PairCafe

Privacy

What we keep, and why.

Last updated

The short version

Pair Cafe is a small, two-person app (often just called “Pair” in this doc). We only collect what we need to make your shared list work, and we never sell or rent it. You can delete your account, your couple, or your data any time from Settings.

We don’t use trackers across the web, we don’t profile you for ads. We disclose content only to your partner and the service providers needed to operate Pair, exactly as described below.

Who we are

Pair Cafe (the “Service”) is made and operated by Thesis Labs, LLC, a California software studio (thesis.do). The Service is provided through our iOS and Android applications. The website at pair.cafe provides marketing, store-download, support, legal-information, and narrowly scoped password-recovery pages; it does not provide browser signup, sign-in, partner linking, or shared-content access. The fastest way to reach us about anything in this policy is through the form at /contact, or by email at support@thesis.do.

What we collect

Pair stores only the data you give us. We don’t buy data, and there’s no analytics SDK trying to fingerprint your device.

From you, when you sign up in a supported app

  • Your email address — used as your sign-in handle and for one-time password-recovery links. Supabase processes and securely hashes your password; Pair Cafe never stores or logs its plaintext value.
  • Your display name — shown next to todos so your partner knows who added or completed what.
  • Optionally, an avatar image you choose, and your relationship start date (used to celebrate your anniversary).

From you, while using Pair

  • The contents of your shared list: todo titles, notes, target dates, who added each item, and who completed it.
  • Completion details — your free-text "How did it go?" note and up to ten normalized JPEG photos per completion (max 19MB before processing). Pair keeps the best-effort capture time, source time-zone offset, dimensions, and a short-lived transformed preview so Memories and Photos can load without fetching the full file. Historic memories may still contain short video attachments; new videos use the verified Cloud Media pipeline and are not sent to OpenAI for recaps.
  • Cloud Media you explicitly add to your couple's shared library. Pair stores a privacy-normalized, high-quality photo or video and smaller previews, along with the filename, media type, capture date and time-zone offset, dimensions, duration when applicable, byte size, processing state, and a cryptographic file fingerprint used to avoid duplicate uploads. We remove location and unrelated embedded metadata from the shared high-quality file. You and your partner may add tags, hearts, comments, and an explicit calendar-day placement; Pair keeps the actor, prior day, new day, and time in a private audit so the shared calendar remains consistent. A separate per-item 'Consider for Our Month' control is off by default and is the only way Cloud Media becomes eligible for the optional recap processing described below; a heart or comment alone is never consent.
  • A UTC-month media-processing counter for each uploader, couple, and verified payer scope. It stores cost-weighted bytes, a coarse operation type, and a server-derived one-way operation digest so an exact retry is not counted twice. The digest does not contain the object path or filename. Deleting media does not subtract bytes already uploaded or processed that month.
  • Reactions you and your partner add to completed items.
  • Categories — auto-assigned for new todos by an AI categorizer (see below) so the app can show you a meaningful filter row.
  • Recaps — monthly (and on-request) recap stories that Pair assembles from your couple's completions. Generating a recap creates and stores rendered recap frames (images) built from your photos, titles, and notes so you can view and share them later. To keep recaps fast, accurate, and cheap to re-generate, Pair also stores a small bounded set of AI-derived signals about the completion photos it considers — a people count, content flags (for example food, venue, outdoor, pet, screenshot, document), a technical quality score, and a short literal caption of what is visible — keyed to each photo, plus, for each finished recap, the curated list of photos it used with their resolved caption. Pair stores these structured signals, not the AI provider's raw responses, prompts, or any signed image links. Suggested-recap ideas (such as a detected trip) are computed on the fly from your existing completion dates and any place you saved; they are not a new stored field.
  • In-app notifications about activity on your shared list.
  • Safety reports you choose to submit, including the reason, your description, the connected partner, and an attached todo when you report from an item. Your partner is not told that you reported them.
  • Optional problem reports you send from the iOS app (shake the phone or Settings → Report a problem). A report includes a screenshot of the screen you were on — captured before the report sheet appears — plus the short description you type, optional extra photos or a short video clip, and device/session metadata (app version and build, iOS version, device model, your user and couple ids, the screen you were on, whether the device is online, notification permission, and Reduce Motion). Reports never include access tokens or signed media URLs.

