Privacy
Privacy policy
Last updated: August 24, 2026
Thirdlight is built for conversations most people would only have in a private room. This page says what we keep, what we never keep, who processes it, and the choices you have — in plain terms first, then in full.
In plain words
- Your first session needs no account and no card. A first name — any name you like — is all Elena asks for.
- We never record your voice or video. We do keep a written record of each session — what you said and what Elena said, as text — along with what she writes: your snapshot, session notes, and takeaways. We read those records to run Thirdlight and make the coaching better.
- What you say in your private sessions is never shown, quoted, or summarized to your partner.
- Your conversations are not used to train AI models — not by us, and not by the model providers we use.
- We don’t sell personal information. Our analytics use no cookies. We do run ads, and the one advertising cookie that comes with them is set without asking — the cookie policy says how to refuse it.
- You can ask us for a copy of your data, or ask us to delete it, at any time.
The summary above is a guide. The full text below is the part that governs.
1. Who we are
Thirdlight (“we”, “us”) operates thirdlight.app: coaching for couples, in live voice sessions with Elena, an AI coach. This policy covers the website and the product, for visitors and for account holders.
2. What this policy covers
It covers the personal information we handle when you visit the site, try a session, create an account, invite a partner, or write to us. It does not make Thirdlight a healthcare provider: Elena is an AI coach, coaching is not therapy or medical care, and nothing here creates a clinician relationship. The terms of service say more about that boundary, and the safety page says what to do when something is urgent.
One position runs through the whole policy: everything said in a session is sensitive by default. We treat it that way regardless of which privacy law applies to you.
3. What we collect and store
Before you have an account
You can do a full session with no account. To make that work, starting a session sets one essential cookie — a random identifier that connects your browser to your in-progress session and your snapshot. It expires after 24 hours and is described in the cookie policy. We also store the first name you give (it can be any name you like) and the choices you tap on the way in, which reach us as plain categories: the topic you picked, the weight reading if you gave one. The one free-text line on the start screen goes straight to Elena at the start of your session so she can use it; the line itself is not stored — the conversation’s transcript is.
The ninety seconds with Elena on the home page works the same way and asks for none of that. Pressing it sets the same 24-hour cookie and nothing else: no name, no topic, no weight reading, and no session record. What you say to her in it is a conversation, so everything in the next paragraph applies to it exactly as written.
The session itself
A session is a live voice conversation. Your audio is streamed and processed in real time so Elena can hear you and answer, and the audio itself is never recorded or saved — nobody can replay the sound of your session, because no recording of it exists. What we keep is the written record: a text transcript of the conversation — what you said and what Elena said, turn by turn — stored with the session. We read transcripts to operate Thirdlight, to review the quality of her coaching, and to improve it. They are never shown to your partner, never sold, and never used to train AI models.
We also store what Elena writes: your couple snapshot, the note from each session, takeaways, and the week’s move. Those artifacts are the product’s memory — when she remembers your history, she is reading her own notes back.
Notes, and who can read them
Every stored note carries a scope, enforced where the data is read: private to you, shared with your partner, or coach-private — working notes Elena keeps to steer, shown to neither of you. Anything private to you is never returned to your partner’s account, and the shared space holds only what you both attended or one of you explicitly chose to share. Section 7 describes this in full.
Accounts and couples
Accounts run on Clerk, our sign-in provider. When you sign up we handle your email address, your name, and your sign-in method (email or Google); Clerk holds the credentials. A couple record links the two accounts and their status. When you invite your partner, the invitation message and any letter you write for them are stored so they can read them — that is the one place your own written words are kept, because delivering them is the point.
Scheduling
If you book a standing slot or a check-in we store the booking and a ledger of the reminders we sent. The hour you pick is never sent to analytics.
Payments
When paid subscriptions open, payment runs on Stripe. Card details go to Stripe directly and never touch our servers; we keep a mirror of your subscription status (active, paused, canceled) so the product knows what to show you.
We send transactional email — invitations you ask us to deliver, session notes, reminders, receipts — through Resend. If you join the waitlist, we store that email address to write to you when there is something to say.
