Read Receipts is a Mac app made by ARKHIVE. It reads your iMessage history on your Mac and helps you see your conversations: who you text, what is coming up, and what you may have missed.
This policy covers the Read Receipts app and the parts of ARKHIVE's servers it talks to. It says what stays on your Mac, what leaves it, and when. For anything about ARKHIVE as a company, and for your ARKHIVE account if you sign in, see ARKHIVE's privacy policy.
What stays on your Mac
- Your Messages archive. You choose your Messages folder yourself, in a standard macOS window. Read Receipts opens it read-only. It never changes, moves or deletes anything in Messages. While it counts, it makes a temporary copy of the Messages database and deletes that copy when it is done. While the app is running, it also reads new messages as they arrive, read-only, so your counts, people and search stay current without a refresh. That happens on your Mac and sends nothing.
- Your contacts. If you allow Contacts, the app reads names, company names, phone numbers, email addresses and messaging addresses, so it can tell who is who. It does not change your contacts.
- What the app works out and saves. Your counts, rankings, saved reads and stories, your Ask chats (your questions, the searches shown under them and the answers), and what you mark on them (Done, Later or Dismiss) are kept in the app's own folder on this Mac.
- Your sign-in. Your ARKHIVE sign-in is kept in your Mac's login keychain.
- What earlier versions saved. If an earlier version kept your own OpenAI key in your keychain, the app deletes it the first time this version runs, and asks for your yes to reads again. Results saved by the Sweep, which earlier versions had, are deleted the first time the app opens.
Reading and counting your archive happen on this Mac. Nothing about your messages leaves it except as described in the next section.
What is sent for a read
A read is anything an AI model writes for you, such as the read of your week on Home, an answer to a question you ask in Ask, a draft text to someone, a story about a friendship, or an answer to a question about one.
- Only after you say yes. The app asks once, before your first read: on its consent step during setup, or, if you skipped that step or updated from an earlier version, when you first start a read. Nothing is sent until you say yes. "Not now" sends nothing, and the app asks again the next time you start a read.
- What the consent step shows you. To show what a read would look at, the consent step counts your last week of texts (or your last 30 days, if the week was quiet) on your Mac: how many texts, who you texted most, your group chats with their typed names, how many conversations ended on the other person's text, and how many texts name a day or a time or mention meeting someone. These counts and names are worked out on your Mac and shown only to you. They are not sent, and saying "Not now" sends nothing.
- When reads are sent after a yes. When you start one: Read my week, Refresh, Try again, asking a question in Ask (or in the Ask bar on Home, which opens Ask), Draft, writing a story or asking about one, opening the midweek notification, or opening your share cards. And once each morning while the app is running, even with its window closed: after 7:00 a.m. your time, at most once a day, only while the app can read your Messages, and only if you have not read your week since 6:00 p.m. the evening before. If your Mac was asleep or the app was not running at 7:00, that morning's read happens the first time the app opens, comes to the front or wakes later that day. A morning read that fails is not tried again until the next morning. And, only if you turn on keeping your read up to date (a checkbox on the consent step, on unless you uncheck it, which you can turn off any time in Settings under "Keep my read up to date"), after new messages arrive while the app is running, so the read on Home stays current without you refreshing it: only if something new has arrived since your last read and that read is at least 30 minutes old, at most once every two hours and a few times a day (no more than four of these background reads a day, counting the morning one), and only while the app can read your Messages. If you have not signed in, these automatic reads use at most about half of your free reads for the day and always leave the last few for reads you start. One that fails waits longer before the next try, and none of them sends you a notification. Without your yes to reads, nothing is read automatically and Home asks you instead; with it but with automatic reads off, only the morning read and the reads you start are sent. A question in Ask sends your last 30 days of messages, plus what its searches find: to answer, the app may search further back in your Messages on this Mac, by a word, by dates or by a person, up to four times for one question, and each search adds what it found to what is sent. Every search is shown under your question as it happens.
- What is sent. The recent conversations the read needs, including who said what, and the instructions for the model. An automatic read after new messages usually sends less: what your last read found (each thing it raised, with the short quotes from your texts it rests on) and only the conversations with a new message since then, each from about its last week. The rest of your conversations are not sent again. So the read knows you, it also includes what you have told the app: your answers to its questions, the corrections you saved with "What's actually true?", and the app's own short summary of your month, saved from an earlier read. For the people in the read, it adds a few rough facts counted from your older messages with each of them, such as since when and roughly how much and how often you have texted, without their names. Share cards are the exception: for those, only the counts already on the cards and the first names printed on them are sent, never a text.
- A question in Ask. Your question is sent with the same last 30 days of conversations and the same things you have told the app that the read of your week uses, and with your earlier questions and answers in the same chat. Searches run on your Mac: the app reads the messages a search names and sends the ones it found, never your whole history. It goes the same way as a read, with names swapped as below, including names in what a search found.
- Draft. A draft text to one person is written from the moment it is about and the last few lines of your conversation with that person. Lines from other conversations are not sent.
- Names are swapped before anything is sent. Before a request leaves your Mac, the app replaces the names it knows (from your contacts and the people in your chats) with made-up names. It replaces each typed group chat name (like "Sarah's 30th") with a placeholder like "Group 1", wherever it appears, including inside messages. It replaces phone numbers, email addresses and card numbers with placeholders like "[phone 1]". It swaps them back when the answer arrives. This is not full anonymization. Names the app does not know, places, addresses and the rest of what was written are sent as written.
