Private Thoughts
The spaceWhat’s insidePrivacyFAQ

Privacy by design

Privacy Policy

How Private Thoughts separates your private app content from the limited measurement needed to operate its website.

Effective date: August 5, 2026
On this page
General1. Who we are
2. Optional support communication
3. Why we process information
4. Service providers and transfers
5. Retention
6. Your rights
7. Children
8. Security, updates, and contact
Website9. Website analytics and technical data
Private Thoughts App10. Private content inside the application
11. Local encryption and personal analytics
12. Encrypted manual and optional cloud backup

General

1. Who we are

SERENITY RESEARCH AND INNOVATION SRL, CUI 41490155, Trade Register number J2019003117121, Str. Mihai Românul nr. 13, Sc. A, Et. 7, Ap. 68, Cluj-Napoca, Cluj County, Romania, provides Private Thoughts and acts as controller for personal data that we actually receive through the website or voluntary support communication.

We do not receive or control private app content, whether it remains local or you place an encrypted recovery copy in your own cloud account.

2. Optional support communication

If you choose to report a bug, send feedback, or contact support, we process the message, request category, an optional email address, and limited technical context: application version, operating-system version, device model, locale, and request time. We do not automatically attach private app content, a device identifier, an advertising identifier, or a persistent tracking identifier. Attachments are not supported.

Do not include Notes, Journals, Journey content, passwords, or other sensitive information. An email address is used only to reply. Requests are stored in our support database hosted in the AWS Frankfurt region and accessed by authorised staff currently located in Romania.

3. Why we process information

Depending on the context, we process information to provide requested support, operate and secure the website, comply with legal duties, and understand aggregated website performance. The applicable legal bases may include performance of a contract, consent, compliance with legal obligations, and our legitimate interest in operating a secure and useful service.

4. Service providers and transfers

Relevant providers may include Amazon Web Services and CloudFront for website and support infrastructure, Google Workspace for email, Google Analytics 4 after consent, Apple for App Store, StoreKit, iCloud and iCloud Keychain services, and Google for Google Play Billing and Google Drive app data services. They process information under their own terms or on our behalf, depending on the service.

Where information is transferred outside the European Economic Area, we or the responsible provider use an available lawful transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, and appropriate safeguards.

5. Retention

Local content remains on your device until you delete it, remove all app data, or uninstall the application. An optional cloud backup remains until you delete it, replace it under the backup lifecycle, or remove it through the applicable flow or provider account.

Support requests are retained for up to 12 months after closure unless a longer period is required for a dispute, security investigation, or legal obligation. Product suggestions may then be retained only in anonymised form. Security and rate-limiting logs are normally retained for no more than 30 days. Google Analytics retention is configured for 14 months, and the browser consent preference is stored for up to 12 months.

6. Your rights

Where the GDPR applies, you may have rights of access, correction, deletion, restriction, portability, objection, and withdrawal of consent. Send a request to [email protected]. We may request limited information needed to verify the request without collecting unnecessary identity data. You may also complain to the competent data protection authority. These rights apply to personal data we actually control; content stored only on your device remains directly under your control through the application.

7. Children

Private Thoughts is not specifically directed or marketed to children and does not ask for age. If local law requires a parent or legal guardian to be involved, the responsible adult should review the Terms and the application's privacy, purchase, and recovery choices.

8. Security, updates, and contact

We use technical and organisational safeguards appropriate to the information we process. No device, software, network, or storage method can be guaranteed absolutely secure.

We may update this Policy when the product, providers, or legal requirements change. For privacy requests, use the Support section inside the application or email [email protected]. The legal entity is SERENITY RESEARCH AND INNOVATION SRL, CUI 41490155, Trade Register number J2019003117121, Str. Mihai Românul nr. 13, Sc. A, Et. 7, Ap. 68, Cluj-Napoca, Cluj County, Romania.

Website

9. Website analytics and technical data

The website may use Google Analytics 4 only after you give explicit analytics consent. We use it to understand visits, performance, referral sources, and interactions. We do not use advertising features, remarketing, Google Signals, advertising identifiers, or analytics inside the application. Analytics retention is configured for 14 months.

Amazon Web Services and CloudFront may process limited technical information, such as IP address, browser information, requested URL, request time, and security events, when necessary to deliver and protect the website. Security logs are normally retained for no more than 30 days unless needed for an incident. Website measurement is never used to access or infer content stored inside the application.

Private Thoughts App

10. Private content inside the application

The application may store the following content in app-private storage on your device:

  • Notes, Journal entries, moods, Journey goals, checkpoints, and connected context.
  • Images, audio, stickers, rich-text structure, exports, and other media you add.
  • Local profile information, settings, reminder preferences, and application state.

11. Local encryption and personal analytics

Private app content is stored in encrypted local storage. The application does not send us your writing, moods, goals, advertising identifiers, or product telemetry.

The Journal, Notes, and Journey analytics visible inside the application are personal insights calculated locally from your own content. They are not website analytics and are not transmitted to us for profiling or advertising.

The application does not include third-party analytics, telemetry, advertising, or crash-reporting SDKs. Apple and Google may provide platform-level diagnostics only for users who enabled diagnostic sharing in their device or store settings; their own privacy terms apply.

Purchases are processed and verified locally through Apple StoreKit or Google Play Billing. We do not operate a payment or purchase-tracking backend and do not receive payment-card details, store passwords, purchase receipts, purchase tokens, or order identifiers from the application.

12. Encrypted manual and optional cloud backup

Cloud backup is disabled by default. If you explicitly enable it, your working data remains on the device and the application creates a separate encrypted recovery copy before upload. The cloud provider receives an encrypted container and limited technical metadata required to store, verify, list, and restore the backup, not your readable Notes, Journals, Journey goals, or media.

On iOS, private iCloud app storage may be used and the backup key may be recoverable through iCloud Keychain when available. On Android, backup may use the hidden Google Drive app data folder. Multiple versions and backups from different devices may be visible. Backup is not live sync, restore requires an explicit action, and losing every usable key or recovery method makes the readable content unrecoverable, including by us.

The readable backup key is not stored inside the cloud backup. The backup contains a password-protected recovery envelope that your saved recovery code can unlock. On iOS, a key record may synchronize separately through end-to-end encrypted iCloud Keychain. We do not receive your readable backup key or recovery code.

Manual backup files are also encrypted and are created, saved, or shared only when you choose. You select where an exported backup file is stored and are responsible for protecting that location and the applicable recovery method.

Private Thoughts

A private space for the thoughts, feelings, and plans that shape your life.

ExploreThe spaceWhat’s insidePrivacyFAQ
Terms & PrivacyTerms & ConditionsPrivacy PolicyWebsite Cookie Policy
CompanySERENITY RESEARCH AND
INNOVATION SRL
CUI 41490155Contact: [email protected]
© 2026 Private ThoughtsYour space stays yours.