Privacy

What happens to what you write

You cannot use a product like this honestly unless you can predict it. So here is the whole model, including the parts that limit us.

Three levels

Every entry, check-in and note carries one of three levels. You choose it before you save, and you can see it on the entry afterwards.

SharedShared — the other person can see thisThey can see it.

Used in conversations you have together. Appears in shared summaries and exports.

PrivatePrivate — only you can see thisThey cannot see it.

Only you. Your guide can use it to help you. You can choose to share it later.

100% privateFully private — never shown to the other personThey cannot see it, and cannot tell it exists.

Never quoted, summarised, counted in a total, hinted at, or exported. No notification is sent when you write it. Your guide can still use it to understand you.

What “100% private” actually means

The strongest level is the one worth being precise about, because a vague promise here is worse than no promise. When you mark something 100% private, the other person in your space will not:

  • see it, in any screen, list, or export
  • see it quoted, paraphrased, or summarised
  • see it counted in any total, average, streak, or chart
  • receive a notification because you wrote it
  • see a “last active” time change because you wrote it
  • be told, hinted, or implied to that anything exists — no “there may be something on their mind”

That last one is the hard part, and it is the one most products get wrong. A sentence like “your partner may not be telling you everything” reveals the existence of a secret even though it names nothing. We treat that as a leak.

How that is enforced

Not by asking the AI to keep a secret. Shared conversations are built by a completely separate piece of code that can only read shared content — your private entries are never loaded into that process at all, so there is nothing there to slip out. Every request is checked against that rule before it is sent, and the check fails loudly rather than quietly filtering.

The same rule is enforced at the database level, so a bug in a screen cannot expose something the query never returned. We run an automated test suite that plays the role of a determined partner trying to detect hidden entries through every available surface.

Your guide can still use it

Private does not mean useless. Your own guide can read everything you have written to understand your history, what sets you off, what you have already tried, and how you like to be spoken to. That is the point of having a private space rather than a locked drawer.

Sharing is always a decision

Nothing is ever promoted from private to shared automatically. If something you wrote privately might help to say out loud, you may be offered the option — and you choose whether to keep it private, share a summary, share the whole thing, or have a version drafted that you can edit before anyone sees it. You approve exactly what leaves.

Connecting and disconnecting

Joining a space never back-fills history. If someone joins in June, they cannot see what was shared in March — not because it is hidden, but because the query that fetches shared content is bounded by when they joined.

Disconnecting ends shared visibility in both directions immediately. It deletes nothing you wrote and exposes nothing that was private. Leaving is meant to be a safe action.

The one limit

Your private notes stay private from the other person in this space. That does not change. There is one limit worth knowing about. If something you write suggests someone is in immediate danger, we may show you crisis resources, and in a small number of serious cases a trained reviewer on our team may look at the relevant entry. We are not an emergency service. We cannot call anyone for you, and we do not contact the police. If someone is in danger right now, contact your local emergency number.

We show this before you use the strongest privacy level for the first time, not only here. We would rather you know the limit up front than discover it later. More detail is on the safety page.

Your data, concretely

  • Entries, notes and transcripts are encrypted before they reach the database, so a backup or a stolen replica is not readable.
  • Voice recordings are deleted once transcribed, unless you turn that off.
  • You can download everything you have written.
  • You can delete individual entries, or your whole account.
  • Deleting your account does not delete the other person's own entries — those are theirs.
  • Analytics record that a check-in happened, never what it said.
  • Notifications never put your content on a lock screen unless you switch that on.

Questions about any of this: privacy@onbetterterms.com. The formal version is the privacy policy; if the two ever disagree, tell us, because this page is what OnBetterTerms intends to do.

Privacy — OnBetterTerms