From your device, only if you opt in

  • A native device push token, platform, app version, and random app-install identifier so we can deliver notifications when Pair isn't open. You enable this from Settings; dead tokens are removed when the push provider rejects them, and the current device token is removed on sign-out.
  • Photos or videos you explicitly choose from your library or camera. Pair does not scan your library or collect assets you do not select.
  • Your approximate or precise current location only when you tap Nearby while adding a place. We use it to bias place-search results and attach the place you choose; Pair does not collect location in the background or build location history.
  • Local preferences such as theme and notification choices, stored in the native app on that device.
  • A time-limited local cache of recently loaded list, calendar, notification, comment, reaction, and recap-summary data so the native app can show a read-only recent view during a connection interruption. The cache lives in the operating system's private app storage and is cleared when the signed-in account changes.

If you make a purchase

  • Purchases are processed by Apple through the App Store or Google through Google Play. We never see or store your card number or billing address.
  • To keep your unlock working, we receive and store store transaction records (transaction or purchase-token and product identifiers, purchase status and dates, and an account-linked billing token — not your Apple ID or Google password).
  • Your couple's entitlement record — which plan covers your shared space and which partner's purchase covers it — is visible to both of you in the app.
  • If we give you targeted promotional access, we store only a cryptographic digest of the one-time code, its intended account or couple, its expiry, and the redemption/audit time. We never store or log the plaintext code.

Automatically, when your app or the website talks to our server

  • Short-lived Supabase access and refresh tokens so you stay signed in to the native app; the apps store them using encrypted platform storage. If a recovery link cannot return directly to the app, the recovery-only website flow may use a short-lived secure cookie solely while you choose a new password, then signs that browser session out.
  • Standard request metadata (IP, timestamp, user agent) that our hosting and database providers process to serve traffic and protect against abuse. We don't use this for analytics, ad targeting, or profiling.

How we use it

We use what you give us to do the obvious things and nothing else:

  • Show your shared list, unified Photos and Memories views, calendar, completion gallery, and notifications using small signed previews; full media is authorized only when you open, play, or download it.
  • Store, process, display, deduplicate, play, download, and delete the Cloud Media you intentionally share with your partner while enforcing the active-couple allowance and, for verified subscribers, the payer-scoped allowance across current and temporarily retained former-couple media.
  • Limit monthly media ingress and processing so repeated upload-delete-reupload cycles cannot turn Pair into a bulk file-transfer service or create unbounded provider costs. This operational limit is separate from the amount of media currently stored.
  • Find nearby places when you explicitly request a location search and save the place you select with a todo or memory.
  • Authenticate you with email and password and send one-time recovery or other necessary account-management emails.
  • Deliver native device push notifications you've opted into.
  • Categorize new todos so the filter row stays useful.
  • Generate your monthly or on-request recaps — first selecting a small, varied set with dates, engagement, tags, and exact duplicate suppression, then writing recap titles and captions with limited AI help as described below.
  • Verify App Store and Google Play purchases, redeem targeted promotional access, and keep your couple's entitlement record accurate.
  • Triage messages you send through the contact form.
  • Diagnose optional problem reports you send from the app.
  • Review safety reports, prevent blocked accounts from pairing again, enforce our Terms, and protect users and the Service.

We do not use your data to train any AI model, sell to brokers, build advertising profiles, or share with anyone outside the subprocessors listed below.

Who else sees it (subprocessors)

Pair runs on a small, deliberately boring stack. Each provider sees only what they need to do their job:

