Is it safe to give a chat analyzer your WhatsApp chat?
With WholeThing, your chat is read and counted on your iPhone. It isn’t fully offline: to write the report’s sentences, the counted facts and a capped sample of messages are sent to Google’s Gemini model, with your two names, phone numbers, emails and links removed first. The sample isn’t kept; the sentences are kept 30 days.
The short answer
A chat is about as private as it gets, so this page doesn’t round anything off. WholeThing is not a “nothing leaves your phone” app, and it doesn’t pretend to be one. Here’s the honest version:
- There’s no account. The app never asks for your name, email address or phone number.
- Your chat is read and counted on your phone. Every number in the report comes from there.
- To write the report’s sentences, a limited, redacted sample is sent to our server and on to a language model. We don’t keep that sample.
- The written sentences are kept for 30 days, stored against a fingerprint of the file rather than against you.
- No ads, no tracking, and we don’t sell data.
The rest of this page explains each of those, in more detail than a policy usually gives. The privacy policy is the formal version, and it says the same thing.
What stays on your phone
- The export you import. It’s parsed on the phone, and every count, percentage and date in your report is computed there. The whole chat is never uploaded.
- Screenshots. They’re read on the phone with Apple’s built-in text recognition. The images are never uploaded.
- Your reports. They’re stored on the phone, in Your reports.
That’s the part that does the analysing. Who starts, reply times, the week things changed: all of it is worked out by the app, not by a server. How it works explains the method.
Exactly what is sent to write the sentences
The report’s sentences are written by a language model on our server, because a model’s key can’t live safely inside an app anyone can download. For each report, the app sends:
- The facts it counted. Mostly numbers, plus the few words a card is about, such as the word you both keep using or your top emojis. A card that quotes someone, like the chat’s first message, is only sent if nothing in the quote needed removing; otherwise the app writes that card itself.
- A sample of the conversation. At most 360 messages and 24,000 characters, with each message cut to 200 characters. It gives the sentences the chat’s voice; the analysis itself still reads every message, on the phone.
- A list of words you both use often, without your two names.
- The language, the relationship and the question you picked.
- A fingerprint of the file. A one-way hash, used to recognise the same report again. The file can’t be rebuilt from it.
Before anything leaves the phone, it passes through a redactor:
| In the chat | What’s sent |
|---|---|
| The two people’s names, with endings like Sam’s | {you} and {other} |
| Phone numbers, and any number six digits or longer | [phone] or [number] |
| Email addresses | [email] |
| Links | [link] |
| Times, prices, short numbers | Kept, so the sample still reads like a conversation |
So a sample message like “Sam, call me at +44 7700 900123 when you land” goes out as “{other}, call me at [phone] when you land”. (Sam is a sample name.)
Redaction has limits, and you should know them. Names of other people mentioned in the messages, and nicknames, aren’t detected and can stay in the sample. Screenshots don’t carry names at all, so there the app tells the two of you apart by which side of the screen a message is on.
Some unlocked cards end with a general line on what a pattern usually means in chats. Those are asked for in a separate request that carries no sample, no words and no fingerprint: only the pattern, in general terms.
Where it goes and how long it’s kept
- The request goes to a function hosted by Supabase, which also hosts our database.
- The sentences are written by Google’s Gemini model on Google Cloud Vertex AI, which processes the request under Google Cloud’s terms.
- We don’t store the sample or the word list.
- The written sentences are kept for 30 days, stored against the file’s fingerprint and the request rather than against you, so reopening a report or trying again doesn’t do the same work twice. After 30 days they expire and are deleted.
- Our server logs record whether a request failed and how, never what it contained.
On Google’s side, its Vertex AI documentation says it won’t use customer data to train or fine-tune its models without permission. It also describes automated abuse monitoring: if its safety classifiers flag a request as a possible policy violation, Google may log the prompt to investigate, for a limited time. The sources below link to both.
Every sentence the model writes is checked, on the server and again on the phone. One that adds a number, names one of you or claims to know what someone feels is thrown out, and the card uses the app’s own sentence. If the service is down, the report is still complete, just plainer.
The device key, usage events, and what isn’t there
The device key. The app creates a random ID on your phone and keeps it in the keychain, so it can outlast reinstalling the app for as long as the keychain keeps it. It’s sent with each request and used for two things: counting how many analyses a phone runs each day, so one device can’t run up unlimited requests; and, if you use invites, holding your invite code, the invites redeemed with it and the credits they earn. It’s never joined to a name or to anything from your chats. For invites, Apple’s DeviceCheck also stores two yes-or-no values per device, to check that a phone hasn’t already claimed a reward.
Usage events. The app defines a short list of anonymous events: an import succeeded or failed (with a coarse reason, like “group chat”), the first and second findings were reached, an analysis failed, the purchase screen opened, a purchase succeeded or failed (with which product), a report was read to the end, and a few steps of inviting a friend. None carries a message, a name, a date range or a count. This version of the app doesn’t send them anywhere.
What isn’t there:
- No account, so nothing to sign up for and nothing to reset.
- No advertising.
- No tracking across other apps or websites, and no third-party SDK that follows you.
- No selling or sharing of data for anyone else’s use.
- Purchases are handled entirely by Apple. We never see your payment details.
Deleting a report
Long-press a report in Your reports and delete it. The conversation and its report are removed from your phone. Deleting the app removes all of them.
The sentences written for a report stay on the server until their 30 days run out, then they’re deleted. They’re stored against the file’s fingerprint, not against you, so nothing there points back to you in the meantime.
Questions to ask any chat analyzer
Whatever app you use, a private chat deserves straight answers to these before you hand it over. If an app can’t answer one, that’s an answer too.
- Are the numbers worked out on my phone, or is the whole chat uploaded to a server?
- What exactly leaves the phone: everything, a sample, or nothing? Is there a limit on how much?
- What is removed before it leaves, and what does the removal miss?
- Which company’s model reads it, and under whose terms?
- How long is anything kept, and against what: me, an account, or a file?
- Do I have to make an account, or give an email or phone number, to see results?
- Can the model make up a number or a verdict, and what actually stops it?
- Are screenshots uploaded, or read on the device?
- Are there ads, or SDKs that track me across other apps?
- How do I delete a report, and what does deleting remove?
This page is WholeThing’s answer to each of them.
Only chats you’re part of
A chat holds the other person’s messages too, and they haven’t agreed to anything. WholeThing is for a conversation you’re in, exported from your own phone. Only import chats you have the right to use; that’s in the terms, and it’s also just fair to the person on the other side.
WholeThing counts patterns. It doesn’t judge anyone, and it won’t tell you what the other person feels.
Questions
- Does WholeThing work fully offline?
- No. The counting happens on your phone, but writing the report’s sentences needs our server and a language model. If they can’t be reached, the report still appears, in the app’s own plainer words.
- Is my chat used to train AI?
- We don’t use it for that. Google’s Vertex AI documentation says Google won’t use customer data to train or fine-tune its models without permission.
- Do I need an account?
- No. The app never asks for your name, email address or phone number.
- Are my screenshots uploaded?
- No. They’re read on your phone with Apple’s text recognition, and the images never leave it. A redacted sample of the text can be sent to write sentences, like with an export.
- What happens if I delete the app?
- All your reports are removed from the phone. Sentences on our server expire after 30 days.