General
1. Who we are
SERENITY RESEARCH AND INNOVATION SRL, CUI 41490155, Trade Register number J2019003117121, Str. Mihai Românul nr. 13, Sc. A, Et. 7, Ap. 68, Cluj-Napoca, Cluj County, Romania, provides Private Thoughts and acts as controller for personal data that we actually receive through the website or voluntary support communication.
We do not receive or control private app content, whether it remains local or you place an encrypted recovery copy in your own cloud account.
2. Optional support communication
If you choose to report a bug, send feedback, or contact support, we process the message, request category, an optional email address, and limited technical context: application version, operating-system version, device model, locale, and request time. We do not automatically attach private app content, a device identifier, an advertising identifier, or a persistent tracking identifier. Attachments are not supported.
Do not include Notes, Journals, Journey content, passwords, or other sensitive information. An email address is used only to reply. Requests are stored in our support database hosted in the AWS Frankfurt region and accessed by authorised staff currently located in Romania.
3. Why we process information
Depending on the context, we process information to provide requested support, operate and secure the website, comply with legal duties, and understand aggregated website performance. The applicable legal bases may include performance of a contract, consent, compliance with legal obligations, and our legitimate interest in operating a secure and useful service.
4. Service providers and transfers
Relevant providers may include Amazon Web Services and CloudFront for website and support infrastructure, Google Workspace for email, Google Analytics 4 after consent, Apple for App Store, StoreKit, iCloud and iCloud Keychain services, and Google for Google Play Billing and Google Drive app data services. They process information under their own terms or on our behalf, depending on the service.
Where information is transferred outside the European Economic Area, we or the responsible provider use an available lawful transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, and appropriate safeguards.
5. Retention
Local content remains on your device until you delete it, remove all app data, or uninstall the application. An optional cloud backup remains until you delete it, replace it under the backup lifecycle, or remove it through the applicable flow or provider account.
Support requests are retained for up to 12 months after closure unless a longer period is required for a dispute, security investigation, or legal obligation. Product suggestions may then be retained only in anonymised form. Security and rate-limiting logs are normally retained for no more than 30 days. Google Analytics retention is configured for 14 months, and the browser consent preference is stored for up to 12 months.
6. Your rights
Where the GDPR applies, you may have rights of access, correction, deletion, restriction, portability, objection, and withdrawal of consent. Send a request to [email protected]. We may request limited information needed to verify the request without collecting unnecessary identity data. You may also complain to the competent data protection authority. These rights apply to personal data we actually control; content stored only on your device remains directly under your control through the application.
7. Children
Private Thoughts is not specifically directed or marketed to children and does not ask for age. If local law requires a parent or legal guardian to be involved, the responsible adult should review the Terms and the application's privacy, purchase, and recovery choices.
8. Security, updates, and contact
We use technical and organisational safeguards appropriate to the information we process. No device, software, network, or storage method can be guaranteed absolutely secure.
We may update this Policy when the product, providers, or legal requirements change. For privacy requests, use the Support section inside the application or email [email protected]. The legal entity is SERENITY RESEARCH AND INNOVATION SRL, CUI 41490155, Trade Register number J2019003117121, Str. Mihai Românul nr. 13, Sc. A, Et. 7, Ap. 68, Cluj-Napoca, Cluj County, Romania.
Website
9. Website analytics and technical data
The website may use Google Analytics 4 only after you give explicit analytics consent. We use it to understand visits, performance, referral sources, and interactions. We do not use advertising features, remarketing, Google Signals, advertising identifiers, or analytics inside the application. Analytics retention is configured for 14 months.
Amazon Web Services and CloudFront may process limited technical information, such as IP address, browser information, requested URL, request time, and security events, when necessary to deliver and protect the website. Security logs are normally retained for no more than 30 days unless needed for an incident. Website measurement is never used to access or infer content stored inside the application.
Private Thoughts App
10. Private content inside the application
The application may store the following content in app-private storage on your device:
- Notes, Journal entries, moods, Journey goals, checkpoints, and connected context.
- Images, audio, stickers, rich-text structure, exports, and other media you add.
- Local profile information, settings, reminder preferences, and application state.
11. Local encryption and personal analytics
Private app content is stored in encrypted local storage. The application does not send us your writing, moods, goals, advertising identifiers, or product telemetry.
The Journal, Notes, and Journey analytics visible inside the application are personal insights calculated locally from your own content. They are not website analytics and are not transmitted to us for profiling or advertising.
The application does not include third-party analytics, telemetry, advertising, or crash-reporting SDKs. Apple and Google may provide platform-level diagnostics only for users who enabled diagnostic sharing in their device or store settings; their own privacy terms apply.
Purchases are processed and verified locally through Apple StoreKit or Google Play Billing. We do not operate a payment or purchase-tracking backend and do not receive payment-card details, store passwords, purchase receipts, purchase tokens, or order identifiers from the application.
12. Encrypted manual and optional cloud backup
Cloud backup is disabled by default. If you explicitly enable it, your working data remains on the device and the application creates a separate encrypted recovery copy before upload. The cloud provider receives an encrypted container and limited technical metadata required to store, verify, list, and restore the backup, not your readable Notes, Journals, Journey goals, or media.
On iOS, private iCloud app storage may be used and the backup key may be recoverable through iCloud Keychain when available. On Android, backup may use the hidden Google Drive app data folder. Multiple versions and backups from different devices may be visible. Backup is not live sync, restore requires an explicit action, and losing every usable key or recovery method makes the readable content unrecoverable, including by us.
The readable backup key is not stored inside the cloud backup. The backup contains a password-protected recovery envelope that your saved recovery code can unlock. On iOS, a key record may synchronize separately through end-to-end encrypted iCloud Keychain. We do not receive your readable backup key or recovery code.
Manual backup files are also encrypted and are created, saved, or shared only when you choose. You select where an exported backup file is stored and are responsible for protecting that location and the applicable recovery method.
