Dyad is an invite-only private alpha. This policy explains, in plain language, what we collect, why, who else touches it, and what happens if you leave. Where the plain-language version and the legal version might disagree, this document is the legally binding one. That said, we’ve tried hard to make sure they say the same thing.
Dyad is not for emergencies. If you are in crisis, call 911, or call or text 988 (the Suicide & Crisis Lifeline, US). Outside the US, contact your local emergency number.
Who we are
Dyad is currently operated by a single individual, not yet incorporated, based in Washington State, USA. For anything about this policy, your data, or your account, write to jsavett@gmail.com: a person reads and answers it, usually the same person who built the thing you’re using.
Dyad is a structured reflection and communication practice for couples. It is not therapy and not a substitute for a licensed clinician. We say more about what that means legally further down.
What we collect
We collect only what the product needs to run:
- Waitlist: your email address, if you ask to be invited.
- Account data: email and password (handled by our authentication provider, Supabase), display name, and any invite or pairing codes used to connect you to a partner.
- Preferences: your chosen voice and AI model, topic overrides, private intentions, feedback settings, and goals you set.
- Session content: voice audio streamed during a session to produce a transcript, the resulting transcripts, session notes and topics, items you choose to share into the shared space, and ratings you give your AI persona.
- Operational data: usage events, audit/ledger events (records of shares, withdrawals, and views), and error logs if something breaks.
- Cookies: only the essential cookies our authentication provider needs to keep you signed in. No tracking cookies, no third-party advertising cookies, no analytics beacons.
How we use it
We use your data to operate Dyad for you: running sessions, producing transcripts, powering your AI persona, maintaining the shared space, and keeping the service working and debuggable. That’s it.
We do not sell your data. We do not use it for advertising. We do not train AI models on your content. Nothing sold, nothing trained on, no ads, ever.
AI processing: where your words actually go
Dyad’s sessions are powered by third-party AI providers. This means the content of your sessions (including intimate, personal material) is sent to those providers to generate a response. Specifically:
- Your voice is transcribed to text using OpenAI’s Whisper.
- Spoken responses are synthesized using OpenAI’s text-to-speech voices.
- Your coach persona’s responses are generated by Anthropic (Claude) or OpenAI (GPT), depending on which model you select in Settings.
These providers process your content under their own commercial terms in order to return a result to Dyad. We do not control, and cannot fully audit, everything a provider does on their end. We chose them because they are the leading providers for this kind of work, and we disclose this plainly because you deserve to know exactly whose systems your words pass through.
Who else touches your data
Beyond the AI providers above, a small number of infrastructure vendors process data on our behalf to keep Dyad running:
- Vercel: hosts the Dyad web app.
- Supabase: handles authentication and stores account, preference, pairing, and encrypted transcript data.
- Fly.io: runs the voice session server that your browser connects to during a live session.
- Anthropic and OpenAI: power AI responses, transcription, and text-to-speech, as described above.
Each of these processes your data under commercial terms that restrict them to providing their service, not selling your data or using it for their own advertising. Some AI providers may retain API content briefly under their own terms (for example, for abuse monitoring) before deleting it; we don’t control those windows, and their current terms state that API content is not used to train their models. We do not share your data with anyone else, and we don’t have advertising, data-broker, or analytics-resale relationships of any kind.
The partner-sharing model
Dyad’s core design is two private pools and one shared space in the middle. Here is exactly how that works, in terms that also describe the technical reality:
- Everything in your private sessions stays in your private pool. Your partner cannot see it: not the transcript, not a summary, not a sentiment score, not the fact that a session happened on a given day.
- Only items you explicitly select and preview, word for word, are copied into the shared space. Nothing crosses automatically or by inference.
- You can withdraw anything you shared. Withdrawing removes it from the shared space and stops it from being fed into your partner’s AI context going forward.
- Withdrawal cannot make your partner un-see or un-remember something they already read before you withdrew it. We track and disclose withdrawals. We cannot reach into a person’s memory.
- A mutual, plain-language ledger records share, withdrawal, and view events, visible to both partners, so neither of you has to wonder what happened.
Encryption, honestly stated
Session transcripts are encrypted at rest today. We are rolling out, over the course of the alpha, encryption keys derived from each person’s own passphrase. That rollout is in progress, not complete. So right now, this is an aim we are actively building toward, not a guarantee we can already make. We are not claiming end-to-end encryption and we are not claiming that the operator cannot access your content.
As operator, the only person with any access to Dyad’s systems does not read your session content except as needed to operate or debug the service, with your consent, or as required by law.
Important: please read this part
Dyad is not a licensed healthcare provider, and using Dyad does not create a therapist-patient or any other clinical relationship. Conversations on Dyad are not legally privileged the way conversations with a licensed therapist or attorney can be. Like any other business records, your transcripts and shared-space content could be subject to a subpoena or other legal process (for example, in a divorce or custody proceeding). We are telling you this plainly, up front, rather than burying it, because we think you should be able to decide what to say with that in mind.
AI-generated responses may be wrong, incomplete, or poorly timed. They are not medical, legal, or financial advice, and should not be treated as such.
Retention and deletion
- You can export your own data as plain markdown at any time.
- Deleting your account deletes your content and identity from our live systems. Content-free usage statistics (session counts and costs) are kept in anonymized form with no link back to you, so our aggregate numbers stay accurate. Residual copies in routine encrypted backups age out on the backup provider’s cycle rather than instantly, and we may keep the minimum records the law requires us to keep.
- The mutual ledger of boundary actions (that a share or withdrawal happened, not its content) remains visible to your partner, because it is a shared record of what happened between you.
- If you and your partner unpair, the shared space closes for both of you. Each of you keeps your own private vault. Shared material is deleted rather than divided between you.
Your rights
Regardless of where you live, you can ask us to let you access, correct, delete, or export your personal data. Write to jsavett@gmail.comand we’ll handle it. You don’t need to cite a specific law for us to take the request seriously. We are a US-based operator and your data is processed in the United States.
Children
Dyad is for adults. You must be 18 or older to use it. Dyad is not directed to children, and we do not knowingly collect data from anyone under 18.
Changes to this policy
If we make a material change to this policy, we’ll notify you by email or in the app before it takes effect. Continuing to use Dyad after that notice means you accept the updated policy.
Contact
Questions, requests, or concerns about privacy: jsavett@gmail.com.