Last updated: June 4, 2026
Gather is a Mac app that reads your iMessages locally and turns them into relationship insights — personality patterns, attachment style, relationship health, and smarter ways to respond to the people you care about. This policy explains exactly what we see, what we don't, and where each piece of your data goes.
For any privacy question or request, email sesana.allen@gmail.com.
When you grant Full Disk Access during onboarding, Gather reads ~/Library/Messages/chat.db directly. All of this happens entirely on your Mac:
The overwhelming majority of your messages are never sent anywhere.
Two categories of data leave your Mac in normal use. Nothing else.
When you run a Kit, Gather assembles a transcript of the selected conversation and sends it to our API proxy, which forwards it to OpenAI's GPT-4o for analysis. What is sent over the wire:
Requests go to our proxy at msg-assistant-v0.vercel.app/api/kits/complete. The proxy holds the OpenAI API key server-side and forwards the request — it does not log or persist message content. OpenAI retains data up to 30 days for safety monitoring, then deletes it. They do not use API data to train models.
For one-time kits, Gather stores the generated output in our Supabase database so you can replay it later without re-running AI. This row contains a pseudonymous user id, the kit id, the generated text output, and a timestamp. No raw message text, no contact names, no phone numbers.
We also log lightweight usage stats per kit run (kit id, duration, model used, token counts, cost estimate, app version, and error codes if any). These rows contain no message content of any kind.
Sign-in uses your email address and Supabase Auth's magic-link / OTP flow. Session tokens are stored locally in the Mac app's renderer process and refreshed automatically. Your email is stored in Supabase Auth for account management only and is not shared with any third party beyond the subprocessors listed in Section 4.
Three companies see some piece of your data on the way to providing the service:
| Subprocessor | What they see | Retention |
|---|---|---|
| OpenAI | Redacted message excerpts from the chat you select when running a kit | Up to 30 days, then deleted. No model training. |
| Supabase | Auth (email), pseudonymous user id, one-time kit outputs, usage stats | Until you delete your account |
| Vercel | Hosts the proxy + web app. IP address + request metadata in access logs; not request bodies. | ~30 days (Vercel default) |
We do not use third-party analytics SDKs, advertising platforms, or trackers. No Facebook pixel, Google Analytics, PostHog, Segment, or similar.
Delete your Gather account
(1) Self-serve in the Mac app. Settings → Account → Delete account. Immediately removes your auth row, kit outputs, and usage stats. Nothing is recoverable after.
(2) Email us. sesana.allen@gmail.com with subject "Delete my Gather account." We'll process it within 7 days.
You can also locally: quit and uninstall Gather to stop all collection, or revoke Full Disk Access in System Settings → Privacy & Security → Full Disk Access.
Gather is intended for adults aged 18 and older. We don't knowingly collect data from anyone under 18. If you believe a minor has signed up, email sesana.allen@gmail.com.
The project is operated from the United States. If you reach us from the EEA, UK, or California, the access / deletion / correction rights in Section 6 apply under GDPR and the CCPA/CPRA. We do not "sell" or "share" personal information as defined under CCPA/CPRA.
If this policy changes materially, we'll post a notice on our website and email currently-active users at least 14 days before the change takes effect.
For anything privacy-related — questions, requests, complaints:
We'll respond within 7 days.
Gather · sesana.allen@gmail.com