PairCafe

Privacy

What we keep, and why.

Last updated

The short version

Pair Cafe is a small, two-person app (often just called “Pair” in this doc). We only collect what we need to make your shared list work, and we never sell or rent it. You can delete your account, your couple, or your data any time from Settings.

We don’t use trackers across the web, we don’t profile you for ads. We disclose content only to your partner and the service providers needed to operate Pair, exactly as described below.

Who we are

Pair Cafe (the “Service”) is made and operated by Thesis Labs, LLC, a California software studio (thesis.do). The Service is available at pair.cafe and through our iOS and Android applications. The fastest way to reach us about anything in this policy is through the form at /contact, or by email at support@thesis.do.

What we collect

Pair stores only the data you give us. We don’t buy data, and there’s no analytics SDK trying to fingerprint your device.

From you, when you sign up

  • Your email address — used as your sign-in handle and for one-time password-recovery links. Supabase processes and securely hashes your password; Pair Cafe never stores or logs its plaintext value.
  • Your display name — shown next to todos so your partner knows who added or completed what.
  • Optionally, an avatar image you choose, and your relationship start date (used to celebrate your anniversary).

From you, while using Pair

  • The contents of your shared list: todo titles, notes, target dates, who added each item, and who completed it.
  • Completion details — your free-text "How did it go?" note and up to four photos or short video clips per completion (max 19MB each; supported photos may be resized on your device or browser before upload, while clips are uploaded as-is).
  • Reactions you and your partner add to completed items.
  • Categories — auto-assigned for new todos by an AI categorizer (see below) so the app can show you a meaningful filter row.
  • Recaps — monthly (and on-request) recap stories that Pair assembles from your couple's completions. Generating a recap creates and stores rendered recap frames (images) built from your photos, titles, and notes so you can view and share them later.
  • In-app notifications about activity on your shared list.
  • Safety reports you choose to submit, including the reason, your description, the connected partner, and an attached todo when you report from an item. Your partner is not told that you reported them.

From your device, only if you opt in

  • A browser push subscription or native device push token, platform, app version, and random app-install identifier so we can deliver notifications when Pair isn't open. You enable this from Settings; dead tokens are removed when the push provider rejects them, and the current device token is removed on sign-out.
  • Photos or videos you explicitly choose from your library or camera. Pair does not scan your library or collect assets you do not select.
  • Your approximate or precise current location only when you tap Nearby while adding a place. We use it to bias place-search results and attach the place you choose; Pair does not collect location in the background or build location history.
  • Local preferences such as theme and the web "Add to Home Screen" dismissal, stored on that device.
  • A time-limited local cache of recently loaded list, calendar, notification, comment, reaction, and recap-summary data so the native app can show a read-only recent view during a connection interruption. The cache lives in the operating system's private app storage and is cleared when the signed-in account changes.

If you make a purchase

  • Purchases are processed by Apple through the App Store. We never see or store your card number or billing address.
  • To keep your unlock working, we receive and store App Store transaction records (transaction and product identifiers, purchase status and dates, and a random billing token that links the purchase to your account — not your Apple ID).
  • Your couple's entitlement record — which plan covers your shared space and which partner's purchase covers it — is visible to both of you in the app.

Automatically, when your app or browser talks to our server

  • Short-lived Supabase access and refresh tokens so you stay signed in. The website stores these in secure cookies; the native apps store them using encrypted platform storage.
  • Standard request metadata (IP, timestamp, user agent) that our hosting and database providers process to serve traffic and protect against abuse. We don't use this for analytics, ad targeting, or profiling.

How we use it

We use what you give us to do the obvious things and nothing else:

  • Show your shared list, calendar, completion gallery, and notifications.
  • Find nearby places when you explicitly request a location search and save the place you select with a todo or memory.
  • Authenticate you with email and password and send one-time recovery or other necessary account-management emails.
  • Deliver browser or native device push notifications you've opted into.
  • Categorize new todos so the filter row stays useful.
  • Generate your monthly or on-request recaps — selecting photos and writing recap titles and captions with AI help, as described below.
  • Verify App Store purchases and keep your couple's entitlement record accurate.
  • Triage messages you send through the contact form.
  • Review safety reports, prevent blocked accounts from pairing again, enforce our Terms, and protect users and the Service.

We do not use your data to train any AI model, sell to brokers, build advertising profiles, or share with anyone outside the subprocessors listed below.