  • Supabase — hosts our database, authentication, and private storage buckets. It processes your account record, your couple's todos and reactions, native notification registrations, Cloud Media metadata, privacy-normalized photos and photo previews, entitlement state, and deletion state.
  • Resend — delivers necessary transactional account email, such as password-recovery and email-change messages. It receives the recipient email address, sender, subject and email body (including the time-limited account-action link), plus ordinary delivery and bounce metadata; Pair does not use it for advertising email.
  • Cloudflare Stream — receives privacy-normalized Cloud Media videos and associated technical metadata so it can inspect and encode them, generate posters and adaptive playback versions, provide an encoded downloadable MP4, deliver private token-protected playback, and delete those versions when the media expires or is removed. Pair does not retain the exact video file selected from your camera library. Cloudflare Stream is a video-processing, storage, and playback provider, not an end-to-end encryption service.
  • Vercel — hosts the marketing, store-download, support, legal-information, and recovery-only website pages and serves traffic from its edge network. The website also uses Vercel Analytics for anonymous, aggregated page-view counts (no cookies, no cross-site tracking, nothing that identifies you). Standard request logs apply.
  • OpenAI — powers categorization and limited recap assistance. Categorization receives a todo title and notes so it can return one or two category labels; up to four completion attachments may also be sent when visual context is needed. Recaps may send up to sixteen size-reduced completion photos for low-detail structured tagging, and Pair caches the resulting bounded signals — a people count, content and technical-quality flags, and a short literal caption — keyed to each photo so re-generating a recap does not re-analyze it. Cloud Media is handled more narrowly: only an item whose 'Consider for Our Month' control was explicitly turned on may be selected; Pair first uses deterministic diversity rules, signs at most twelve normalized previews or posters, and may send at most four engaged, not-yet-cached previews for structured visual analysis. We never send the Cloud Media original or video bytes, comments, tags, filename, capture time, location, OCR text, name, or email in that analysis. Hearts and comments may affect ranking but never grant consent. A static instruction treats any text visible inside an image as untrusted content, and a hard monthly item-and-cost ledger stops additional analysis. Pair caches only bounded structured labels, face count, technical quality, and a short literal caption, not provider responses, prompts, or signed URLs. Turning the control off prevents new jobs and deletes Pair's cached analysis; an already-running provider request cannot be recalled.
  • Apple — processes App Store payments and purchase state. Apple sends us signed transaction records (never your payment details) so we can verify purchases and keep your couple's entitlement accurate.
  • Google — processes Google Play payments and purchase state on Android. Google provides purchase tokens and status (never your payment-card details) so we can verify purchases and keep your couple's entitlement accurate.
  • Komoot's Photon service — receives the place-search words you type and, only after you tap Nearby and allow location, coordinates used to bias those search results. Pair does not send your account identity to Photon.
  • Apple Push Notification service and Google Firebase Cloud Messaging — route notification payloads to the native device token you registered so notifications can land on your lock screen. The lock-screen text may be visible to those platform services while they deliver it.

We don’t use Google Analytics, Meta Pixel, Mixpanel, PostHog, or any equivalent tool. There is no analytics or advertising SDK in the native apps. The website’s only measurement is Vercel Analytics, as described above — cookieless, anonymous, and aggregated.

How long we keep it

  • Account data (email, profile, couple, todos, completion notes, completion media, reactions) — kept as long as your account exists, subject to the specific Cloud Media lifecycle below.
  • Unfinished completion-photo uploads — if an upload cannot be finalized, Pair may delete its exact stored full-size and preview objects immediately when your device rolls it back or automatically after a one-hour grace period. This cleanup never touches copies saved in your phone's photo library.
  • Deleted memories — either current partner may explicitly confirm deletion of a shared calendar-memory photo or todo. Pair hides it immediately, permanently removes only its recorded attachments, and removes the shared row after the provider confirms those exact objects are gone. A bounded deletion audit containing request and exact-path state may remain for up to 30 days so retries cannot delete the wrong file.
  • Cloud Media after Premium ends — available while Premium is active and during any billing-recovery grace reported by the app store. When that period ends, new uploads stop and the current-couple library remains read-only, playable, downloadable, and deletable for 90 days. We provide reasonable notice when contact channels are available. At the end of the window, we delete the high-quality media, previews, Cloudflare Stream versions, and active metadata. Renewing during the window restores normal access.
  • Cloud Media after a couple is archived — shared access and issuance of new shared capabilities stop immediately. For 30 days, each former member may list, export, and delete only media that person uploaded. That view does not disclose the former partner's media, usage, or continued presence. Re-pairing does not extend the window, and media funded by a verified subscriber continues to count toward that subscriber's 100 GB allowance until deletion completes. At the deadline, all remaining Supabase files, Cloudflare Stream versions, and related active metadata enter irreversible purge. Archive notices are best effort.
  • Already-issued Cloud Media capabilities — server authorization stops issuing new shared capabilities immediately after archival, opt-out, or deletion. A Supabase download capability issued just beforehand may remain usable for about 10 minutes plus a short cache margin, and a Cloudflare video playback capability may remain usable for about 40 minutes so an already-started 30-minute video can finish. These bearer capabilities cannot be recalled individually; provider-object deletion is the immediate-revocation path when required.
  • Cloud Media recap analysis — kept only while that item remains opted in and the current analysis version is useful. Turning 'Consider for Our Month' off prevents new jobs and removes Pair's cached structured analysis; deleting the item or couple cascades its tags, hearts, comments, job records, and cached analysis. A provider request already in progress cannot be recalled, but its result is rejected if consent was withdrawn before completion.
  • Completion-photo recap analysis and curated recap sets — the cached structured signals about a completion photo (people count, content and quality flags, and a short caption) are kept while the current analysis version is useful and are removed automatically when the underlying photo, its todo, or the couple is deleted. The per-recap list of photos a finished recap used is removed when that recap is deleted. Deleting your account removes all of it as part of the couple cascade.
  • Monthly media-processing counters — media deletion does not refund the current UTC month's counter. Couple deletion removes that couple's scoped counter and operation history. Historic uploader and verified-payer aggregate counters remain while the account exists so deleting a couple and re-pairing cannot reset abuse prevention; only the current UTC month's aggregate is enforced. Account deletion removes that account-scoped counter.
  • Native push registrations — removed on sign-out from that device, when you disable them, when account deletion begins, or when the relevant push service reports that the registration is no longer valid. Retired browser push subscriptions are removed on a best-effort basis when the website next opens and by ordinary stale-registration cleanup.
  • Notifications — kept in your in-app inbox until you or your partner clear them.
  • Contact form messages — kept until we've actioned them, then archived. We may keep them for up to 24 months for support continuity.
  • Safety reports — kept for up to 24 months for review and abuse prevention. Reports you submitted are deleted if you delete your account. If another person reported your account, the direct account/content links are removed when your account is deleted, but their report may remain until its retention period expires.
  • Optional problem reports (screenshots, extra clips, and the device/session metadata above) — kept until we close the report or you delete your account, whichever comes first. Closing a report removes it from the active queue; account deletion removes your reports and their stored files.
  • Billing and promotion records (App Store transaction identifiers, promotion-code digests and redemption history, and entitlement history) — kept while your account exists, and afterwards only as long as needed for tax, accounting, fraud-prevention, and audit obligations. Plaintext promotion codes are never retained.
  • Deleted data is removed from Pair Cafe's active systems. Encrypted provider disaster-recovery backups may retain a copy temporarily until they expire on the provider's normal backup cycle; we do not restore deleted accounts from those backups except as required for disaster recovery.
  • Server request logs (held by Supabase, Vercel, and Cloudflare) — retained according to each provider's configured service and legal requirements.

