Privacy policy
Last updated: 14 August 2026
1. Who is responsible
OPERATOR_LEGAL_NAME, an Enkeltmandsvirksomhed in Denmark, postal address OPERATOR_ADDRESS (“Thinline”, “we”, “us”) is responsible for the personal data described in this notice.
Privacy contact: josipmiljak@proton.me
Postal address: OPERATOR_LEGAL_NAME
Enkeltmandsvirksomhed, Denmark
OPERATOR_ADDRESS
Data Protection Officer: We have not appointed a DPO. We are not a public authority, we do not monitor people on a large scale as a core activity, and we do not process special-category data on our systems as a core activity.
EU representative: Not appointed. We are established in Denmark, in the EU.
2. What Thinline does
Thinline is a private self-reflection app. It lets you track categories based on the seven deadly sins, write notes and journal entries, work through a panic flow, view patterns, and buy a subscription. It is not medical care, professional counseling, addiction treatment, crisis support, or pastoral authority.
There is no account. You do not give us an email address, a phone number or a name, and we do not create a user record for you.
The app is intended for adult self-reflection. You must be at least 16 years old to use Thinline. We do not ask for your date of birth, and the app is not directed at children.
3. Where your data lives
Everything you write in Thinline is stored in a database file on your phone and is never sent to us. That covers the categories you track, every tap you log, note text, journal entries, panic-flow notes and step recaps, and your app settings.
Authored panic-flow copy ships inside the app. The app fetches only our public operational-notices file from the marketing site's static hosting. That request carries no identifier and no content of yours. Thinline is not fully offline: it also talks directly to RevenueCat for subscriptions and Expo for updates, but there is no Thinline application server.
Panic-flow media. A drawing, a voice note or a photo taken during a panic session exists only for that session. It is held in temporary files on your phone and deleted when you leave the flow. It is never uploaded and never saved into your history. Only the words you type on the closing screen, and the timings of the steps, are kept — on your phone.
How the file on your phone is protected. The rows in it are not separately encrypted by Thinline. The protections are the operating system's own file encryption (iOS Data Protection, Android file-based encryption), which ties the file to your device passcode, and the optional in-app App Lock, which requires biometrics or your device passcode before Thinline will show anything. App Lock is not a subscription-only control; once enabled, it remains in force before the paid access utility surface and its export control. Anyone who can unlock your phone, or who extracts the file from an unlocked or unprotected device, can read what is in it.
Device backups. The database is deliberately included in iCloud Backup on iOS and Android Auto Backup on Android. Because we hold no copy, a device backup is one of only two ways you get your history back after losing a phone — the other is the export archive described in section 8. The consequence is that your Thinline data goes into Apple's or Google's backup service under their terms and their account security, and you can turn that off in your device settings.
4. What we actually receive
| What | When | Data |
|---|---|---|
| Static notices request | The app checks for operational notices | The network metadata any web request carries; locale resolution happens on the device |
| App update check | The app starts | The build's runtime version, channel and platform, sent to Expo's update service |
| Subscription | You buy, restore or hold a subscription | An anonymous identifier RevenueCat generates on your device, and the purchase and entitlement data described in section 6 |
Network metadata means the things a static host or vendor sees for any request: IP address, approximate time, and request headers. We do not operate our own application logs of these requests. Cloudflare may retain ordinary request metadata for the marketing site and notices file under Cloudflare's terms.
We do not receive your tracked categories, your counts, your notes, your journal entries, your panic records, or any media. We could not produce them if we were asked to.
Because of the app's religious framing and the personal nature of what people write, the data on your device may reveal religious beliefs, health, sex life or other highly sensitive information. That is exactly why none of it is sent to us.
5. Why we process data and our legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Serve operational notices as a static public file | Network metadata | Legitimate interests (GDPR Article 6(1)(f)): operating and securing a public static file that returns the same bytes to everyone |
| Provide and support paid subscriptions | Anonymous RevenueCat identifier, purchase and entitlement data | Contract (GDPR Article 6(1)(b)): providing the paid access you purchase through Apple or Google |
| Respond to rights requests and legal duties | The request and our correspondence | Legal obligation (GDPR Article 6(1)(c)) where the law requires us to respond, and otherwise legitimate interests (Article 6(1)(f)) in handling the request |
Special-category data. We do not receive the tracker, journal, or panic content on your phone. That content may include special-category information about you; it is not processed on any system of ours. We do not claim an Article 9 condition for data we actually receive. Ordinary network metadata and anonymous purchase identifiers are not treated as special-category data.
We do not rely on consent for the processing in the table above. If we ever ask for consent for a new purpose, you may withdraw it without affecting processing already carried out lawfully.
Our legitimate interests are operating the public notices channel, keeping the static site available and secure, and handling privacy or support mail we cannot otherwise identify. The data involved is ordinary request metadata or correspondence you send us. It does not include what you write in the app.
6. Who receives data
We do not use third-party advertising, behavioral-analytics or crash-reporting SDKs, and we send no marketing email. The complete list of parties that receive anything is:
- Cloudflare: statically hosts the marketing site and public notices file. It sees the network metadata of requests to those assets.
