Belvantis
  • Products
  • OmniThink
  • Candor: Private AI Journal
  • Candor AI Note
  • Parallax
  • About
Effective: 2026-06-17 · Last updated: 2026-06-17

privacy policy

Parallax is a relationship insight app for couples. Both partners answer the same question; the app holds both answers privately until you've both submitted, then reveals them side by side. Over time it measures how well you understand each other.

This policy explains who we are, what we collect, what we don't, what we can and can't see, how long we keep it, and what choices you have. We have written it plainly. If anything here is unclear, write to us at info@belvantis.com and we will revise the language.


Who we are

Parallax is operated by Belvantis LLC (a Virginia, USA limited liability company), the data controller for the personal data described here. You can reach us about anything in this policy — privacy questions, access or deletion requests, or security disclosures — at info@belvantis.com, or by mail at the address at the end of this policy. We do not currently have a designated Data Protection Officer; the contact above reaches the person responsible for privacy.

What we collect

Account identifier

When you sign in with Apple or Google, those providers federate your sign-in through Microsoft Entra External ID, which gives us a stable identifier that is unique to you and to Parallax. We use it to associate your devices with your dyad. We never receive your password.

Display name

We store the first name you choose so your partner's app can show who they're paired with, and so we can address you in the app. It is stored on our servers and shared with your paired partner. You can change it any time in Settings.

Pairing data

When you pair with your partner, we store the dyad relationship — that your account is linked to theirs — along with each device's public key. The public keys are mathematical artifacts; they cannot be used to read your answers.

Answer and prediction envelopes

Every answer ("what I think") and prediction ("what I predict my partner thinks"), and every weekly pulse response, is encrypted on your phone before it leaves the device. The encryption key lives only on your and your partner's phones. The data we store on our servers is opaque ciphertext. We cannot decrypt it. Nobody can but you and your partner.

Reflection notes

Parallax has two kinds of reflection notes. Private notes never leave your device — they are stored locally on your phone alone and we never receive them. Shared notes are written by one partner for the other; we encrypt them on your phone with the same end-to-end key your answers use, and store the opaque ciphertext on our servers so your partner can fetch and decrypt it. We cannot read shared notes.

Custom questions

If you write your own question for your partner, the question prompt — the wording you choose — is stored on our servers, keyed to your account, so it stays available to you across devices, sign-outs, and re-pairings. We can read these prompts: they are stored the same way as the questions in our public library, and are not part of the end-to-end-encrypted layer. We hold them only to keep your personal question library available to you; we never use them for advertising or share them for that purpose. Your partner's answers to a custom question are always end-to-end encrypted and remain unreadable to us, exactly like answers to any other question.

Creating a question set with AI (optional, paid)

With "create a set," you can describe a topic you'd like to explore with your partner, and we generate a set of questions for it. To do this, the topic you type is sent from our servers to our AI provider, Anthropic (the Claude API), which returns the generated questions; we then store your topic and the generated questions on our servers, keyed to your account, so the set stays available to you. The topic you type is the only thing sent to Anthropic — it is processed under Anthropic's commercial API terms, under which your inputs are not used to train models. Your partner's answers are never sent to Anthropic or to any AI service; only the questions you ask leave our servers, and only when you tap to generate a set.

Asking Omnithink (optional)

From a round that both of you have already revealed, you can tap "ask omnithink" to get a reflection from Omnithink, another Belvantis product. When you do — and only on that explicit tap — that round (the question and both partners' revealed answers and predictions) leaves Parallax's end-to-end-encrypted world and is sent to Omnithink, where it is processed and stored under Omnithink's own privacy policy until you delete it there. This never happens automatically, and only for rounds already revealed to both of you. If you never tap it, no round content is ever sent to Omnithink.

Question metadata

When a round uses a question from our published library, our servers record which library question was issued to your dyad and when. The question itself is public material from our library — not something you wrote — and what you and your partner answered stays encrypted as described above. We also keep a count of how many questions were issued and how many answer envelopes were submitted, never their contents.

Subscription status

If you subscribe, we store the subscription state (active, in trial, cancelled, etc.) so we know whether your account has access. Payment is handled entirely by Apple (App Store) or Google (Play Store). We never see your card, your billing address, or your payment history.

Push notification token

If you allow notifications, your device's push token (from Apple's APNs or Google's FCM) is stored so we can tell you when your partner has answered. Notification text contains only your partner's first name and a brief, generic message — never any answer content. You can turn notifications off in your device settings; the token is removed when you sign out.

Crash reports

In the builds we distribute through the app stores, when the app crashes we capture technical details with Sentry: a stack trace, the app version, and your device model and operating-system version. Crash reports do not include your answers, predictions, or notes — that content is end-to-end encrypted and is not part of a crash report — and we do not attach your name. Local development builds send nothing.

