Where We Stand Privacy Policy
In short
- Where We Stand keeps your information on your device (and in your own iCloud account) and, for the features described under “What leaves your device”, on our server and with the services listed there.
- No tracking and no ads. Where We Stand doesn’t track you across other companies’ apps or websites and doesn’t show ads.
- No analytics or crash-reporting services are built in.
- No account: you don’t sign in, and we don’t know who you are.
- Purchases are handled by Apple. We never see your payment details.
Who we are
Where We Stand is published by Marketgence Technologies LLC (“we”, “us”). This policy explains what happens to your information when you use Where We Stand on your iPhone or iPad. Questions: support@marketgence.com.
What stays on your device
Where We Stand keeps these on your device, in the app’s own storage that other apps can’t read:
- Your connections, imported conversations, the screenshots you keep, readings, journal entries, agreements, milestones and notes.
- Your settings, your pronouns and the name to avoid.
- Items shared into the app and the widget's moment, in the app's own container on the device.
- A record of how much AI each feature used.
- This install's App Attest key (held by iOS) and its ID, which the app uses with our AI proxy.
- A random purchase identifier and your purchase record, in this device's Keychain.
Like other app data, it may be included in your device backups (iCloud Backup or a computer backup) if you use them.
iCloud. If you turn on iCloud sync, Off until you turn on Settings ▸ Privacy ▸ Sync with iCloud. Then your connections, messages, moments, readings and notes, and the screenshots you keep, are copied to your own private iCloud database (CloudKit) and your other devices, starting the next time the app opens. An install that was already syncing under an earlier version keeps syncing until you turn it off. It’s off unless you turn it on. Only you can read it: it’s kept by Apple under Apple’s Privacy Policy, not by us.
What leaves your device
| What | Why | Sent to | When | Linked to you |
|---|---|---|---|---|
| The conversation text you import, as written, including the other person's messages and any names, numbers or other details in them, marked as yours or theirs, with the time gaps measured on the device | Producing AI readings and the safety screen, and the worded reads and drafts you ask for | Our AI proxy, then the Vercel AI Gateway, then Google (Gemini 2.5 Flash), or OpenAI (GPT-4o mini) if that fails | Only after you turn on cloud AI (the switch on the last onboarding page, or Settings ▸ Drafting & interpretation ▸ Enable AI synthesis). Then after each import you save, once after an update that changes how readings work, and when you use an AI feature. | Yes |
| Your context and notes for that connection (its shape, structure, distance, life circumstances, stated intent and your current question), confirmed notes, agreements and milestones, journal entries and debrief answers used by a read, drafts you ask about, and the AI's earlier notes and findings | Producing AI readings, worded reads and drafts | Our AI proxy, then the Vercel AI Gateway, then Google (Gemini 2.5 Flash), or OpenAI (GPT-4o mini) if that fails | Only after you turn on cloud AI (the switch on the last onboarding page, or Settings ▸ Drafting & interpretation ▸ Enable AI synthesis). Then after each import you save, once after an update that changes how readings work, and when you use an AI feature. | Yes |
| Details that can reveal sexual orientation or sex life: whatever the conversations and your notes say, the relationship structure you set (for example open or polyamorous), and whether a connection is marked as closeted | Producing AI readings that take the relationship's real context into account | Our AI proxy, then the Vercel AI Gateway, then Google (Gemini 2.5 Flash), or OpenAI (GPT-4o mini) if that fails | Only after you turn on cloud AI (the switch on the last onboarding page, or Settings ▸ Drafting & interpretation ▸ Enable AI synthesis). Then after each import you save, once after an update that changes how readings work, and when you use an AI feature. | Yes |
| Health details you record or confirm for a connection: a Health life circumstance, health notes, safer-sex and sexual-health agreements, and sexual-health talk milestones | Producing AI readings that take the relationship's real context into account | Our AI proxy, then the Vercel AI Gateway, then Google (Gemini 2.5 Flash), or OpenAI (GPT-4o mini) if that fails | Only after you turn on cloud AI (the switch on the last onboarding page, or Settings ▸ Drafting & interpretation ▸ Enable AI synthesis). Then after each import you save, once after an update that changes how readings work, and when you use an AI feature. | Yes |
| This install's App Attest key ID, with the key's public key and Apple's attestation receipt | Checking that requests come from the real app on a genuine device, and counting this install's AI requests | Our AI proxy only; it is not passed to the AI gateway or the model providers | When cloud AI is on: once to set up the key, then with every AI request and when Settings shows the monthly allowance | Yes |
| How many AI requests this install made (in total, this minute, today, and this month as free or Pro) and when it last made one | Applying this install's AI limits per minute, per day and per month | Our AI proxy, which counts the requests; the counts are not sent anywhere else | With each AI request while cloud AI is on | Yes |
| If you have Pro: your App Store transaction for the Pro plan, signed by Apple, which the proxy checks | Applying the Pro allowance | Our AI proxy only | With each AI request while you have Pro and cloud AI is on | Yes |
We don’t sell your information, and it isn’t used for advertising.
