Privacy Policy
Last updated: July 20, 2026, draft, not yet reviewed by a lawyer
This is a working draft written to accurately describe what the app actually does today. It has not been reviewed by a lawyer. Given this app handles descriptions of real relationship conflict and, sometimes, disclosures of feeling unsafe, we recommend a real legal review before relying on this for real users, particularly around data retention, breach notification, and multi-jurisdiction privacy law (this app is used from the US, Canada, the UK, Nigeria, and elsewhere).
Between ("we," "us") provides a communication tool for couples. This policy explains what information we collect, why, and what we do (and deliberately do not do) with it.
What we store
- Account information: your email address and a securely hashed password, managed by our authentication provider (Supabase). We never see or store your password in plain text.
- Usage count: how many free sessions you've used, tied to your account (or, if you're not signed in, to your IP address instead), so the free-tier limit works correctly either way.
- Subscription status: if you subscribe, we store your Stripe customer and subscription IDs and status (active, canceled, etc.). We never receive or store your card number, Stripe handles that entirely.
- Shared sessions: if you invite a partner into a shared session, we store both people's email addresses and, for each message in the back-and-forth, only the short "what might be underneath" insight, never the raw text either of you typed. If a message describes a safety concern, nothing about it is stored here at all. Either person can end the conversation at any time, which permanently deletes the whole thread, both emails and all messages, right away. A partner's first reply is also only stored if they explicitly choose to share it; if they decide not to, nothing about their reply is saved either.
- Optional check-ins and marketing: if you opt in (a check-in reminder, or the marketing checkbox on a shared session), we store your email for that specific purpose. We only send marketing email to addresses that explicitly opted in, never to someone just because they were invited to a shared session.
What we deliberately do not store
The text you paste into "what happened" or "what they said" is sent directly to our AI provider (Anthropic) to generate a response, and that response is sent back to your browser. We do not save this text to our database. If you close the tab, it's gone from our side. This is a deliberate choice given how personal and sometimes sensitive this content can be.
The country you select (to show the right support resources) is not stored anywhere either, it only affects what's shown to you in that moment.
If you use the microphone button to speak instead of type, Between never receives, sees, or stores your voice audio at all. Your browser sends that audio directly to its own speech-recognition service (see "Third parties we use" below) to convert it to text, and only the resulting text ever reaches Between, exactly as if you had typed it yourself.
Third parties we use
- Anthropic (Claude), to generate the translate/reply suggestions. Your input is processed according to Anthropic's own privacy practices.
- Supabase, for authentication and our database.
- Stripe, for subscription billing. Stripe collects and stores your payment details directly; we never see your full card number.
- Resend, to send transactional email (shared session invites, check-in reminders) and, only for addresses that opted in, occasional marketing email.
- Your browser's speech-recognition service (for example, Google's, in Chrome), only if you use the microphone button. This is your browser talking directly to its own vendor, not something Between routes or controls. See "What we deliberately do not store" above for what this means in practice.
- Sentry, for error and crash monitoring, so we can catch and fix bugs. Sentry may receive technical details about an error, like a stack trace or which page you were on, but is not intentionally sent the text you type into the app.
- Vercel, our hosting provider, which processes all traffic to and from the app as a normal part of serving it to you.
Your data may be transferred to and processed in countries other than the one you're in, including the United States, by these providers.
Cookies
We use a login session cookie so you stay signed in. We do not currently use any advertising, tracking, or analytics cookies.
How long we keep things
Account data is kept for as long as your account exists. To request deletion of your account and associated data, contact us at hello@usebtwn.com. We don't yet have a self-serve delete-my-account button; we're handling deletion requests manually for now.
Safety-related content
If what you write is identified as describing a safety concern, our AI is instructed to respond with validation and never to make a diagnosis. Crisis and support hotline numbers shown to you are hardcoded by us based on your selected country, never generated by the AI, specifically to avoid the risk of an AI-generated phone number being wrong.
Children
This app is intended for adults 18 and older and is not directed at children.
Changes to this policy
If this policy changes in a material way, we'll update the date at the top of this page.
Contact
Questions about this policy: hello@usebtwn.com.
← Back to Between