Privacy Policy
Last updated: July 26, 2026
1. Introduction
ReadBeneath (“we,” “us,” “our”) operates the ReadBeneath platform, an in-depth relationship analysis service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
2. Information We Collect
Account Information
When you create an account, we collect your email address and, if you register with a password, a securely hashed version of your password. If you sign in via Google OAuth, we receive your email address and Google account identifier. We do not store your Google password.
Conversation Data
When you upload chat exports for analysis, we process the message content to generate your report. All data moves over encrypted connections (TLS). The raw files you upload are removed from temporary storage once processing finishes. The parsed conversation and generated analysis are retained so your report and cited-message previews keep working. Retained conversation content and analysis are protected with application-level encryption at rest using AES-256-GCM and a distinct data key for each conversation. Our backend decrypts that content only when needed to analyse or serve your report. This is not end-to-end encryption: ReadBeneath has to decrypt and read the conversation to provide the service. We do not sell your conversation data, use it for advertising, or use it to train AI models.
Payment Data
Payments are processed by Stripe. We store your Stripe customer ID and subscription status but never store credit card numbers, CVVs, or full payment details on our servers.
Usage Data
We collect limited service-activity and product-analytics events (for example, feature usage and reliability signals). Some events are linked to your account so we can operate the service and include them in your data export. They do not contain conversation content or personal messages.
3. How We Use Your Information
- To provide, maintain, and improve our services
- To process payments and manage subscriptions
- To generate AI-powered relationship analysis reports
- To communicate with you about your account or service updates
- To detect and prevent fraud, abuse, or security incidents
4. Data Sharing
We do not sell your personal data. We share data only with the following categories of service providers, under strict contractual obligations:
- AI Processing:OpenAI (for analysis generation). Before any message is sent, we mask personal identifiers in the content — email addresses, phone numbers, street addresses, and card/ID numbers. Participants' first names are kept, because the analysis has to attribute patterns to the right speaker. No account details (your email, password, or payment information) are ever shared with OpenAI.
- Payment Processing: Stripe (for subscription and payment handling).
- Product Analytics: PostHog (feature-usage events only, and only if you accept analytics cookies). Events never contain message content.
- Error Monitoring: Sentry (technical error reports so we can fix failures). Reports are scrubbed of message content.
- Infrastructure: Cloud hosting providers for database and application hosting.
5. Data Retention
- Uploaded files: Removed from temporary storage after processing completes, with a 24-hour fallback expiry if processing does not finish normally.
- Parsed conversations: Retained in our database to serve your report and cited-message previews, until you delete the conversation or your account.
- Analysis reports: Retained for 30 days in cache, then served from the database as long as your account exists.
- Account data: Retained until you delete your account.
6. Your Rights
You have the right to:
- Access & portability:Download a portable copy of your retained account and product data as a JSON file from Settings → Privacy & data.
- Deletion:Delete your account and all associated data at any time from Settings → Privacy & data.
- Correction: Update your account information.
- Objection: Object to processing of your personal data.
To make a broader access request, exercise another privacy right, or get help with the self-service tools, contact us at privacy@readbeneath.com.
7. Security
We use TLS encryption in transit and application-level encryption at rest for retained conversation content and generated analysis. Each conversation has a distinct encrypted data key; versioned master keys remain in the backend environment and are not sent to your browser. This is not end-to-end encryption because our backend must decrypt the content to analyse it and serve your report. We also use bcrypt password hashing, JWT authentication, rate limiting, input validation, and role-based access controls. No method of transmission or storage is 100% secure, but we take reasonable steps to protect your data.
8. Cookies
We use essential cookies and local storage for authentication (JWT tokens) and session management. We do not use third-party tracking cookies or advertising cookies.
9. Children's Privacy
Our service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a minor, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised “Last updated” date.
11. Contact Us
If you have questions about this Privacy Policy, contact us at privacy@readbeneath.com.