each analysis is called a "run." Runs are generated on demand and shown to you.
02Your permission
Nothing is uploaded until you allow it. Before Third Eye sends any chat text off your device for the first time, it shows you a disclosure screen whose button reads "Allow & Continue". That screen says, in these words:
- "Sender names are swapped for aliases on your phone before anything leaves it."
- "With your OK, the chat is uploaded to our server and read by Google's Gemini AI for one job: writing your read. It isn't stored after."
- "Your reads live only on your phone. Delete the app and they're gone."
The app checks for your permission immediately before every upload, on every route that can start one — including a chat you share straight into Third Eye from the iOS share sheet. Without a recorded permission, no chat data leaves your device.
You can withdraw it at any time in the app: You → "AI analysis consent". Once it is off, the next reading asks you again before anything is sent.
03How your data flows
- On your device — aliasing. Before any part of your chat is transmitted, Third Eye replaces each participant's sender name with a neutral placeholder (P1, P2, and so on) locally on your phone. The message text itself is sent as written — so if someone typed a name inside a message, that word is sent along with the rest of the sentence. We are explicit about this because the alternative would be an overstatement: we alias who said it, not every word said.
- Our relay — no storage. The text is sent to a small relay we operate (Google Cloud Functions). The relay checks that the request comes from a genuine copy of the app and that a run is authorized, then forwards the text unchanged to the AI provider. It does not log or store your chat content, and we keep no database of chats or reads. The integrity check and the app's remote settings are provided by Google Firebase (App Check, Remote Config), which receives a Firebase installation identifier and basic technical data about the request — no chat content and no reads.
- At the provider — transient AI processing. The text is processed to generate your insights and the result is returned. It is not used by us to build a profile of you.
- Results stay on your device. The insights returned to the app are written to local storage on your phone only. They are not uploaded, backed up to our systems, or shared.
- What we do keep on our servers: a counter. To enforce how many runs your plan includes and how many credits you have left, we store a small ledger — your remaining allowance and credit balances — against the anonymous app user ID described in section 06. It holds no chat content, no results, no name, and no email.
04The AI provider
Google's Gemini API, provided by Google LLC, is the only third-party AI service Third Eye sends chat text to. There is no second provider and no fallback.
- What it receives: the text of the chat export you chose to analyze, with sender names already replaced by aliases on your device.
- What for: generating your reading, and nothing else.
- Training: under the paid Gemini API terms, Google does not use content submitted through the paid API to improve or train its models. Google's handling is governed by the Gemini API Additional Terms and the Google Privacy Policy.
An earlier version of Third Eye could fall back to a second AI provider, DeepSeek. It was removed from the app and from our servers in August 2026 and receives nothing.
05Analytics & attribution
Third Eye uses Amplitude (Amplitude, Inc.) to understand how the app is used so we can improve it. This collects:
- App-interaction events — for example, that a screen was opened or a run was started, with run metadata only (never the content of your chats, and never your participants' names).
- Device and app identifiers — an anonymous installation identifier and basic device/OS information.
We configure Amplitude not to store your IP address, so no IP-derived location is kept, and we do not collect precise GPS location. Amplitude analytics is not linked to a real-world identity — we have none to link it to — and it is not used for advertising. Amplitude's processing is described in its Privacy Policy.
Why the App Store label mentions location. Our privacy label lists Coarse Location under Analytics, and that can look like a contradiction, so here is the whole of it: Third Eye never asks for location permission, so iOS cannot grant it one, and we request no GPS position. The category is declared because the analytics and notification kits built into the app state in their own Apple privacy manifests that they are able to derive an approximate location. We would rather declare a category we may not use than under-declare one we do.
Install attribution, and the ad identifier. To learn which ad or link brought someone to Third Eye, we use AppsFlyer. This works in two layers, and they are not the same thing:
- Apple's SKAdNetwork. Aggregate, privacy-preserving install reporting built into iOS. It identifies no individual and needs no permission from you.
- Your device's advertising identifier (IDFA) — only if you allow it. On first launch iOS shows you the App Tracking Transparency prompt. If you allow tracking, AppsFlyer may use the IDFA to attribute your install to an ad campaign, and that identifier is shared with AppsFlyer as an advertising partner. Under Apple's definition this is tracking, which is why the app's App Store privacy label says Data Used to Track You.
