Privacy policy

Panache
Privacy Policy

Effective date
Last updated

Panache ("we," "us," or "our") operates the Panache Android app and its supporting backend service. This policy explains how we handle information when you use the app, service, or website. The Panache marketing website is informational only and does not provide accounts, chat submission, or sign-in features.

Panache is a dating-conversation coach. It helps you analyze conversation context and prepare coaching and reply suggestions. It is not a dating app, does not control dating-app accounts, and never sends messages for you.

18+ only

Panache is intended only for people aged 18 or older. We do not knowingly collect information from children. If you believe a child has provided information, contact us at support@panache.chat.

Information we handle

Account and authentication information

When you sign in, Panache handles the authentication information needed to create and maintain your account, including a Google sign-in token, account identifier, and permitted basic account details. Android stores sensitive local account state using Android Keystore protections.

Billing and credits

Google Play processes purchases. RevenueCat helps Panache verify purchases and subscriptions using your Panache account UUID as its customer identifier. Panache records product and transaction identifiers, subscription status and periods, transaction links to your account, and credit balances and their changes.

Conversation and coaching information

Depending on how you use Panache, we may handle the messaging or dating app you identify, a match name or display name, profile notes you enter, conversation text you paste, share, edit, or submit, text extracted from a screenshot or visible screen, speaker-label corrections, user-supplied facts, and the tone or coaching mode you select.

Conversation text can contain personal information about you and another person. Submit only the context needed for coaching and remove unnecessary sensitive information when you can.

Panache may create and store conversation sessions and timestamps; coaching scores and classifications; suggestions, next moves, and explanations; user-control and policy records; and feedback or reported outcomes. A reported "sent" outcome means only that you recorded what happened outside Panache. Panache does not send or verify a message.

Screenshots and visible-screen capture

When you choose to scan, Panache captures one screen image with Android's permission and reads its text on your phone. The normal scan ends after that image. The floating bubble does not continuously read your screen. You can also import a screenshot you select through Android.

Clear scans can send recognized conversation text through Panache's backend to OpenAI for a reply before a separate review step. You can check and correct the text afterward. Conversation text and generated replies may be saved to your Panache account.

Screenshot pixels are processed on-device by default using Google ML Kit. ML Kit does not send screenshot content or recognized text to Google. It may send usage and performance metrics to Google. Panache does not upload or durably store screenshot pixels unless you choose one of the options below. One-shot images remain in memory until cleared, replaced, or the app process ends.

If you separately approve Improve scan, Panache sends one screenshot through its backend to OpenAI to help read it. Panache does not durably store that image; OpenAI's retention rules still apply. The improved text returns for your review and correction before it is used to generate a reply.

Separately, you can explicitly attach a screenshot to a bug report. The labeled Share example flow uploads only the blurred diagnostic shown in its preview, not your screenshot or messages. Uploaded attachments are private and follow the retention limits below. Any donation for training or evaluation needs separate consent, as explained below.

The bubble can stay available after capture ends. You can stop it from its controls or in Panache. When notifications are enabled, its ongoing notification also offers Stop Panache.

Panache does not use Android AccessibilityService, read notification content, access dating-app credentials, automate a keyboard or send button, or request camera, microphone, contacts, or location access.

Support, diagnostics, and device information

When you use Panache, we may process account and session identifiers, a random app-install identifier, trace identifiers, source-app and context-source categories, provider/model/fallback/error categories, transcript-quality and latency measurements, and bug-report comments, attachments, or metadata you explicitly provide. Routine telemetry is designed not to include raw screenshots, raw chats, credentials, provider payloads, names, profile text, generated replies, or free-form feedback. Hosting and web-server logs may include connection information such as IP address, request time, requested path, user agent, response status, and error information.

Do not include private chat text, passwords, contact details, or other sensitive information in a support or bug-report message unless it is necessary to resolve your request.

Website measurement

We use Plausible Analytics to understand visits to panache.chat and clicks on its Google Play buttons. This includes pages visited, referring websites, approved campaign labels, browser and device type, approximate location, visit timing, and scroll depth.

Plausible receives your IP address and browser information to estimate location and count visitors. It says it does not store raw IP addresses or user-agent strings. Its visitor identifiers change daily. It stores event and session records in the EU and shows us aggregated statistics, without analytics cookies or tracking you across websites, apps, or devices.

We send only approved page paths, campaign labels, referring website origins, and the fixed Play link clicked. We do not send Panache account identifiers, email addresses, conversation text, or screenshots to Plausible. Website analytics retention follows Plausible's trial or subscription terms, separately from the app's product-telemetry retention below. See Plausible's data policy and service plans.

Our Google Play links include fixed labels identifying this website and the button clicked. Google receives those labels when you follow the link and may report attributed visits and installs to us in aggregate. The labels do not identify your Panache account. Clicking a download button does not tell us that you installed or opened the app.