When you delete your account from Settings → Danger zone, access to shared profile details and the couple you’re part of is revoked immediately. While provider cleanup finishes, the signed-in requester can see only a minimal deletion-status screen and use it to safely resume the confirmed request; no shared content or ordinary profile controls remain available. We then queue the couple’s todos, completion notes, comments, recaps, photos, videos, Cloudflare Stream versions, and any problem reports you sent for irreversible deletion from the active service, including unfinished completion-photo uploads associated with you or the affected couple. Provider deletion is asynchronous and may finish after access has already ended. Your partner loses access to those shared memories; their own profile and any solo data stays untouched. We don’t keep an accessible content shadow, and we can’t undo the deletion. The minimal requester status record disappears when account deletion completes. Temporary disaster-recovery backups age out as described above. Copies either person previously saved to a phone remain on that phone.

Your rights

You have the right to:

  • Access the data we hold about you — most of it is visible directly in the app; the rest is one request away.
  • Export it in a portable format.
  • Correct anything that's wrong (you can edit your name, email, anniversary, todos, and notes directly in the app).
  • Delete your account and your shared content at any time from Settings → Danger zone.
  • Withdraw consent for push notifications by toggling them off in Settings — we'll stop sending and remove your subscription.
  • Report or block a connected partner. Blocking archives the shared relationship for both people and prevents the two accounts from pairing again while the block remains.
  • Lodge a complaint with your local data protection authority if you believe we've mishandled your data.

To exercise any of these rights beyond what the app exposes directly, send a message via /contact. We aim to respond within 30 days.

Children

Pair isn’t designed for or directed at children under 13 (or the equivalent minimum age in your jurisdiction). Don’t use the Service if you are under that age. If we learn we’ve collected data from someone underage, we’ll delete it.

Where your data lives

Pair’s primary database and Supabase storage are operated in the United States. Vercel and Cloudflare use distributed infrastructure and may process requests or video in the United States and other locations where they and their subprocessors operate. By using the Service you understand that your data may be processed in those locations.

Security

Connections to Pair are encrypted with TLS. Password-recovery links are single-use and short-lived; they may briefly use the recovery-only website bridge described above. Native session tokens use encrypted platform storage. Private Supabase storage, row-level database policies, short-lived media authorization, and signed Cloudflare playback tokens scope normal access to the two members of your current couple. After archival, a separate time-limited authorization permits each former member to access only media that person uploaded; it does not expose the former partner’s media or usage. Pair Cafe and its service providers can process Cloud Media to operate the Service; Cloud Media is not represented as end-to-end encrypted. No system is invincible — if you spot something that looks off, please tell us at /contact.

Changes to this policy

If we make a substantive change, we’ll update the Last updated date at the top and, when the change materially affects your rights, give you reasonable notice through the app or via email before it takes effect.