Who else sees it (subprocessors)

Pair runs on a small, deliberately boring stack. Each provider sees only what they need to do their job:

  • Supabase — hosts our database, authentication, and the storage bucket where completion photos live. They process your account record, your couple's todos and reactions, your push subscriptions, and your photos.
  • Vercel — hosts the website itself and serves traffic from their edge network. The website also uses Vercel Analytics for anonymous, aggregated page-view counts (no cookies, no cross-site tracking, nothing that identifies you). Standard request logs apply.
  • OpenAI — powers two features. Categorization: receives a todo title and notes so it can return one or two category labels. Whenever a completed item that has attached media is categorized — including automatically when you log a memory with photos or edit a completed item, not only when you tap refresh — up to four of its completion photos or short clips may also be sent for visual context. Recaps: when a monthly or on-request recap is generated, up to sixteen of your completion photos or clips may be sent for content tagging, along with todo titles, category counts, and short excerpts of completion notes, so the recap's titles and captions can be written. We don't send your name or email for either feature. You can disable AI features by leaving the API key unset on your self-hosted copy.
  • Apple — processes App Store payments and purchase state. Apple sends us signed transaction records (never your payment details) so we can verify purchases and keep your couple's entitlement accurate.
  • Komoot's Photon service — receives the place-search words you type and, only after you tap Nearby and allow location, coordinates used to bias those search results. Pair does not send your account identity to Photon.
  • Expo Push Service plus Apple, Google, and Mozilla push services — route notification payloads to the browser or device token you registered so notifications can land on your lock screen. The lock-screen text may be visible to those platform services while they deliver it.

We don’t use Google Analytics, Meta Pixel, Mixpanel, PostHog, or any equivalent tool. There is no analytics or advertising SDK in the native apps. The website’s only measurement is Vercel Analytics, as described above — cookieless, anonymous, and aggregated.

How long we keep it

  • Account data (email, profile, couple, todos, completion notes, photos, reactions) — kept as long as your account exists.
  • Browser and native push registrations — removed on sign-out from that device, when you disable them, or when the relevant push service reports that the registration is no longer valid.
  • Notifications — kept in your in-app inbox until you or your partner clear them.
  • Contact form messages — kept until we've actioned them, then archived. We may keep them for up to 24 months for support continuity.
  • Safety reports — kept for up to 24 months for review and abuse prevention. Reports you submitted are deleted if you delete your account. If another person reported your account, the direct account/content links are removed when your account is deleted, but their report may remain until its retention period expires.
  • Billing records (App Store transaction identifiers and entitlement history) — kept while your account exists, and afterwards only as long as needed for tax, accounting, fraud-prevention, and audit obligations.
  • Deleted data is removed from Pair Cafe's active systems. Encrypted provider disaster-recovery backups may retain a copy temporarily until they expire on the provider's normal backup cycle; we do not restore deleted accounts from those backups except as required for disaster recovery.
  • Server request logs (held by Supabase and Vercel) — typically retained for 30–90 days per their respective policies.

When you delete your account from Settings → Danger zone, we delete your profile andthe couple you’re part of — which means every todo, completion note, comment, recap, and photo you and your partner created together is removed at the same time. Your partner loses access to those shared memories as a result; their own profile and any solo data stays untouched. This is a hard delete from the active service: we don’t keep an accessible shadow account, and we can’t undo it. Temporary disaster-recovery backups age out as described above.

Your rights

You have the right to:

  • Access the data we hold about you — most of it is visible directly in the app; the rest is one request away.
  • Export it in a portable format.
  • Correct anything that's wrong (you can edit your name, email, anniversary, todos, and notes directly in the app).
  • Delete your account and your shared content at any time from Settings → Danger zone.
  • Withdraw consent for push notifications by toggling them off in Settings — we'll stop sending and remove your subscription.
  • Report or block a connected partner. Blocking archives the shared relationship for both people and prevents the two accounts from pairing again while the block remains.
  • Lodge a complaint with your local data protection authority if you believe we've mishandled your data.

To exercise any of these rights beyond what the app exposes directly, send a message via /contact. We aim to respond within 30 days.

Children

Pair isn’t designed for or directed at children under 13 (or the equivalent minimum age in your jurisdiction). Don’t use the Service if you are under that age. If we learn we’ve collected data from someone underage, we’ll delete it.

Where your data lives

Pair’s database, storage bucket, and hosting are operated in the United States. By using the Service you understand that your data may be processed there.

Security

Connections to Pair are encrypted with TLS. Password-recovery links are single-use and short-lived; native session tokens use encrypted platform storage. Photos and todos are protected by row-level security policies that scope access to the two members of your couple. No system is invincible — if you spot something that looks off, please tell us at /contact.

Changes to this policy

If we make a substantive change, we’ll update the Last updated date at the top and, when the change materially affects your rights, give you reasonable notice through the app or via email before it takes effect.