How we use information

We use information to operate and secure Panache; authenticate accounts; verify purchases and subscriptions; manage credit balances; extract and analyze user-requested conversation context; create coaching suggestions; restore saved sessions and results; enforce the no-auto-send and user-control boundaries; diagnose failures; improve Panache's reliability; respond to support, deletion, and privacy requests; and comply with legal obligations.

AI providers and automated coaching

Panache uses deterministic safeguards and OpenAI for model-backed reply generation. When you request coaching, including through a clear scan, the backend may send relevant conversation text you submit or choose to scan, user-supplied facts, reply preferences, source-app information, derived routing information, and safety instructions to OpenAI. Separately approved Improve scan requests also send one screenshot for text recognition. The Android app does not call OpenAI directly.

OpenAI states that API inputs and outputs are not used to train its models by default unless the customer opts in. Its default abuse-monitoring logs may retain prompts, responses, and related metadata for up to 30 days. Longer retention may apply when required by law or reasonably needed to protect OpenAI's services or others from harm. Images flagged for possible child sexual abuse material may be kept for manual review. Other retention rules can apply to specific API features. Panache does not promise immediate provider-side deletion or Zero Data Retention. See OpenAI's API data controls and Privacy Policy.

Panache does not use private conversations as public examples, sell them, or use them for targeted advertising. Saving conversation history, using Improve scan, or filing a bug report is not permission to use private conversations for model training or evaluation. Any separate Share example for improvement flow requires an explicit choice and its own disclosed retention and deletion terms. Panache's scores and suggestions are coaching tools, not legal, employment, credit, housing, insurance, or similarly significant decisions.

When information is shared

We share information only as needed to operate Panache: with our hosting and database infrastructure, including Render or its configured infrastructure; with OpenAI when you request a reply or separately approve Improve scan; with Google Play and RevenueCat for purchase and subscription verification; with Google/Firebase distribution services if used for app delivery; and with professional advisers, authorities, or other parties when required by law, needed to protect users or rights, or authorized by you.

Panache does not sell or rent personal information, provide private chats to data brokers, use private chats for targeted advertising, or receive information directly from a dating-app account. Dating and messaging apps are separate services; Panache receives only information you choose to capture, import, paste, or submit.

Retention and deletion

Saved match profiles and conversation history, including text accepted by a clear scan without separate review, remain available until you delete that match, clear all saved matches, delete your account, or the applicable product lifecycle ends. Limited content-free audit records may remain where needed to demonstrate user control, security, or legal compliance, but they do not recreate deleted chat text, names, profile details, generated replies, screenshots, or free-form feedback.

Response-cache entries expire after 30 minutes and are no longer reused. Hidden generated-reply and HUD records, bug-report text, parser diagnostics, and privately stored screenshot attachments you explicitly provide become eligible for deletion after 30 days. Content-free product telemetry becomes eligible for deletion after 90 days and is designed not to contain conversation text, names, profile text, generated replies, screenshots, or free-form feedback.

These are expiry and cleanup thresholds, not guarantees that records are physically deleted at that exact moment. Scheduled cleanup runs at startup and hourly while the service is active; records can remain until cleanup succeeds. The Android app also maintains an encrypted last-read cache with a logical 24-hour lifetime.

Delete this match removes only the selected match's saved profile, saved conversation text, generated replies and results, reports, attachments, and device-local match memory. Other saved matches and account settings remain. Clear all saved matches removes the same information for every saved match while keeping the account and its settings. Neither action changes a match in a dating app or cancels or refunds a Google Play subscription.

Delete account erases Panache account credentials and associated private content, including saved matches, saved conversation text, generated replies, reports, attachments, credit balance, and purchase linkage. It does not delete your Google account or cancel or refund a Google Play subscription. It also does not automatically erase records held by Google Play, RevenueCat, OpenAI, or other providers; their own retention rules apply.

Operational backups are not active product history and may retain deleted records until the hosting provider's backup cycle expires. Before a restored database serves requests, Panache reruns retention cleanup so expired private artifacts do not return to the active service.

To request deletion, access, correction, or other privacy help, email support@panache.chat. We may ask for enough information to verify the request and locate the relevant account or conversation.

Your choices

You can decline Android screen-sharing, overlay, or Improve scan permission, stop the bubble, use pasted or imported context instead of screen capture, ignore or edit a suggestion, delete one match, clear all saved matches, delete your account, clear cached conversation and sign-in state by signing out, and contact us about deletion or other privacy requests. Panache never automatically sends a suggested reply.

Security and international processing

We use safeguards intended to protect your information, including HTTPS production connections, account-scoped backend access, Android Keystore protection for sensitive local state, disabled Android backups, and telemetry field allowlists. No system is completely secure; avoid submitting unnecessary sensitive information and protect your account and device.

Our hosting, support, and AI providers may process information outside your province, state, or country, including outside Canada. Information processed elsewhere may be subject to the laws of that location.

Changes and contact

We may update this policy as Panache's features, providers, or legal obligations change. We will update the date above and provide additional notice when a material change affects how private conversation information is handled.

Privacy contact: support@panache.chat
Operator: Panache
Country: Canada