Subtext Privacy Policy
This is the privacy policy for Subtext, a relationship communication-insight mobile app published by Keller Tech LLC (doing business as Banked Embers). Subtext reads message threads you bring to it and uses an AI model to give you a brief read on the communication patterns in those threads. This policy describes what data the app touches, where it goes, and what we never do with it.
If you only read one section, read How your messages are handled. The short version: your conversations are analyzed in the moment and never stored on our servers.
Who we are
- Developer: Keller Tech LLC (Banked Embers)
- Apps: Android (
com.bankedembers.subtext) and iOS (com.bankedembers.Subtext)
- Contact: help@bankedembers.com
Your account and sign-in
Subtext requires you to sign in with Google or Apple before you can use it. We use Firebase Authentication (a Google service) to manage sign-in. When you sign in, we receive and store a limited account profile:
- A unique account identifier (the Firebase user ID).
- The email address and, where the provider supplies it, the display name associated with your Google or Apple account. If you use Apple's "Hide My Email," we only ever see Apple's relay address.
We use this account to recognize you across devices, to grant your free trial once per account (the trial is granted by our backend, not by the app store), and to keep your subscription and usage limits tied to the right person. We do not use it to email you marketing.
Data the app accesses on your device
Depending on your platform and the import method you choose, Subtext may access:
- Notification access (Android): Used only to surface Subtext's analysis overlay above your messaging app when you ask for it. The app does not read or transmit notifications from other apps.
- Screenshots and pasted text: When you import a conversation by screenshot, the images you pick are downscaled on your device and sent over TLS-encrypted HTTPS to our transcription endpoint, which uses Anthropic's Claude to read the conversation out of them. The images are processed in the moment and discarded: they are never stored on our servers and never appear in logs. Screenshot import needs a connection; if the upload fails, the app shows an error and nothing is imported. When you paste a conversation, only the text you paste is used.
The app does not access your SMS messages, contacts, location, camera stream, microphone, calendar, call log, or any sensor data, and it does not use an advertising identifier.
How your messages are handled
When you ask Subtext to analyze a thread:
- The messages from that thread (sender, body, timestamp, up to the 250 most recent) and the contact's display name are sent over TLS-encrypted HTTPS to our analysis endpoint, hosted on Google Cloud Functions.
- The endpoint forwards that content to Anthropic's Claude API for analysis. Anthropic processes the content under its commercial terms and does not use it to train its models. See anthropic.com/legal/privacy.
- The result (a score, a few short pattern flags, a brief summary, and a suggested next move) is returned to your device.
- Nothing about the conversation is stored on our servers. No message bodies, no contact names, no thread excerpts. The request is processed and discarded.
- Our server-side logs record only anonymous metadata: your account or device identifier, a timestamp, and request latency. We never log message content, contact names, or conversation excerpts.
This is a hard architectural constraint. The backend has no code path that writes message content to durable storage, so it cannot be retained even if we wanted to.
Screenshot imports follow the same rules. The screenshots you pick are sent over TLS-encrypted HTTPS, transcribed into a conversation by Anthropic’s Claude under the same commercial terms, returned to your device, and discarded. The images are never stored on our servers and never appear in logs.
Data that stays on your device
To avoid re-analyzing the same thread every time, the most recent analysis result for each contact may be cached locally on your device only. This cache:
- Contains the analysis result (score, flags, summary), not the underlying messages.
- Never leaves your device.
- Is cleared if you reinstall the app or clear the app's storage.
- Can be turned off in Settings, which immediately deletes any stored readings.
Because nothing is stored on our servers, we cannot recover this data for you. If you uninstall the app, clear its storage, or lose or replace your phone, your saved readings and any context notes you have added are gone. There is no server-side copy to restore from, and standard device backups do not carry them over, because the data is encrypted with a key that never leaves your device. This is a deliberate tradeoff: the same design that means we cannot show your readings to anyone also means we cannot bring them back for you. Treat anything you want to keep long-term accordingly, for example by exporting or sharing a reading you care about.
