Touchstone Privacy Policy
Touchstone is a private place to make sense of your dating life. Because what you write here is personal, we've tried to make this policy unusually plain and honest — it describes what Touchstone actually does, in real language. If anything below is ever unclear, email us at privacy@pathoz.com.
This policy covers the Touchstone iOS and Android apps and the
Touchstone website (including the no-install pages friends open to read
something you've shared, the hosted Friend Consensus room, and pathoz.com).
Sharing a view with a therapist is covered by a separate
Therapist Dashboard Privacy Notice.
Touchstone is for adults 18 and older who live in the United States.
1. The short version
We know you may be reading this at a hard moment, so here's the honest summary. If it ever conflicts with the detail below, the detailed sections govern.
- Your diary is private by default. What you write lives in your private vault, in our database, locked to your account. Nothing leaves it unless you choose to share it.
- A few Touchstone staff can access diary content — only for customer support, safety review, or operating the service, only in specific roles (never marketing), and every access is logged. We won't pretend otherwise.
- Sage is powered by a cloud AI. To reflect your patterns, the words you write are sent to a contracted AI provider — without your name, email, or account attached, so it isn't stored there in your name. The AI never trains on your words. This means your diary is not end-to-end encrypted and not processed only on your device; we'll never claim otherwise.
- We show no ads, and we don't track you across other apps or websites.
- You can export everything (in a file you encrypt with your own password) and delete everything, anytime — from Settings, in a few taps.
- Sharing is always your choice. Friends see only the curated view you pick — never your whole diary.
- Some of what you write may reveal especially sensitive information (about your sex life, health, or beliefs). We treat it as a special category and ask for your explicit, in-app consent before processing it.
2. What we collect
We collect only what we need to run Touchstone. The labels in parentheses match the data types Apple and Google use in their app-store privacy disclosures.
Account and identity. Your email address and display name (Contact Info); your password, stored only as a secure hash we can't read, and your sign-in tokens (Identifiers); and an account/device identifier we use to operate the service (Identifiers).
Your diary — the sensitive core. Everything you write, plus its automatic classification into relationship dimensions, life domains, and feelings, and your conversation history with Sage (User Content and Sensitive Info). If you speak an entry, the audio is transcribed to text on your device — we don't store voice recordings and we don't collect any biometric or voiceprint data.
Friend Consensus. The contact details you enter for friends you invite (Contacts/Contact Info); the curated summary you choose to share; and your friends' votes and written responses on it (User Content).
Billing. Your subscription status and transaction records, handled through Apple and Google app-store billing — we never receive or store your full card number (Purchases / Financial Info).
Analytics and stability. Behavioral event metadata (such as "installed," "logged an entry," "subscribed"), anonymized geolocation at the country/region level, your IP address (which our analytics provider automatically anonymizes), and crash/diagnostic logs (Usage Data / Diagnostics). None of this includes the content of what you write (see §6).
Our website. If you join the waitlist, your email (Contact Info); and standard cookies and any comments on pathoz.com (Identifiers / Contact Info).
3. Your data, the AI's data, and who can see your diary
Please read this section before you write your first entry. It's the most important one.
Two different places hold your information
(1) Your diary, in our database. Everything you write is stored in our database, encrypted, and locked to your account login. This is the record that is yours — searchable, exportable, and deletable by you (§8). It is stored in the United States, and the broader Touchstone community never sees it.
(2) The words Sage sends to a cloud AI. To reflect your patterns, Sage sends the relevant text to a contracted third-party AI provider. We send it without your name, email, or account identifier, under a single application key — so on the provider's side the content is not scoped to you or to any individual user, and the provider cannot tie it to you. Our contracts require the provider not to train on it and not to keep it beyond a short window (it is automatically deleted within 60 days).
What this honestly means:
- Touchstone is not "end-to-end encrypted," not "zero-knowledge," and not processed only on your device.
- The AI never trains on your content, and we never attach your identity to what we send it.
- We send only the context Sage needs for a given reflection — not your whole archive where we can avoid it.
- Because the words you write are your own, they may themselves mention people or places. So the protection is that we don't attach your identity and the provider can't scope the content to a user — not a claim that free text could never describe anyone.