App usage analytics

We use a privacy-first analytics service (Aptabase) to measure broad, anonymous navigation events — such as app opens and taps on non-content buttons. These events never run on the answer-entry or reveal screens and never include your answer content, predictions, or partner data. We do not use Google Analytics, the Meta SDK, or any advertising identifier (IDFA / AAID).

Suggesting a question (optional)

If you choose to suggest a question for our public library, the text you submit is added to a proposal in our public, open-source question repository on GitHub, attributed to an opaque account identifier (and a display name only if you supply one). Anything you submit there is public and becomes part of public version history; do not include anything private in a suggestion.

Third-party services we use

We keep our use of outside services deliberately small, and we never share your data for advertising. The services that may process data on our behalf are:

  • Microsoft Azure — hosting and storage of our backend and database (United States). This is where the opaque ciphertext and the readable account data described above are stored.
  • Microsoft Entra External ID — federated sign-in (you sign in with Apple or Google through it). It receives your sign-in identity and identifier, never a password we hold.
  • Apple — Sign in with Apple, App Store purchases, and push delivery (APNs). Apple processes your purchase; we never see your payment details.
  • Google — Sign in with Google, Google Play purchases, and push delivery (FCM). Google processes your purchase; we never see your payment details.
  • Anthropic (Claude API) — only when you use "create a set," to generate questions from the topic you type. It receives that topic only — no answers, names, or partner data.
  • Omnithink — only when you tap "ask omnithink," as described above.
  • Sentry — crash diagnostics (no answer content, no name).
  • Aptabase — anonymous usage analytics (no content, no identifiers).
  • GitHub — only if you submit a question suggestion to our public library.

Why we are allowed to process your data (legal bases)

For users in the EU, UK, and other regions with similar laws, we rely on these lawful bases under the GDPR / UK GDPR:

  • Performance of a contract — to provide the app: your account identifier, display name, pairing, storage and delivery of your (encrypted) content, subscription status.
  • Consent — for push notifications and for the optional features that send data out (AI "create a set," "ask omnithink," suggesting a question). You give consent by enabling notifications or tapping the feature, and you can withdraw it at any time.
  • Legitimate interests — to keep the service secure and working: crash diagnostics, anonymous analytics, abuse and fraud prevention, and enforcing usage limits. We balance these against your rights and keep the data minimal.
  • Legal obligation — where we must keep or disclose limited records to comply with the law.

How long we keep your data

  • Account data (identifier, display name, pairing, subscription, devices, custom questions, AI question sets, and your opaque encrypted content) is kept for as long as your account exists. When you delete your account, it is removed from our servers immediately, as described under "Your rights."
  • A partner-assisted recovery package (see below) has a 48-hour time-to-live and is deleted automatically; once it is used, we immediately erase the sealed contents.
  • Question-issuance and usage-limit records are kept only for the rolling window needed to enforce freemium limits and are pruned automatically once they age out.
  • Crash and analytics records are retained by Sentry and Aptabase under their standard retention periods, then deleted.
  • Anything you send to Omnithink, or post as a public question suggestion, is governed by that destination (Omnithink's policy, or public GitHub history) and is not reached by deleting your Parallax account.

What we can and cannot see

We cannot see:

  • Your answers.
  • Your predictions of your partner's answers.
  • Your trends or empathy match scores. (These are computed entirely on your device.)
  • The answers and predictions you and your partner give to any question — from our library, written by one of you, or AI-generated — the answer envelopes are encrypted end-to-end and opaque to us. (We do store the prompt of a custom or AI-generated question; see "Custom questions" and "Creating a question set with AI" above. It is the answers, never the prompts, that are encrypted.)
  • Your weekly pulse responses (encrypted end-to-end, like your answers).
  • Your private reflection notes (they never leave your device).
  • The contents of your shared reflection notes (encrypted end-to-end; we hold the opaque ciphertext but cannot decrypt it).

We can see:

  • Your account identifier, your display name, and pairing-time public keys.
  • That your account is paired with another account (the dyad), and your partner's display name once you are paired.
  • The text of questions you write yourself, and the topics you type into "create a set" along with the questions it generates. (These are stored readable so your personal question library stays available to you; your answers to them are never readable to us.)
  • Which questions from our public library were issued to your dyad, and when. (The library is public; your answers to it are not.)
  • Your subscription status.
  • Your push notification token, if you allow notifications.
  • The number of questions you've been issued and the number of envelopes you've submitted (but not their contents).
  • Aggregate, anonymous navigation events (app opens, non-content button taps).

What we explicitly do not collect

  • We do not collect your contacts.
  • We do not collect your location.
  • We do not access your camera, microphone, photos, or other media.
  • We do not collect device identifiers used for advertising.
  • We do not collect biometric data.
  • We do not collect health or fitness data.
  • We do not sell or share your personal information, and we do not share data with third parties for advertising.