- Where it goes. Every read goes through ARKHIVE's server; the app no longer has a way to use your own AI key. The request goes from our server to OpenRouter, which sends it to an AI model. Every request requires zero data retention: OpenRouter may only send it to a model provider that does not keep prompts, and never to one that collects data. If no such provider is available, the read fails. It is not sent anywhere else. The request also asks that the response not be stored.
- ARKHIVE does not keep your conversations. Our server passes the request through. It does not save, log or send to analytics your conversations, the instructions, or the answer.
- What our server records for each read. Your ARKHIVE account ID, the kind of read, the model and provider, token counts, cost, how long it took, and whether it finished. If a read fails, we record the reason and an error code. These records are kept in our database and in our analytics tool, PostHog, and are tied to your ARKHIVE account. We also count how many reads each account makes per day, and, if you have not signed in, how many questions you ask in Ask and how many reads your anonymous account has made in all, to enforce its free allowance: more on its first day, fewer each day after, and a limit in all, after which reads need you to sign in. These are counts only, kept against your account ID.
We collect anonymous usage data
Read Receipts sends anonymous usage data so we can see which parts of the app people use and where they get stuck.
- What is collected. Which screens and sheets you open, which setup steps you reach, whether a read, story or count finished or failed and why, how long things took, token counts, the size of your archive as a rough range (like "1k-9k" messages), and your app and macOS versions. When the consent step comes up, it also records the number of texts it counted as a rough range (like "100-999"), and, for each of its four cards, only yes or no for whether the card showed a count from your texts.
- What is never included. Your messages, names, contacts, phone numbers, email addresses, questions, search terms, stories, or the text of any read. Usage events are made only of fixed choices, counts and yes or no values, so there is no place in them for anything you wrote.
- Tied to a random install ID, not to you. The ID is made up on your Mac. It is not linked to your ARKHIVE account, even if you sign in, and the app tells PostHog not to build a profile from it. The ID is replaced when you delete your local data ("Delete local data", in Settings).
- Where it goes. To PostHog, our analytics provider. Like any internet request, the connection carries your IP address. The app does not add it to the usage data.
- On by default, and you can turn it off. Nothing is sent until the app has shown you the switch: on the Messages step of setup, in Settings, or in a one-time notice on Home and on the Stories screen. What happens before that, like opening the app, is kept on your Mac and sent only once you have seen the switch. If you turn it off first, or quit before you see it, that is discarded and never sent. Turn off "Share anonymous usage" on the Messages step of setup or in Settings at any time. Turning it off also drops anything not yet sent.
- Some copies send nothing. A copy of the app built without our analytics key sends no usage data and shows no switch.
Accounts
You don't need an account to use Read Receipts. Reading and counting your archive work without one.
- An anonymous account for reads. The first time a read is sent, after you have said yes to reads, or the first time you send feedback from the app, whichever comes first, the app creates an anonymous ARKHIVE account. It has no name, email address or phone number. It exists so we can limit how many free reads are made, each day and in all. Its sign-in is kept in your Mac's keychain.
- Signing in is optional. You can sign in with Apple, or with an ARKHIVE account you created by texting ARKHIVE. If you sign in with Apple, the app carries your anonymous account into it when it can. Your ARKHIVE account is covered by ARKHIVE's privacy policy.
Notifications
The app offers the midweek heads-up only after you have said yes to reads, since the morning read is what makes it ready. If you say yes to it, the app schedules one notification on your Mac for Wednesday morning. It is created on your Mac, not sent from our servers. It names nobody and says nothing about your messages: it reads "Your midweek read is ready." It is skipped if you have already read your week. You can turn it off in Settings.
Feedback
- In the app. "Send feedback" works before you sign in or ask for a read. It sends your note and its type (bug, wrong read or idea) to ARKHIVE's server, with your app version, your ARKHIVE account ID, a reply email address if you give one, and the diagnostics the sheet shows you before you send: app and macOS versions, your Mac model and chip, which screen you were on and which setup step you reached, whether Messages and Contacts access are on, how many conversations your last read covered, how long recent reads and counts took, and recent error codes. Diagnostics never include your messages, names or contacts, and you can leave them out. We store the feedback in our database, tied to your ARKHIVE account, and email it to the team. If sending fails, you can send it from your own mail app instead.
- On the website. The feedback box on readreceipts.ai emails your note, your email address if you give one, and your browser's user agent to the team, through Resend, our email provider. We do not store it anywhere else.
- "Email me the link" on the website. We use your email address to send you the download link, and keep it as a contact with Resend, our email provider.
Deleting your data
- On your Mac. In Settings, under "Your data", press "Delete local data…". The app asks first ("Delete local data?"), and nothing is deleted until you press Delete local data. That removes your counted archive, your saved stories and their chats (including YOU), your saved reads and the app's summary of your month, your Ask chats, your answers to the app's questions, your corrections, and what you marked on cards. It also forgets your yes to sending reads, withdraws a pending midweek notification and forgets your answer to it, and replaces your usage install ID. Then the app starts over at setup, and it does not read your Messages again until you press Begin. Your Messages and Contacts are not changed, your choice about sharing anonymous usage is kept, and you stay signed in: use Sign out in Settings for that.
- On our servers. To delete your ARKHIVE account and the read and feedback records tied to it, email privacy@arkhive.space. If you never signed in, your anonymous account has no name, email address or phone number, so we may not be able to find it from your request. Usage data is tied only to a random install ID, so we cannot find it to delete it for you.
Changes and contact
When this policy changes, we will update the date at the top. Questions or requests? Email privacy@arkhive.space.