- Your diary is never used for advertising, sold, or shared with ad networks (§6).
Who at Touchstone can access your diary
We won't pretend no one at Touchstone can ever see your entries — that would be untrue. In limited circumstances, specific Touchstone staff can access diary content to:
- help you when you contact support (with only the context needed to help);
- keep people safe — for example, a trust-and-safety review when there is a credible risk of harm, or a legal obligation; and
- operate and fix the service — debugging, data integrity, and security investigations.
We hold this access to a tight standard: it is role-based (only roles like support and trust-and-safety can reach diary content — marketing cannot), every access is logged with a timestamp, and staff see only what the task requires. Beyond these internal roles, the only people who ever see your diary are those you deliberately share it with — your friends (§5) and, if you choose, your therapist.
4. How we use your information
- To run Touchstone for you — your diary, its classification, your trends and history, and your account.
- To power Sage's reflections — with your explicit consent, since your diary can include sensitive details (§3).
- To run Friend Consensus and deliver the shares you choose to send.
- To manage your subscription and payments.
- To understand and improve the product — through privacy-preserving analytics that never see your diary (§6).
- To keep Touchstone secure and prevent fraud and abuse.
- To send you service messages, and — only if you opt in — occasional product email.
We are a United States service, and we apply strong data-protection practices as a matter of policy regardless of where you live.
5. Sharing with friends
What your friends see
When you share an entry or convene a Friend Consensus panel, your friends see only the curated summary you opt in — never your full diary, never your archive. You preview exactly what each friend will see first. Sage may add neutral context you've approved, then steps out before any vote and never votes — the result is your friends' read, shown as plain counts ("4 of your 6 friends…"), never an algorithm's judgment.
No account needed to read or vote
A friend can open your share and respond without installing the app or creating an account — we don't make your friends move into our app. An account is needed only if a friend decides to start her own diary.
Because there's no login on these pages, access works through a private, unguessable, single-use link — so treat the link like a key. Each friend gets their own link, you can revoke any friend's access instantly, and links are time-limited and stop working when you close the panel or delete the entry. When you create a panel room, you can require each friend to confirm entry with a one-time code sent to the contact you invited — so the room can't simply be forwarded to someone you didn't choose.
The contact details you enter for a friend are used only to deliver your invitation and to power that optional confirmation and your ability to revoke access. They are never added to marketing lists or shared with advertising tools, and are kept only briefly. A friend can decline, and can ask us to delete their contact details (§8).
6. Advertising and analytics
- We show no ads, and we do not track you across other apps or websites. There is no in-app advertising, and we have turned off our analytics provider's advertising-identifier collection — so there's no ad-tracking prompt, and on Apple's privacy labels this is "Data Not Used to Track You."
- We use Google Firebase Analytics to understand and improve the product — and your diary is walled off from it. Firebase receives behavioral event metadata (such as "installed" or "logged an entry") and anonymized geolocation, and automatically anonymizes IP addresses. It never receives your diary content, your Sage conversations, your classifications, or the content of any share.
- When we run ads on other platforms to tell people Touchstone exists, we measure them with privacy-preserving methods built into Apple (SKAdNetwork) and Google Play (install referrer) that report results in aggregate without identifying you across apps.
For California residents: we do not sell or share your personal information for cross-context behavioral advertising, so there is no "sale" or "share" to opt out of. We honor Global Privacy Control signals on our website.
7. Who processes your data
We share data only with service providers under contract, each bound by data-protection terms. We do not sell your personal information, and no advertising networks are involved.