Our server
Only if you turn on cloud AI. For this install: its App Attest key ID, the key's public key and Apple's attestation receipt, the app version Apple reports, how many AI requests it has made (in total, this minute, today, and this month as free or Pro) and when it last made one. If you have Pro, the proxy can keep the result of checking your App Store transaction: the product, its expiry and a SHA-256 fingerprint of the transaction. The proxy does not store the text you send.
Where it runs: Where We Stand's AI proxy, a Cloudflare Worker we run. How long it’s kept: an install's record is deleted after 180 days without an AI request, and each new request restarts that period. A Pro check result is kept for at most 24 hours, or until the subscription expires if that is sooner.
Services we use
These outside services receive data from Where We Stand to make it work. Each handles that data under its own privacy policy.
- Vercel (AI Gateway)
- Passes each AI request from our proxy to the model provider. What it receives: The request body: conversation text as written, your context and notes for that connection, the journal entries and drafts a feature uses, and the AI's earlier notes and findings. The proxy does not forward your App Attest key ID or App Store transaction. Only when cloud AI is on. Each request asks the gateway for zero data retention and no training on prompts. What Vercel and the providers keep is set by their own terms; see their policies. Privacy policy: vercel.com.
- Google (Gemini)
- Writes the AI readings and worded reads (Gemini 2.5 Flash). What it receives: The same request body, passed on by the Vercel AI Gateway. Only when cloud AI is on. Each request asks for zero data retention and no training on prompts; Google's terms decide what it keeps. See Google's policy. Privacy policy: policies.google.com.
- OpenAI
- Answers instead when Gemini fails (GPT-4o mini), as the gateway's fallback. What it receives: The same request body, passed on by the Vercel AI Gateway. Only when cloud AI is on and Gemini fails. Each request asks for zero data retention and no training on prompts; OpenAI's terms decide what it keeps. See OpenAI's policy. Privacy policy: openai.com.
- Cloudflare (hosting for our AI proxy)
- Runs our AI proxy, which checks App Attest, counts requests and forwards them to the Vercel AI Gateway. What it receives: Every AI request passes through it: the request body, this install's App Attest key ID and, with Pro, your App Store transaction, plus normal request data such as your IP address. Only when cloud AI is on. The proxy keeps only the install record described above and doesn't log request bodies. Cloudflare keeps standard request metrics; see its policy. Privacy policy: cloudflare.com.
- Apple (App Attest)
- Confirms to our proxy that requests come from the real app on a genuine Apple device. What it receives: Handled by iOS between your device and Apple when the app sets up its App Attest key. The first time cloud AI is used on this install. Privacy policy: apple.com.
- Apple (iCloud)
- Syncs your records through your own private iCloud database. What it receives: Your records and the screenshots you keep, stored in your private iCloud database, which Apple keeps for you. Only if you turn on Sync with iCloud. Until you delete them; Delete everything also asks your private iCloud database to delete them. Privacy policy: apple.com.
Artificial intelligence
Where Apple Intelligence is available, some worded reads (decoding a message, boundary scripts, reading panels) are produced by Apple's on-device model. Built-in worded reads is on by default; when cloud AI is on, cloud AI does the deeper reads. This runs on your device with Apple’s on-device model; your text isn’t sent anywhere for it.
Optional cloud AI: readings after each saved import (reading new messages, the safety screen, research readings and a summary), worded reads, drafting help and weekly summaries. It uses Google (Gemini 2.5 Flash) and OpenAI (GPT-4o mini, as a fallback) through our App Attest proxy (a Cloudflare Worker), then the Vercel AI Gateway. It’s off until you choose to use it. When you use it, this is sent: The conversation text as written, including the other person's messages, with your context, notes, agreements and milestones for that connection, journal entries and drafts a feature uses, and the AI's earlier notes and findings. The proxy also receives this install's App Attest key ID and, with Pro, your App Store transaction. The service generates the answer and may keep request records under its own policy. Don’t include anything you wouldn’t want processed this way.