Choosing Ask App Not to Track costs you nothing: no feature changes, and SKAdNetwork attribution is unaffected. You can change the answer any time in iOS Settings → Privacy & Security → Tracking. We never use the IDFA to read, analyze, or link anything about your chats. AppsFlyer's own processing is described in its Privacy Policy.
You can turn all of this off inside the app: You → Share usage analytics. The switch stops both Amplitude and AppsFlyer on your device. Once it is off, the attribution SDK does not start on later launches, so the tracking prompt is not shown again.
06Purchases
Subscriptions and credits are billed by Apple through your App Store account; we never see your payment details. To verify purchases and unlock what you bought we use RevenueCat, which processes your purchase and transaction history for the app together with an anonymous app user ID — never your name, email, or chat content. Apple's handling of purchase data is governed by Apple's Privacy Policy; RevenueCat's by its Privacy Policy.
About that anonymous app user ID. It is a random identifier created on your device the first time you open the app. It is not an account, you never choose it, and it is tied to no name, email or phone number. The same value is used as the user identifier in Amplitude, in our server-side allowance ledger, and for notification delivery, so that a purchase, a run and a push all line up as coming from one install. We also pass your AppsFlyer install identifier to RevenueCat so a purchase can be matched to the campaign that led to the install, and purchase events are forwarded from RevenueCat to Amplitude as revenue analytics.
07Notifications
If you allow notifications, Third Eye uses OneSignal to deliver them — for example, telling you a read is ready. OneSignal receives your push token, an identifier it assigns to the install, the anonymous app user ID from section 06, and two non-identifying tags: whether you have reminders on, and when your last analysis happened. It receives no chat content, no reads, and no name.
iOS asks your permission before any notification is sent, and you can withdraw it at any time in iOS Settings → Notifications → Third Eye. OneSignal's processing is described in its Privacy Policy.
08Third parties at a glance
Every company that receives anything from Third Eye, what it gets, and what for:
- Google LLC — Gemini API. Gets the chat text you chose to analyze, sender names aliased. For generating your reading. Not used to train models under the paid API terms.
- Google LLC — Firebase and Cloud Functions. Gets that same text in transit, a Firebase installation identifier, and technical request metadata. For running our relay, verifying the app is genuine (App Check), and delivering remote settings.
- RevenueCat, Inc. Gets your purchase and transaction history for this app and the anonymous app user ID. For verifying purchases and unlocking what you bought.
- Amplitude, Inc. Gets app-interaction events with run metadata and an anonymous install identifier. For understanding how the app is used. Off via You → Share usage analytics.
- AppsFlyer Ltd. Gets install and attribution signals, and your advertising identifier only if you allowed tracking. For attributing installs to ad campaigns. Off via the same switch, or by declining the tracking prompt.
- OneSignal, Inc. Gets your push token, an install identifier, the anonymous app user ID, and two non-identifying tags. For delivering notifications you opted in to.
Equal protection. We confirm that these third parties provide the same or equal protection of user data as stated in Apple's Developer Program License Agreement and the App Store Review Guidelines. None of them receives your name, email address or phone number, because we never collect them. Apart from Google, none of them receives chat content at all.
09No accounts
Third Eye has no sign-up, no login, and no user accounts. We do not ask for your name, email, or phone number to use the app.
10Children
Third Eye is rated 16+ and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has used the app in a way that raises a concern, contact us and we will help.
11Retention, deletion & your controls
How long each kind of data lives, and how you end it:
- Chat text — held only for as long as the request takes. Not stored by our relay and not stored by us. There is nothing to delete afterwards, because nothing was kept.
- Your readings — on your device only, for as long as you keep them. Delete a single run inside the app to remove that reading. Delete the app to remove every Third Eye reading on the device.
- Allowance and credit balances — kept against the anonymous app user ID so a purchase survives a reinstall on the same App Store account. No chat content, no readings, no identity.
- Analytics and attribution events — held by Amplitude and AppsFlyer under their own retention policies, linked to nothing but an anonymous identifier. Stop them in the app at You → Share usage analytics.
- Your permission to use AI — withdraw it at You → "AI analysis consent", any time.
We hold no account and no copy of your chats or readings, so there is nothing for us to delete on your behalf. If you want an analytics record removed, or have any other request, email support@getthirdeye.app and we will handle it.
12Changes to this policy
We may update this policy as the app evolves. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be reflected here before they take effect.
13Contact
Questions about privacy? Email support@getthirdeye.app and we'll get back to you. Common questions — including how to delete a read and how purchases work — are answered on the Support page.