What the app collects besides your messages
The conversation is the obvious data and it is not the only data. A companion app, like any consumer app, collects account identifiers, device information, usage telemetry and purchase events, and each of those is described in a different part of a privacy policy. The category that people miss is the third one, because on this particular kind of product it describes something quite specific.
Five categories, all disclosed separately
Account identifiers. An email address, sometimes a phone number, sometimes an identity from a sign-in provider. Where a third-party sign-in is used, that provider learns you use the app, which is a disclosure that happens at the moment you tap the button and is not mentioned again.
Device and technical data. Model, operating system version, language, region, an advertising or installation identifier, and an IP address, which resolves to an approximate location without any location permission being granted. This is collected by essentially all mobile software and is usually listed under a heading like information we collect automatically.
Usage telemetry. Session start and end times, session length, number of messages sent, screens visited, buttons pressed, features used, notifications opened. This is the standard product-analytics set and it is what makes the product measurable.
Purchase and billing events. What tier you are on, when you upgraded, what you were doing shortly beforehand, whether you cancelled, whether you responded to an offer. Card details themselves normally sit with a payment processor rather than the operator.
Derived data. Anything computed from the above: a segment, a lifecycle stage, a propensity score, a churn risk. Policies describe this as inferences or derived information, and it is the category with the least visibility because none of it was submitted by you.
Why the telemetry category is the interesting one here
Telemetry is unremarkable in a weather app. On a companion app the same fields describe when you are alone, how late you stay up, how long you talk, how the frequency changes week to week, and which days you did not open it. The metadata is behaviourally specific even with the message text removed, and it is collected for ordinary reasons.
Those reasons are worth stating plainly because they are not sinister. Product teams need retention and engagement figures to know whether the thing works. Engineering needs error and latency data. Growth needs to know which onboarding step loses people. And the same numbers are what make an upgrade prompt’s placement measurable — the telemetry is not gathered in order to find a moment, but it is what a moment gets found in.
Permissions are a separate question from policies
A policy describes what is collected. The operating system’s permission list describes what the app has asked for access to, and the two are worth comparing.
Microphone access is needed for spoken input, and speech is handled by a separate system with its own retention. Photo library access is needed if you upload an image. Notification permission is needed to send you anything when the app is closed, which is the mechanism behind messages you did not ask for. Contacts, precise location and calendar access have no obvious function in a text conversation, so if one is requested the useful move is to note what the app says it is for.
Permissions are also revocable after the fact, individually, in the operating system settings, which is one of the few controls in this entire subject that is entirely yours.
THE PRODUCT — everything except the messages
· "We collect information you provide"
→ one of five categories. Identifiers,
device data, telemetry, purchases and
inferences are the others.
· Session times, message counts, streaks
→ ordinary product analytics, which on
this product describe when you are
alone.
· Inferences
→ data about you that you never submitted
and cannot see.
· An IP address
→ approximate location, with no location
permission involved.
· What is collected and for how long
→ THE OPERATOR DECIDES, and the policy
states today's list.
· The specific list for any app
→ CHECK THE POLICY. Search for
"automatically", "device", "analytics",
"inferences", "advertising".
What you can check
Read the app store’s data disclosure section. Both major stores require developers to declare what categories they collect and whether data is linked to identity or used for tracking. It is a summary rather than the full picture, it is self-declared, and it is far shorter than a policy, which makes it the fastest first look available.
Compare that against the permission list. A permission with no visible function in the product is worth a question. Revoke the ones you do not need; the app will tell you if something stops working.
Search the policy for “analytics” and “advertising”. These find third-party software development kits embedded in the app, which is how telemetry commonly reaches companies other than the operator. Naming the categories is normal; naming the specific providers is better disclosure.
Look for a data controls or privacy screen in settings. Where an analytics opt-out or a personalised-ads toggle exists, that is where it is, and it is generally not surfaced during onboarding.
What this doesn’t tell you
It does not tell you what any particular app collects. The categories above are what is available to collect and what policies conventionally disclose, not a claim about anyone’s practice.
It does not tell you where the data goes after collection, which is what the retention and third-party sections of a policy address.
And it does not tell you that any of this is being used against you. Most of it is used to run and sell a product, which is the mundane and accurate version, and it is still worth knowing the shape of.