AI-generated text can be wrong or incomplete; see the Terms of Use.
Permissions
Where We Stand asks for these only when you use the feature that needs them. You can change your answer at any time in the Settings app.
| Permission | Why |
|---|---|
| Microphone | To hear a reflection you speak, only while you are recording it. |
| Speech Recognition | To turn spoken reflections into text on your device; the audio is not sent anywhere. |
| Notifications | Optional reminders you turn on: the morning-after debrief, your week, the interrupt, predictions that are due, and the next-date nudge. |
Tracking, ads and analytics
Where We Stand doesn’t track you: it doesn’t link information about you with information from other companies’ apps, websites or data brokers, and it doesn’t use an advertising identifier.
Where We Stand doesn’t show ads.
It has no analytics or crash-reporting services. If you’ve chosen to share analytics with app developers in your iPhone’s settings, Apple may share crash reports with us; Apple doesn’t include your identity.
Accounts
There are no accounts in Where We Stand. You don’t sign in or give us your name or email address.
Purchases
Where We Stand offers auto-renewable subscriptions and one-time purchases through Apple’s App Store. Apple processes the payment and knows what you bought; we don’t receive your name, email address or payment details. The app checks what you’ve bought on your device with Apple’s StoreKit. Apple’s Privacy Policy applies to the purchase.
Children
Where We Stand isn’t directed at children under 13, and we don’t knowingly collect personal information from them. Made for adults using it for dating and relationships; not directed to children. Onboarding asks people to confirm they are adults.
How long data is kept, and deleting it
Information on your device stays until you delete it. You can delete it in the app: Settings ▸ Your data ▸ Delete everything. If sync was on, it also asks your private iCloud database to delete the records. A single connection can be deleted from its reading screen. Deleting Where We Stand removes the information it keeps in its own storage on your device; copies in your backups or your iCloud account remain until you delete those. If you've bought something, a random purchase identifier that the app keeps in the iOS Keychain can stay on the device after the app is deleted, so your purchases can be matched again; it doesn't identify you.
On our server: an install's record is deleted after 180 days without an AI request, and each new request restarts that period. A Pro check result is kept for at most 24 hours, or until the subscription expires if that is sooner. The proxy keeps no content. Delete everything doesn't contact the proxy or reset this install's App Attest key; the proxy deletes the install's record after 180 days without an AI request. Deleting the app removes the key.
Vercel (AI Gateway): Each request asks the gateway for zero data retention and no training on prompts. What Vercel and the providers keep is set by their own terms; see their policies.
Google (Gemini): Each request asks for zero data retention and no training on prompts; Google's terms decide what it keeps. See Google's policy.
OpenAI: Each request asks for zero data retention and no training on prompts; OpenAI's terms decide what it keeps. See OpenAI's policy.
Cloudflare (hosting for our AI proxy): The proxy keeps only the install record described above and doesn't log request bodies. Cloudflare keeps standard request metrics; see its policy.
Apple (iCloud): Until you delete them; Delete everything also asks your private iCloud database to delete them.
Your rights
Depending on where you live (for example in the European Union, the United Kingdom or California), you may have the right to know what information we hold about you, to get a copy, to correct or delete it, and to object to how it’s used. To make a request or a complaint, email support@marketgence.com. You can also contact your local data-protection authority.
Changes to this policy
If we change how Where We Stand handles information, we’ll update this page and its effective date, and list the change below.
- : The app is now Where We Stand and its pages moved to this address. Cloud AI now goes through our App Attest proxy and the Vercel AI Gateway to Google, with OpenAI as a fallback; the earlier relay is gone. iCloud sync is off until you turn it on. The data sent for AI is now listed as linked to you, and sensitive information and health details are added.
- : First version on apps.marketgence.com; replaces the policy at Rork's preview site Corrected: AI text is sent in full, not redacted (the old page said names were replaced with tokens); purchases are checked on your device (older text named RevenueCat); iCloud sync is on by default; Delete everything removes the relay ID from your device only.
Contact
Marketgence Technologies LLC · support@marketgence.com