Security

The content you and your partner create — your answers, predictions, pulse responses, and shared notes — is end-to-end encrypted on your device, so we hold only ciphertext we cannot read. All data is additionally encrypted in transit (HTTPS/TLS) and at rest on our servers. The local database on your phone is itself encrypted. Access to our systems is limited and our administrative actions are logged. No system is perfectly secure, but we design Parallax so that the most sensitive thing — what you actually said — is never readable by us. If we ever become aware of a data breach affecting your personal data, we will notify you and any required authority as the law requires.

Automated decision-making

We do not use automated decision-making that produces legal or similarly significant effects about you. Your empathy-match scores are computed on your own device, and the AI "create a set" feature only drafts questions for you to choose from — neither makes decisions about you.

International transfers

Parallax stores data on Microsoft Azure servers in the United States. If you use Parallax from outside the United States, your data is transferred to and processed in the United States and by the other providers listed above. For transfers from the EU/UK, we rely on the data-processing terms and transfer safeguards offered by these providers (such as Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework). Your answer content is encrypted in transit and at rest, and the end-to-end encryption layer keeps it unreadable to us regardless of where it is stored.

Account recovery and device loss

Your answer history is protected by an encryption key that lives only on you and your partner's phones — not on our servers. Because of that, how recovery works depends on your settings:

  • Partner-assisted recovery (paid plan, opt-in). If backup is turned on in Settings, your new device can ask your partner's phone to send the shared key back. The key is wrapped in a fresh layer of end-to-end encryption before it leaves your partner's device; our server passes the sealed package along but cannot open it, and both of you can confirm a short fingerprint code before approving. Your history then comes back on the new device. The sealed package expires and is erased from our servers within 48 hours.
  • Without backup, or if both of you lose your phones at once. The key is gone, so your past answer history is not recoverable by us or anyone else. You can re-pair on a fresh device and start again. This is the cost of nobody else being able to read your answers, and we tell you so in onboarding.

Counselor mode (v2)

If you choose to share insights with a therapist or counselor, you can grant them read-only access to per-domain match rates and large-gap flags — not your raw answers. You can revoke their access at any time. Counselor mode is not enabled by default and requires both partners to opt in.

Children

Parallax is for adults (18 and over) in a romantic, committed relationship. We do not knowingly collect personal data from anyone under 18. If you believe a minor is using Parallax, write to us at info@belvantis.com and we will delete the account.

Your rights

Depending on where you live, you have the right to:

  • Access the data we hold about your account. Open Settings → Account → Export data, or write to info@belvantis.com. (You can also export your revealed rounds as text from inside the app at any time — this also serves as data portability.)
  • Correct your information — for example, edit your display name in Settings at any time.
  • Delete your account. Open Settings → Account → Delete account. This immediately and irreversibly removes everything we hold for you on our servers: your account record, your display name, your dyad and its encrypted envelopes, your custom questions and AI question sets, your subscription record, your registered devices, and any recovery package. Your partner's app will show that the pairing has ended. (Content you previously sent to Omnithink, or posted as a public question suggestion, lives at that destination and must be removed there.)
  • Restrict or object to a specific processing activity. Write to info@belvantis.com.
  • Withdraw consent at any time — turn off notifications, stop using the optional AI/Omnithink features, or delete your account.

We aim to respond to any request within 30 days. We do not discriminate against you for exercising these rights. If you are in the EU/UK and believe we have mishandled your data, you also have the right to lodge a complaint with your local data protection authority.

California privacy (CCPA/CPRA)

If you are a California resident: in the past 12 months we have collected the categories of personal information described above — identifiers (your account identifier, display name, device push token), commercial information (subscription status), internet/usage activity (anonymous navigation events, crash diagnostics), and the content you create (your custom-question and AI prompts, which we can read, and your answers, which we cannot). The relationship context of this content may be considered "sensitive personal information"; we use it only to provide the service you asked for and do not use it to infer characteristics about you.

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising — and we have not done so in the past 12 months. You have the right to know, access, correct, and delete your personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. To exercise any of them, use the in-app controls above or write to info@belvantis.com; you may use an authorized agent, and we will verify the request through your account.

Changes to this policy

If we make material changes, we will notify you in-app before the changes take effect, and we update the "last updated" date at the top. Continued use of Parallax after a change takes effect means you accept the updated policy.

Contact

Privacy questions, data requests, and security disclosures: info@belvantis.com

Belvantis LLC
11166 Fairfax Blvd, PMB 1155, Ste 500
Fairfax, VA 22030-5017, USA

← back to parallax  ·  terms of service

© 2026 belvantis. all rights reserved.