Privacy

Privacy policy

Last updated: August 5, 2026

Thirdlight is built for conversations most people would only have in a private room. This page says what we keep, what we never keep, who processes it, and the choices you have — in plain terms first, then in full.

In plain words

  • Your first session needs no account and no card. A first name — any name you like — is all Elena asks for.
  • We don’t record your sessions and we don’t store transcripts of them. What we keep is what Elena writes: your snapshot, session notes, and takeaways.
  • What you say in your private sessions is never shown, quoted, or summarized to your partner.
  • Your conversations are not used to train AI models — not by us, and not by the model providers we use.
  • We don’t sell personal information. There are no advertising trackers here, and our analytics use no cookies.
  • You can ask us for a copy of your data, or ask us to delete it, at any time.

The summary above is a guide. The full text below is the part that governs.

1. Who we are

Thirdlight (“we”, “us”) operates thirdlight.app: coaching for couples, in live voice sessions with Elena, an AI coach. This policy covers the website and the product, for visitors and for account holders.

Company details — being finalized
  • Operating entity: [Entity name and legal form — founder to confirm]
  • Registered address: [Business address — founder to confirm]
  • Governing law and venue: [State or country — founder to confirm with counsel]
  • Contact for privacy requests and legal notices: [Dedicated mailbox — founder to confirm. Until it exists, the email channel already in use for the product is the interim route.]

2. What this policy covers

It covers the personal information we handle when you visit the site, try a session, create an account, invite a partner, or write to us. It does not make Thirdlight a healthcare provider: Elena is an AI coach, coaching is not therapy or medical care, and nothing here creates a clinician relationship. The terms of service say more about that boundary, and the safety page says what to do when something is urgent.

One position runs through the whole policy: everything said in a session is sensitive by default. We treat it that way regardless of which privacy law applies to you.

3. What we collect and store

Before you have an account

You can do a full session with no account. To make that work, starting a session sets one essential cookie — a random identifier that connects your browser to your in-progress session and your snapshot. It expires after 24 hours and is described in the cookie policy. We also store the first name you give (it can be any name you like) and the choices you tap on the way in, which reach us as plain categories: the topic you picked, the weight reading if you gave one. The one free-text line on the start screen is different — it never leaves your browser, and no server of ours ever sees it.

The session itself

A session is a live voice conversation. Your audio is streamed and processed in real time so Elena can hear you and answer — and that is the whole life of it. We do not record your voice, we do not save audio files, and we do not store transcripts of what was said. At the end of a session, a working summary is used once to write your snapshot and is not kept. Nobody at Thirdlight can replay your session, because no recording of it exists.

What we do store is what Elena writes: your couple snapshot, the note from each session, takeaways, and the week’s move. Those artifacts are the product’s memory — when she remembers your history, she is reading her own notes back, not consulting a recording.

Notes, and who can read them

Every stored note carries a scope, enforced where the data is read: private to you, shared with your partner, or coach-private — working notes Elena keeps to steer, shown to neither of you. Anything private to you is never returned to your partner’s account, and the shared space holds only what you both attended or one of you explicitly chose to share. Section 7 describes this in full.

Accounts and couples

Accounts run on Clerk, our sign-in provider. When you sign up we handle your email address, your name, and your sign-in method (email or Google); Clerk holds the credentials. A couple record links the two accounts and their status. When you invite your partner, the invitation message and any letter you write for them are stored so they can read them — that is the one place your own written words are kept, because delivering them is the point.

Scheduling

If you book a standing slot or a check-in we store the booking and a ledger of the reminders we sent. The hour you pick is never sent to analytics.

Payments

When paid subscriptions open, payment runs on Stripe. Card details go to Stripe directly and never touch our servers; we keep a mirror of your subscription status (active, paused, canceled) so the product knows what to show you.

Email

We send transactional email — invitations you ask us to deliver, session notes, reminders, receipts — through Resend. If you join the waitlist, we store that email address to write to you when there is something to say.

Analytics

We count named product steps — a session started, a note viewed, an invite accepted — using PostHog, with properties that are categories, numbers, or booleans. Autocapture is off, session replay is off, page-view tracking is off, and the analytics set no cookies and keep no identifier between visits. Nothing you said, typed, or wrote appears in any event. Calls to AI models are logged as metadata only: which model, how long it took, how many tokens — never the words in or out.

Server logs

Operational logs are metadata: identifiers, timings, status codes. No conversation content, no snapshot text, and no names go into logs.

4. What we deliberately do not keep

The short inventory of what does not exist on our systems:

  • No recordings of your voice, and no video of you.
  • No transcripts of any session or check-in.
  • The free-text line from the start screen — it never arrives.
  • No card numbers. Stripe holds those.
  • No advertising identifiers, pixels, or third-party trackers.
  • No session replays or screen recordings of you using the site.

5. How we use what we have

  • To run the session you asked for, live.
  • To write and show you the artifacts — snapshot, notes, takeaways — and to let Elena carry your history from one session to the next.
  • To deliver invitations you ask us to send, and to link a couple.
  • To send reminders you set and receipts you are owed.
  • To bill subscriptions, once billing is open.
  • To keep the product working: rate limits, one live room per person, fraud and abuse prevention.
  • To understand the product in aggregate, from anonymous counts.
  • To meet legal obligations.

Not on the list, because it does not happen: advertising, selling data, and training models on your conversations.