If you choose to share a reading (for example, as an image or text), that is an action you take with content already on your device. We do not create, store, or transmit shared readings on our servers.
Subscriptions and payments
Subtext offers a free trial and paid options (subscriptions and a one-time pass). Purchases are processed by the Apple App Store or Google Play, not by us, so we never see your card number or full billing details. We use RevenueCat to manage subscription status. RevenueCat receives your account identifier and the purchase/transaction information needed to tell whether your subscription or pass is active. We store, in our own database, only the records needed to provide access: your account identifier, whether a trial, subscription, or pass is active, and the relevant expiry timestamps. No message content is ever part of this.
Diagnostics and analytics
To keep the app stable and understand how it is used in aggregate, we use the following Google/Firebase services. None of them ever receive message content, contact names, or the text of a reading.
- Firebase Analytics: Records anonymous, aggregated usage events (for example, that an analysis was requested or completed, which import source was used, or that the paywall appeared). Sensitive values are bucketed rather than recorded exactly, and events never contain conversation content. Firebase attaches coarse, non-identifying properties such as country (from IP, at the country level), language, app version, platform, device model, and OS version. Advertising-identifier collection is turned off, so this is not cross-app tracking.
- Firebase Crashlytics: Records crash diagnostics (stack traces, device model, OS version) so we can fix bugs. Crash reports do not include message content or contact names.
- Firebase App Check: Attests that requests come from a genuine instance of our app, to deter abuse.
- Firebase Installations and Cloud Messaging: Provide an installation identifier and, if you allow notifications, a push token so we can send service messages.
- Firebase Remote Config: Lets us adjust configuration without an app update.
Identifiers we use
- Account ID: Your Firebase user ID, created when you sign in. It ties your trial, subscription, and usage limits to your account.
- Device ID: A random per-install identifier used only as a fallback if a request is ever made before sign-in completes.
- Firebase installation ID and analytics app-instance ID: Used by the Firebase services above. These are kept separate from the identifier sent with an analysis request.
Third parties
- Google / Firebase: Authentication, hosting of the analysis endpoint (Cloud Functions), the entitlement database (Firestore), analytics, crash reporting, app attestation, and messaging.
- Anthropic, PBC: Performs the AI analysis. Thread content is sent over TLS for the duration of the request only and is not used to train models.
- RevenueCat, Inc.: Manages subscription status.
- Apple App Store / Google Play: Process purchases under their own terms.
What we do not do
- We do not sell personal data.
- We do not share personal data with advertisers or data brokers.
- We do not use your message content to train AI models.
- We do not store message content, media, or contact names on our servers.
- We do not log message bodies or conversation excerpts.
- We do not use an advertising identifier or track you across other apps and websites.
Security
All traffic between the app and our servers uses TLS 1.2 or higher; the app does not transmit user data in plain text. Sign-in is handled by Firebase Authentication, and requests are attested with Firebase App Check.
Children
Subtext is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has used the app, contact us at the address above and we will respond promptly.
Your choices and rights
- Delete your account and server-side data: Use "Delete my data" in the app, or our data deletion page. This removes the usage and entitlement records tied to your account and clears your on-device readings.
- Stop sharing device data: Revoke the Notification or Photos permissions in your device settings, or uninstall the app. Access stops immediately.
- Turn off local caching: Toggle off saved readings in Settings, which deletes them at once.
- Manage your subscription: Use your App Store or Google Play account settings.
- Access, correct, or object: Depending on where you live (for example, under GDPR or the CCPA/CPRA), you may have rights to access, correct, delete, or restrict the limited personal data we hold. Email us and we will help. Because we store no message content, most of your data either lives on your device or is the limited account and subscription information described above.
Where data is processed
Subtext is operated from the United States, and the services above process data in the United States and other countries where our providers operate. By using the Service you understand your information may be processed in the United States.
Changes to this policy
If we materially change how Subtext handles your data, we will update this policy and the "Last updated" date above. For changes that affect what data we collect or share, we will give in-app notice the next time you open the app.
Contact
Questions about this policy or about Subtext's data handling: