← BackGather
Legal

Privacy Policy

Last updated: June 4, 2026

Gather is a Mac app that reads your iMessages locally and turns them into relationship insights — personality patterns, attachment style, relationship health, and smarter ways to respond to the people you care about. This policy explains exactly what we see, what we don't, and where each piece of your data goes.

For any privacy question or request, email sesana.allen@gmail.com.

1.

What runs on your Mac

When you grant Full Disk Access during onboarding, Gather reads ~/Library/Messages/chat.db directly. All of this happens entirely on your Mac:

  • All of your iMessages are read locally so Gather can identify which chats are relevant to the kit you're running.
  • Your Contacts are read locally so people appear by name instead of by phone number.
  • Relationship stats, response-time patterns, and communication scores are computed locally and never leave your device in raw form.
  • Any results displayed inside the app are assembled locally and stored only on your Mac.

The overwhelming majority of your messages are never sent anywhere.

2.

What leaves your Mac, and why

Two categories of data leave your Mac in normal use. Nothing else.

2.1 Anonymized message excerpts — to OpenAI, via our proxy

When you run a Kit, Gather assembles a transcript of the selected conversation and sends it to our API proxy, which forwards it to OpenAI's GPT-4o for analysis. What is sent over the wire:

  • The text of messages from the selected chat for the time window you chose.
  • A system prompt describing what the kit is analyzing — no contact names, phone numbers, or email addresses beyond what appears in the message text itself.
  • Gather applies an identity-redaction pass before sending: phone numbers and email addresses in message bodies are replaced with placeholders.
  • For Inbox Zero photo threads only: when the conversation you are drafting a reply to contains an image, that image is downsized on your Mac and sent (alongside the text) to OpenAI's vision model so the reply can refer to what is in the photo. Photos are never sent for any other kit, and are covered by the same OpenAI retention and no-training terms as text.

Requests go to our proxy at msg-assistant-v0.vercel.app/api/kits/complete. The proxy holds the OpenAI API key server-side and forwards the request — it does not log or persist message content. OpenAI retains data up to 30 days for safety monitoring, then deletes it. They do not use API data to train models.

2.2 Kit results and usage stats — to Supabase

For one-time kits, Gather stores the generated output in our Supabase database so you can replay it later without re-running AI. This row contains a pseudonymous user id, the kit id, the generated text output, and a timestamp. No raw message text, no contact names, no phone numbers.

We also log lightweight usage stats per kit run (kit id, duration, model used, token counts, cost estimate, app version, and error codes if any). These rows contain no message content of any kind.

3.

Authentication and your account

Sign-in uses your email address and Supabase Auth's magic-link / OTP flow. Session tokens are stored locally in the Mac app's renderer process and refreshed automatically. Your email is stored in Supabase Auth for account management only and is not shared with any third party beyond the subprocessors listed in Section 4.

4.

Subprocessors

Three companies see some piece of your data on the way to providing the service:

SubprocessorWhat they seeRetention
OpenAIRedacted message excerpts from the chat you select when running a kitUp to 30 days, then deleted. No model training.
SupabaseAuth (email), pseudonymous user id, one-time kit outputs, usage statsUntil you delete your account
VercelHosts the proxy + web app. IP address + request metadata in access logs; not request bodies.~30 days (Vercel default)

We do not use third-party analytics SDKs, advertising platforms, or trackers. No Facebook pixel, Google Analytics, PostHog, Segment, or similar.

5.

What we explicitly do NOT do

  • We do not sell your data.
  • We do not use your messages to train, fine-tune, or evaluate any model — ours or anyone else's.
  • We do not run third-party analytics or fingerprinting.
  • We do not store credit-card or payment information (Gather is currently free).
  • We do not access any messaging platform other than Apple iMessage on your Mac.
  • We do not upload messages from chats you have not explicitly selected for a kit run.
  • We do not retain raw message content on our servers after a kit run completes.
6.

Your rights and how to use them

  • Access — request a copy of everything we store about you.
  • Deletion — self-serve in the Mac app (Settings → Account → Delete account), or email us.
  • Correction — request that we fix incorrect data.

Delete your Gather account

(1) Self-serve in the Mac app. Settings → Account → Delete account. Immediately removes your auth row, kit outputs, and usage stats. Nothing is recoverable after.

(2) Email us. sesana.allen@gmail.com with subject "Delete my Gather account." We'll process it within 7 days.

You can also locally: quit and uninstall Gather to stop all collection, or revoke Full Disk Access in System Settings → Privacy & Security → Full Disk Access.

7.

Security

  • All network traffic between the Mac app, our proxy, Supabase, and OpenAI uses TLS.
  • Supabase row-level-security restricts each user to reading and writing only their own rows.
  • The OpenAI API key lives only on our proxy server and is never shipped in the Mac binary.
  • If we become aware of a data incident affecting your personal information, we'll notify you promptly.
8.

Data retention

  • On your Mac: locally computed data stays until you uninstall or revoke permissions.
  • At OpenAI: up to 30 days, then deleted.
  • In Supabase: until you request deletion.
  • In Vercel access logs: ~30 days.
9.

Children's privacy

Gather is intended for adults aged 18 and older. We don't knowingly collect data from anyone under 18. If you believe a minor has signed up, email sesana.allen@gmail.com.

10.

Region-specific rights (GDPR / CCPA)

The project is operated from the United States. If you reach us from the EEA, UK, or California, the access / deletion / correction rights in Section 6 apply under GDPR and the CCPA/CPRA. We do not "sell" or "share" personal information as defined under CCPA/CPRA.

11.

Changes to this policy

If this policy changes materially, we'll post a notice on our website and email currently-active users at least 14 days before the change takes effect.

12.

Contact

For anything privacy-related — questions, requests, complaints:

Juliajuliasegal@stanford.eduSesanasesana@stanford.edu

We'll respond within 7 days.

Gather · sesana.allen@gmail.com