6. AI, and what it is not trained on

Elena runs on AI models from the providers listed in section 8. Your conversation is processed by them in real time to hold her side of it, and the written artifacts are drafted by text models the same way. This processing happens over business API agreements under which the content is used to provide the service — we do not use your conversations to train models, and the providers we use do not train theirs on this API traffic either.

Her memory of you is not in a model. It lives in her written notes, in your account, where you can read every word of it.

7. Confidentiality between the two of you

Thirdlight is used by two people who trust it separately, so the wall between your accounts matters as much as the wall around them.

  • Anything from a session or check-in you had on your own is never shown, quoted, or summarized to your partner, and never appears in the shared space.
  • Elena may use her understanding of what you told her privately to steer a joint conversation — without revealing what you said, or that you said anything at all.
  • What you both see: notes from sessions you both attended, the week’s move, your couple snapshot, and anything one of you explicitly shared. That is the whole list.
  • Paying for the subscription grants no access. The partner who pays sees nothing of the other’s private space.
  • The one limit: if Elena believes someone is in danger, she says so plainly and points to human help. See the safety page.

8. Who processes data for us

We run on a small set of service providers. Each processes data to provide its function, under a data-processing agreement, and none of them may use your data for their own purposes.

Service providers and what reaches them
ProviderRoleWhat reaches them
RailwayHosting and databasesEverything the product stores, on infrastructure in the United States.
LiveKitReal-time session audioYour voice during a live session, in transit. Not recorded.
xAIThe voice model behind ElenaThe conversation, processed in real time to generate her side of it.
OpenRouterText models for written artifactsThe working material for a snapshot or takeaways, at the moment it is written.
SpatiusElena’s on-screen presenceHer own voice and appearance, animated live in the session room.
ClerkAccounts and sign-inYour email, name, and sign-in method.
ResendEmail deliveryThe address and content of emails we send you, or send for you.
PostHogProduct analyticsAnonymous event names and properties; model-call metadata. Never content.
Stripe (when subscriptions open)PaymentsPayment details, entered on and held by Stripe’s own systems.
CloudflareDomain and DNSNetwork routing for reaching the site.

Beyond these providers: we do not sell personal information and we do not share it for advertising. If the law compels disclosure, we disclose the minimum required and tell you unless we are legally barred from doing so — and the most sensitive thing, the conversation itself, is not in our possession to hand over. If Thirdlight is ever acquired or merged, this policy’s commitments travel with the data, and we would tell you before anything changed.

Where GDPR-style law applies, we rely on:

  • Contract — running sessions, accounts, invitations, scheduling, and billing you asked for.
  • Legitimate interests — keeping the service secure and understanding it through anonymous, content-free analytics.
  • Consent — where we ask for it, such as your browser’s microphone permission before a session.
  • Legal obligation — records we must keep, such as billing records.

10. Where data lives

We operate from the United States and our providers process data there. If you use Thirdlight from elsewhere, your information comes to the US. For transfers from the EEA, UK, and Switzerland, our providers’ data-processing agreements include recognized safeguards such as standard contractual clauses.

11. How long we keep things

  • Session audio and transcripts — not kept at all.
  • The visitor cookie — expires after 24 hours.
  • Artifacts from a session without an account — held under that anonymous identifier so you can claim them if you sign up. Ask us and we delete them.
  • Your snapshot, notes, and takeaways — kept while you keep them. Canceling a subscription never deletes them: your notebook stays readable after you cancel, by design. Deleting your account, or asking us to delete, removes them.
  • Account and couple records — for as long as the account exists.
  • Waitlist email — until we have written to you and you no longer want to hear from us, or you ask sooner.
  • Billing records — as long as tax and accounting law requires, once billing is open.
  • Analytics events — kept as anonymous aggregates with nothing in them that identifies you.

12. Your rights and choices

Wherever you live, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Depending on your jurisdiction — including the EEA, UK, California and other US states — you may also have rights to portability, to object to or restrict certain processing, and to complain to your local supervisory authority. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of, and we will never treat you differently for exercising a right.

To exercise any of these, contact us using the details in the company block in section 1. We verify requests against the email on the account. One honest note on couples: deletion covers your account, your private notes, and your contributions to the shared space. Notes Elena wrote for sessions you both attended belong to both of you, and your partner keeps their access to those.

13. Security

  • Everything moves over encrypted connections.
  • Anonymous sessions hang off long random identifiers that cannot be guessed or enumerated.
  • The privacy scopes on notes are enforced in the data layer itself, not left to individual screens to get right.
  • Conversation content is kept out of logs entirely.
  • The deepest control is structural: the conversation itself is never stored, so it cannot leak from storage.

14. Age

Thirdlight is for adults. You must be 18 or older to use it, and we do not knowingly collect information from anyone younger. If we learn we have, we delete it.

15. If someone is in danger

Elena is a coach, and safety comes before coaching: if she believes someone is in danger, she says so plainly and points to human help. She cannot call anyone on your behalf, and sessions are not monitored by people. The safety page lists who to contact when something cannot wait.

16. Changes to this policy

When this policy changes, we update it here and change the date at the top. If a change is material — new data, new uses, new recipients — we tell account holders by email before it takes effect.

17. Contact

Questions, requests, and complaints go to the contact in the company block in section 1. When the dedicated privacy mailbox is live, it will be listed there.