| Provider | What they handle |
|---|---|
| A contracted AI provider | The de-identified text Sage sends for reflection (§3) — no account identity attached; no training on your content; deleted within 60 days. The provider's name and terms are available to a regulator or auditor on request. |
| Google Firebase Analytics | Behavioral event metadata and anonymized location — advertising-identifier collection disabled; no diary content. |
| Apple & Google app-store billing | Subscription status and transactions; we never receive your full card number. |
| An email/SMS provider | Sending friend invitations and one-time entry codes. |
| A crash/diagnostics provider | App stability logs. |
| Our website host (WordPress / Gravatar) | Operating pathoz.com. |
8. Your choices and rights
| What you can do | How |
|---|---|
| Export everything | Settings → Export. You download a complete copy in a file you encrypt with a password you choose — only you can open it. We surface this option from your very first entry; it's never buried. |
| Delete everything | Settings → Delete account (also on your account page on the web). This erases your vault, your Sage history, and your shared panels, and closes any curated shares you sent. |
| Manage or revoke sharing | In the app — see who has access to each share and revoke any friend instantly. |
| Access or correct your data | Email privacy@pathoz.com. We verify your identity and respond within 45 days (we'll tell you if we need the short extension the law allows). |
| Appeal a decision | Email privacy@pathoz.com with the subject "Privacy appeal." If we decline a request, you may appeal, and we'll respond within the time your state requires. |
| Control notifications and consent | In the app — toggle reminders, manage product email, and withdraw consent for optional analytics. |
About deletion and the AI: when you delete, we erase your data from our database (within 30 days, including from backups as they cycle) and stop sending your content to the AI provider. Anything the provider briefly held was never stored under your name and is automatically deleted within 60 days.
If you're an invited friend (not a Touchstone user): you can decline an invitation and ask us to delete the contact details a user entered for you — email privacy@pathoz.com.
Some of these rights are guaranteed by law where you live (for example in California, Virginia, Colorado, and Connecticut); we extend the core ones to all of our users as a matter of policy, and we won't discriminate against you for using them.
9. Children
Touchstone is for adults 18 and older, and we enforce an 18+ age check at sign-up. We don't knowingly collect information from anyone under 18; if we learn that we have, we delete it. Touchstone is a sensitive-category service and is never directed to children.
10. Where Touchstone is offered
Touchstone is offered only to residents of the United States, is operated from the United States, and stores your diary in the United States. Our apps are distributed only through the U.S. App Store and U.S. Google Play. We don't target or knowingly offer the service to people in the EU, EEA, or UK; if you reach our website from outside the United States, please don't create an account or enter personal information.
11. How long we keep things
| Data | How long |
|---|---|
| Account and diary content | For the life of your account; permanently deleted within 30 days of an account-deletion request, including from backups as they cycle. |
| Content sent to the AI provider | Automatically deleted within 60 days; never stored under your name; never used for training. |
| Friend-invitation contact details | Deleted when a panel ends, or within 30 days of an invitation that isn't accepted. |
| Curated shares with friends | Until you revoke or delete them. |
| Subscription and transaction records | As long as tax and financial law requires (typically up to 7 years). |
| Analytics events | Up to about 14 months; deleted when you delete your account. |
| Crash, diagnostic, and security logs | 90 days. |
| Staff-access logs (who accessed diary data, and when) | 2 years, for accountability. |
12. Security and breach notification
We protect your information with encryption in transit and at rest, role-based access controls (with logged staff access — §3), and a private-vault design in which your diary is never exposed to the broader community. No system is perfectly secure.
If a breach affects your personal information, we will notify affected users and any required authorities without undue delay after confirming it, and tell you what happened, what was affected, and what you can do — consistent with applicable U.S. state breach-notification laws.
13. Your consent, in the app
Before we process your sensitive diary content, and before certain shares, Touchstone asks for your consent inside the app, in plain language — not buried in this policy. You'll see a clear explanation at the moment it matters (for example, before your first entry, and before you share with a therapist), and declining is always a safe, equally available choice.
14. Our commitment to honest disclosure
We hold ourselves to a simple standard: this policy describes what Touchstone actually does — no more, no less. We don't make privacy or security claims we can't keep, and we don't use a feature in a way this policy doesn't disclose. That's why we're deliberately specific here — for example, that Sage uses a cloud AI and your diary is not end-to-end encrypted, and that a few staff in specific roles can access diary content for support and safety. If our practices change, we update this policy first.
15. Changes to this policy
We may update this policy as Touchstone evolves. For material changes — especially anything affecting your sensitive diary content or how the AI processes it — we'll notify you in the app and/or by email before the change takes effect, and ask for fresh consent where it's needed. The "Last updated" date at the top always reflects the current version, and we keep prior versions available on request.
16. Contact us
Questions or requests about your privacy:
Email: privacy@pathoz.com
Mail:
Pathoz LLC
3300 Laguna Dr.
Austin, TX 78741