Analytics
We count named product steps — a session started, a note viewed, an invite accepted — using PostHog, with properties that are categories, numbers, or booleans. Autocapture is off, session replay is off, page-view tracking is off, and the analytics set no cookies and keep no identifier between visits. Nothing you said, typed, or wrote appears in any event. Calls to AI models are logged as metadata only: which model, how long it took, how many tokens — never the words in or out.
Server logs
Operational logs are metadata: identifiers, timings, status codes. No conversation content, no snapshot text, and no names go into logs.
4. What we deliberately do not keep
The short inventory of what does not exist on our systems:
- No recordings of your voice, and no video of you.
- The free-text line from the start screen — it reaches Elena live and is stored nowhere.
- No check-in answers — those are scored in your browser, and only the final score reaches us.
- No card numbers. Stripe holds those.
- No advertising identifier that carries anything you said. The one we do set records that an ad brought you here, and nothing more.
- No session replays or screen recordings of you using the site.
5. How we use what we have
- To run the session you asked for, live.
- To write and show you the artifacts — snapshot, notes, takeaways — and to let Elena carry your history from one session to the next.
- To deliver invitations you ask us to send, and to link a couple.
- To send reminders you set and receipts you are owed.
- To bill subscriptions, once billing is open.
- To keep the product working: rate limits, one live room per person, fraud and abuse prevention.
- To understand the product in aggregate, from anonymous counts.
- To meet legal obligations.
Not on the list, because it does not happen: selling data, and training models on your conversations. We do advertise, and we count which ads led to an account or a session — a number, not a person, and never a word of what was said. We do not ask permission before setting the cookie that makes that count possible; the cookie policy says plainly what it is and how to refuse it.
6. AI, and what it is not trained on
Elena runs on AI models from the providers listed in section 8. Your conversation is processed by them in real time to hold her side of it, and the written artifacts are drafted by text models the same way. This processing happens over business API agreements under which the content is used to provide the service — we do not use your conversations to train models, and the providers we use do not train theirs on this API traffic either.
Her memory of you is not in a model. It lives in her written notes, in your account, where you can read every word of it.
7. Confidentiality between the two of you
Thirdlight is used by two people who trust it separately, so the wall between your accounts matters as much as the wall around them.
- Anything from a session or check-in you had on your own is never shown, quoted, or summarized to your partner, and never appears in the shared space.
- Elena may use her understanding of what you told her privately to steer a joint conversation — without revealing what you said, or that you said anything at all.
- What you both see: notes from sessions you both attended, the week’s move, your couple snapshot, and anything one of you explicitly shared. That is the whole list.
- Paying for the subscription grants no access. The partner who pays sees nothing of the other’s private space.
- The one limit: if Elena believes someone is in danger, she says so plainly and points to human help. See the safety page.
8. Who processes data for us
We run on a small set of service providers. Each processes data to provide its function, under a data-processing agreement, and none of them may use your data for their own purposes.
| Provider | Role | What reaches them |
|---|---|---|
| Railway | Hosting and databases | Everything the product stores, on infrastructure in the United States. |
| LiveKit | Real-time session audio | Your voice during a live session, in transit. Not recorded. |
| xAI | The voice model behind Elena | The conversation, processed in real time to generate her side of it. |
| OpenRouter | Text models for written artifacts | The working material for a snapshot or takeaways, at the moment it is written. We restrict this to model hosts in the United States that do not train on it. |
| Spatius | Elena’s on-screen presence | Her own voice and appearance, animated live in the session room. |
| Clerk | Accounts and sign-in | Your email, name, and sign-in method. |
| Resend | Email delivery | The address and content of emails we send you, or send for you. |
| PostHog | Product analytics | Anonymous event names and properties; model-call metadata. Never content. |
| Stripe (when subscriptions open) | Payments | Payment details, entered on and held by Stripe’s own systems. |
| Cloudflare | Domain and DNS | Network routing for reaching the site. |
| Google Ads | Advertising measurement | That a visit followed one of our ads, and that it reached a step such as an account being created. Set on your first page view, without asking. Nothing from a session, and no name. |
Beyond these providers: we do not sell personal information. We do share the advertising signal described in the last row with Google, which is what “sharing for advertising” means under some US state laws — the cookie policy says how to stop it. If the law compels disclosure, we disclose the minimum required and tell you unless we are legally barred from doing so — and the most sensitive thing, the conversation itself, is not in our possession to hand over. If Thirdlight is ever acquired or merged, this policy’s commitments travel with the data, and we would tell you before anything changed.
