Subtext Privacy Policy

Effective date: 2026-06-24

Last updated: 2026-07-05

This is the privacy policy for Subtext, a relationship communication-insight mobile app published by Keller Tech LLC (doing business as Banked Embers). Subtext reads message threads you bring to it and uses an AI model to give you a brief read on the communication patterns in those threads. This policy describes what data the app touches, where it goes, and what we never do with it.

If you only read one section, read How your messages are handled. The short version: your conversations are analyzed in the moment and never stored on our servers.


Who we are


Your account and sign-in

Subtext requires you to sign in with Google or Apple before you can use it. We use Firebase Authentication (a Google service) to manage sign-in. When you sign in, we receive and store a limited account profile:

We use this account to recognize you across devices, to grant your free trial once per account (the trial is granted by our backend, not by the app store), and to keep your subscription and usage limits tied to the right person. We do not use it to email you marketing.


Data the app accesses on your device

Depending on your platform and the import method you choose, Subtext may access:

The app does not access your SMS messages, contacts, location, camera stream, microphone, calendar, call log, or any sensor data, and it does not use an advertising identifier.


How your messages are handled

When you ask Subtext to analyze a thread:

  1. The messages from that thread (sender, body, timestamp, up to the 250 most recent) and the contact's display name are sent over TLS-encrypted HTTPS to our analysis endpoint, hosted on Google Cloud Functions.
  2. The endpoint forwards that content to Anthropic's Claude API for analysis. Anthropic processes the content under its commercial terms and does not use it to train its models. See anthropic.com/legal/privacy.
  3. The result (a score, a few short pattern flags, a brief summary, and a suggested next move) is returned to your device.
  4. Nothing about the conversation is stored on our servers. No message bodies, no contact names, no thread excerpts. The request is processed and discarded.
  5. Our server-side logs record only anonymous metadata: your account or device identifier, a timestamp, and request latency. We never log message content, contact names, or conversation excerpts.

This is a hard architectural constraint. The backend has no code path that writes message content to durable storage, so it cannot be retained even if we wanted to.

Screenshot imports follow the same rules. The screenshots you pick are sent over TLS-encrypted HTTPS, transcribed into a conversation by Anthropic’s Claude under the same commercial terms, returned to your device, and discarded. The images are never stored on our servers and never appear in logs.


Data that stays on your device

To avoid re-analyzing the same thread every time, the most recent analysis result for each contact may be cached locally on your device only. This cache:

Because nothing is stored on our servers, we cannot recover this data for you. If you uninstall the app, clear its storage, or lose or replace your phone, your saved readings and any context notes you have added are gone. There is no server-side copy to restore from, and standard device backups do not carry them over, because the data is encrypted with a key that never leaves your device. This is a deliberate tradeoff: the same design that means we cannot show your readings to anyone also means we cannot bring them back for you. Treat anything you want to keep long-term accordingly, for example by exporting or sharing a reading you care about.

If you choose to share a reading (for example, as an image or text), that is an action you take with content already on your device. We do not create, store, or transmit shared readings on our servers.


Subscriptions and payments

Subtext offers a free trial and paid options (subscriptions and a one-time pass). Purchases are processed by the Apple App Store or Google Play, not by us, so we never see your card number or full billing details. We use RevenueCat to manage subscription status. RevenueCat receives your account identifier and the purchase/transaction information needed to tell whether your subscription or pass is active. We store, in our own database, only the records needed to provide access: your account identifier, whether a trial, subscription, or pass is active, and the relevant expiry timestamps. No message content is ever part of this.


Diagnostics and analytics

To keep the app stable and understand how it is used in aggregate, we use the following Google/Firebase services. None of them ever receive message content, contact names, or the text of a reading.


Identifiers we use


Third parties


What we do not do


Security

All traffic between the app and our servers uses TLS 1.2 or higher; the app does not transmit user data in plain text. Sign-in is handled by Firebase Authentication, and requests are attested with Firebase App Check.


Children

Subtext is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has used the app, contact us at the address above and we will respond promptly.


Your choices and rights


Where data is processed

Subtext is operated from the United States, and the services above process data in the United States and other countries where our providers operate. By using the Service you understand your information may be processed in the United States.


Changes to this policy

If we materially change how Subtext handles your data, we will update this policy and the "Last updated" date above. For changes that affect what data we collect or share, we will give in-app notice the next time you open the app.


Contact

Questions about this policy or about Subtext's data handling: