Private by design
Your words stay between the two of you.
Effective July 26, 2026
Balanced holds some of the most private things you’ll ever type into an app: what you honestly think and feel about your relationship. This page says plainly what we keep, who can see it, and what we will never do with it.
01The promise
What you write is sealed until you’re both ready. Not hidden by the interface — refused by the database.
Your reflections are locked to your account by row-level security rules inside the database itself. Until both of you press Ready, no request made through Balanced — by your partner’s app or anyone else’s — returns your words. The reveal isn’t a feature we added; it’s the only door there is.
02What we keep
- Your account — the email on your Measrd account, and a display name if you set one.
- Your relationship spaces — current and historical pairing membership, pairing dates and codes, your two colors, origin/reveal dates, and relationship lifecycle records.
- Your reflections — drafts and sealed answers, their questions, context, readiness, reveal, comments, and completion state.
- Content-free progress — the signal your partner sees while you write: how many answers you’ve sealed and which questions, never a word of them.
- Your shared story — moments, photos and image metadata, margin notes, milestones, chapter titles, plans, keepsakes, and generated artifacts.
- Access and payment records — Balanced entitlements and subscriptions, references to the shared Stripe customer attached to your Measrd identity, gifts, gift redemptions, referrals, founder eligibility, and related audit records. We do not store your full card number.
- Email records and preferences — opt-out state and queued, sent, or failed notification delivery records.
- Operational and abuse records — bounded timestamps, outcomes, IP-derived rate-limit keys, and events such as creating a pairing code or opening a ritual. These records do not contain reflection bodies.
We do not build an advertising identity or sell a behavioral profile. Aggregate site analytics are described below.
03What your partner can see
Before the reveal: only that you’re making progress — how many answers you’ve sealed and which questions they belong to, plus a soft presence light when you’re in the ritual room. Never your words, never a preview, never a count of characters.
After you’re both ready: the answers you each sealed in that ritual, side by side, at the same moment. Completed rituals stay readable to both of you in Legacy, exactly as revealed.
04What we never do
- We never sell your data — to anyone, for anything.
- We never show ads, and never share your words with advertisers or data brokers.
- We never use your reflections to train AI models — ours or anyone else’s.
- We do not use advertising pixels or cross-site behavioral tracking.
- We do not send marketing blasts. You can turn off Balanced’s quiet product emails in Settings.
05How the seal is enforced
The privacy boundary lives in the database, not in the app’s good manners: row-level security rules decide what every request may read, and the reveal is derived from both partners’ independent ready marks — it isn’t a flag anyone can flip.
The repository includes an automated privacy suite with dozens of assertions that try to read a partner’s words early, forge readiness, or reach across couples. A release is not considered verified until those checks pass against isolated infrastructure.
Your words travel encrypted (TLS) and are stored encrypted at rest — and your answers go further. Everything the two of you write — ritual answers, context notes, moments, margin notes — is individually encrypted with a key the database never holds, before it is stored. Database consoles, admin tooling, and backups see only ciphertext; the database itself refuses to accept your words unencrypted. Your words are decrypted only in the moment a server composes your rituals or shows you what you are entitled to see. No human-readable path to them exists in our tooling. Credentials that could bypass these rules live only on servers, never in the app your browser runs.
06The questions you're asked
Your first ritual draws from a question set we wrote by hand. Every ritual after is composed for the two of you: once a ritual is revealed and kept, that shared history — and only that — shapes your next thirteen questions.
Here is exactly how, in plain words. The shaping step can only read what you’ve both already revealed — the database makes sealed reflections unreachable to it, the same way it makes them unreachable to your partner before the reveal. That revealed digest is sent to Claude, the AI model we use (made by Anthropic), under API terms that prohibit training on it. The model returns your next questions and nothing else; we keep the questions, not the exchange. Sealed words never make that trip, and if this boundary ever needs to change, we’ll tell you first.
07Analytics, cookies, and email
Cookies do exactly one job here: keeping you signed in to your Measrd account across measrd.com apps. No third-party cookies, no cross-site tracking, no fingerprinting.
When analytics is enabled, we use Cloudflare Web Analytics on public marketing and legal pages for aggregate page-view, referrer, browser/device, country, and performance measurements. We exclude private gift routes and the signed-in app. The public-page beacon receives technical request data and the page URL, but not reflection, note, photo, gift-secret, or payment contents. Cloudflare states that this product does not use cookies, local storage, or fingerprinting to collect its usage metrics. See the Cloudflare data-collection description.
Balanced can send four opt-out product notes through Resend: questions arrived, partner joined, partner ready, and a margin note arrived. Account, security, receipt, and billing messages may still be sent by Measrd, Supabase, or Stripe when needed to provide the account or transaction.
08Processors and where data lives
Balanced uses Supabase for database, sign-in, private storage, Realtime, and server functions; Cloudflare for hosting, Web Analytics, and encrypted R2 backups; Resend for product email; Stripe for checkout, subscriptions, receipts, and billing support; Anthropic for composing future questions from already-mutually-revealed history; and GitHub Actions for scheduled operations and encrypted backup verification. These providers process only the data needed for those jobs under our instructions.
Primary service infrastructure is in the United States. Data is encrypted in transit; database, storage, and backup providers encrypt stored data.
09Keeping and deleting
Your shared space remains while the relationship is active. Ending a relationship freezes that immutable relationship space, removes current access, closes unfinished rituals, and prevents any later partner from inheriting it. It does not move history into a new relationship.
You can delete Balanced in Settings, or email mtthw@measrd.com from your account address. This is product-scoped deletion, not deletion of your whole Measrd account. Deletion begins with a 48-hour window: nothing is removed yet, your partner is told plainly — in the app, and by email if they receive Balanced emails — and you can cancel from Settings at any point before it runs. Each of you can read and export your own written words at any time, including after a partner's deletion or after a relationship ends. An active Balanced Checkout window must close and expire before deletion can run, which can take up to about 35 minutes; unrelated product billing does not block the request.
Balanced deletion revokes your Balanced membership and current access, removes or de-identifies the Balanced records you authored where they can be separated safely, queues the photos you authored for retryable deletion from private storage, and cancels Balanced subscriptions billed to your Measrd account. It closes the current relationship for both people. Partner-authored records remain theirs, and partner-owned billing is not canceled. Genuinely shared or derived records stay frozen and inaccessible to both former participants. There is no survivor archive of shared history, those records are never exposed to a new partner, and we have not set a fixed deletion timeline for jointly created history. Your own written words are different: each of you can read and export what you yourself wrote, at any time, from Settings. We confirm asynchronous completion rather than claiming deletion while cleanup is pending.
Balanced deletion preserves your Measrd identity and sign-in, the shared Stripe customer, saved payment methods and billing portal, and every other product’s data, access, and subscriptions. To request deletion of the whole Measrd identity instead, use the separate operator-assisted path in your Measrd account. Whole-account deletion has broader consequences and its own shared-space, transaction-retention, and backup limits.
Nightly encrypted logical backups and provider point-in-time recovery cannot be edited one account at a time. Deleted data can remain in access-controlled backups until those backups are retired, and any restoration must reapply outstanding deletion requests. The repository currently does not encode an automatic expiry window for the nightly and monthly R2 backup objects; we therefore do not claim a shorter period here.
10Changes and contact
If this policy changes in any way that matters, we’ll say so in the app before it takes effect — not bury it here. Questions, concerns, or something that doesn’t look right: mtthw@measrd.com.
Balanced is made by Measrd LLC. The governing documents for every Measrd app live at measrd.com: the Terms of Service and the ecosystem privacy policy — this page is Balanced’s own seal, stated in full, layered under them.