9. Legal bases (EEA and UK)
Where GDPR-style law applies, we rely on:
- Contract — running sessions, accounts, invitations, scheduling, and billing you asked for.
- Legitimate interests — keeping the service secure and understanding it through anonymous, content-free analytics.
- Consent — where we ask for it, such as your browser’s microphone permission before a session.
- Legal obligation — records we must keep, such as billing records.
10. Where data lives
We operate from the United States and our providers process data there. If you use Thirdlight from elsewhere, your information comes to the US. For transfers from the EEA, UK, and Switzerland, our providers’ data-processing agreements include recognized safeguards such as standard contractual clauses.
11. How long we keep things
- Session audio — never kept at all.
- Session transcripts — kept as part of your session record for as long as we keep the session itself. Ask us and we delete them.
- The visitor cookie — expires after 24 hours.
- Artifacts from a session without an account — held under that anonymous identifier so you can claim them if you sign up. Ask us and we delete them.
- Your snapshot, notes, and takeaways — kept while you keep them. Canceling a subscription never deletes them: your notebook stays readable after you cancel, by design. Deleting your account, or asking us to delete, removes them.
- Account and couple records — for as long as the account exists.
- Waitlist email — until we have written to you and you no longer want to hear from us, or you ask sooner.
- Billing records — as long as tax and accounting law requires, once billing is open.
- Analytics events — kept as anonymous aggregates with nothing in them that identifies you.
12. Your rights and choices
Wherever you live, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Depending on your jurisdiction — including the EEA, UK, California and other US states — you may also have rights to portability, to object to or restrict certain processing, and to complain to your local supervisory authority. We do not sell personal information. We do share for cross-context behavioral advertising, in the narrow sense that our Google advertising cookie lets Google connect your visit to its own advertising profile of you. You can opt out of that at any time, and without asking us: clear or block the cookie in your browser, or turn off personalised advertising across Google in My Ad Center. Both routes are spelled out in the cookie policy. Visitors in the EEA, the UK and Switzerland are opted out already — the tag runs with advertising storage off there and sets no such cookie. We will never treat you differently for exercising a right.
To exercise any of them, write to leland@thirdlight.app — section 17 is the whole of what you need. We verify any such request against the email on the account. One honest note on couples: deletion covers your account, your private notes, and your contributions to the shared space. Notes Elena wrote for sessions you both attended belong to both of you, and your partner keeps their access to those.
13. Security
- Everything moves over encrypted connections.
- Anonymous sessions hang off long random identifiers that cannot be guessed or enumerated.
- The privacy scopes on notes are enforced in the data layer itself, not left to individual screens to get right.
- Conversation content is kept out of logs entirely.
- The deepest control is structural: the conversation itself is never stored, so it cannot leak from storage.
14. Age
Thirdlight is for adults. You must be 18 or older to use it, and we do not knowingly collect information from anyone younger. If we learn we have, we delete it.
15. If someone is in danger
Elena is a coach, and safety comes before coaching: if she believes someone is in danger, she says so plainly and points to human help. She cannot call anyone on your behalf, and sessions are not monitored by people. The safety page lists who to contact when something cannot wait.
16. Changes to this policy
When this policy changes, we update it here and change the date at the top. If a change is material — new data, new uses, new recipients — we tell account holders by email before it takes effect.
17. How to reach us
Write to leland@thirdlight.app about anything on this page: a question, a request to see, correct, export or delete what we hold about you, or a complaint. That address reaches a person at Thirdlight rather than a queue, and it is the same address published on the terms and the about page. We answer requests about personal data as quickly as we can, and within the time your local law allows. You also have the right to complain to your local supervisory authority instead of, or as well as, writing to us.
Thirdlight is not an emergency service, and this mailbox is not monitored for emergencies. If you or someone you love may be in danger, call your local emergency number — the safety page lists crisis lines by country.