- RevenueCat, Inc.: subscription and entitlement management. The app never sends RevenueCat an email address, a name or any identifier of ours; the SDK uses an anonymous app user ID that it generates on your device. It receives purchase and entitlement data and the device and network data its SDK collects, under RevenueCat's terms.
- Apple (App Store, iOS) and Google (Google Play, Android): they run the purchase, hold the purchase records, and provide the operating-system services the app uses, under their own terms.
- Expo / 650 Industries, Inc.: app builds and over-the-air updates. It sees update-check requests from the app.
- Professional advisers, authorities, or a buyer of the business, where the law requires it or where it is necessary to run or transfer the service. We would still have no copy of what you wrote in the app.
Cloudflare R2 object storage, OpenAI, Resend and Twilio were used by earlier versions of Thinline and are no longer used by any part of the service. There is no AI feature, no media upload, and no email or SMS sent to app users.
We do not sell personal data.
7. Where data is processed
We are established in Denmark. Cloudflare, RevenueCat, Apple, Google, and Expo may process data in the United States and other countries under their own terms. Each publishes its own transfer safeguards, which often include Standard Contractual Clauses or an adequacy decision. We do not claim custom transfer contracts of our own beyond those vendors' standard terms.
Your tracked content is not transferred anywhere by us, because we never receive it. If you enable a device backup, Apple or Google process that backup in the locations set out in their own terms.
8. Your data on your device: keeping it, exporting it, deleting it
There is no onboarding, free tier, or device-local trial. If RevenueCat verifies that no active pro entitlement exists, the app presents its paid launch purchase screen after the splash and any App Lock handoff instead of mounting the ordinary screens. Active pro includes a subscription, an eligible monthly or annual store trial while active, or the lifetime purchase. Export and delete-all remain available through the data-control surface without payment or a time limit.
- Export. Settings → Backup → “Save a backup” writes an archive of everything on the device and hands it to your operating system's share sheet, so you choose where it goes. The archive is a ZIP containing a plaintext manifest that describes the file, plus the data itself. You can protect the data with a passphrase the app generates; it is then sealed with a key derived from that passphrase, and the passphrase is never sent anywhere and cannot be recovered by us or anyone else. This export is also the machine-readable copy you would use to exercise a portability right.
- Restore. Settings → Backup → “Restore from a backup” replaces everything on the device with the contents of an archive you choose.
- Delete. Settings → Delete all data erases the device database. It is irreversible and we hold no copy to restore. Uninstalling the app removes it as well. Neither action reaches a device backup you have already made, an export you have already saved, or the purchase records held by Apple, Google and RevenueCat.
After RevenueCat confirms active paid access, the app keeps a local confirmation timestamp and continues access for seven days from that confirmation. This is intended to cover unavailable entitlement checks, but it can also delay lockout after a subscription cancellation. A successful inactive store response overrides that grace. After deleting and reinstalling while offline, the app may lack both that timestamp and RevenueCat's cached state; an existing purchaser may then remain on the wall until the device gets online and restores purchase status.
9. How long we keep data
| What we hold | How long |
|---|---|
| Everything you write in the app | We never hold it. It stays on your device until you delete it there, and we cannot delete it for you. |
| Static-host request logs | We do not operate our own application logs. Cloudflare may retain ordinary request metadata under Cloudflare's terms. |
| Authored panic copy and notices | Not personal data. Panic copy ships in the app. Published notices remain in source control as operational records. |
| Purchase and entitlement records at RevenueCat, Apple and Google | Held by them under their own terms and retention. We do not keep a parallel customer database. |
| Rights-request correspondence | For as long as needed to handle the request and any related complaint or legal duty, then deleted. |
10. Your choices and rights
Depending on applicable law, you may request access, correction, erasure, restriction, objection, portability, or withdrawal of consent, and may complain to a supervisory authority.
Because we hold no user record, most of these rights have nothing on our side to act on. There is no account to look you up by, and asking us for a copy of your tracker data would produce nothing — the export in section 8 is how you get it, and it runs entirely on your phone.
Contact josipmiljak@proton.me. We may ask for proportionate verification and will normally respond within one month under GDPR, subject to lawful extensions or exceptions.
Lead supervisory authority: Datatilsynet (Denmark), datatilsynet.dk. You may also have a right to contact the supervisory authority where you live or work.
Subscriptions are cancelled through Apple or Google, not through us.
11. How we can reach you
We have no email address, phone number or push token for anyone using the app, so there is exactly one channel: a notice the app fetches and shows you when you open it. We use it for things like a security incident, a change of price, or the service shutting down.
Its limitation is real and worth stating: a notice only reaches people who open the app after it is published. Someone who has stopped using Thinline will not see it. If you want to be reachable another way, there is currently no way for us to offer that without collecting a contact detail we have chosen not to collect.
12. Security
The measures we rely on are: no Thinline application server and no remotely stored user content; a static public notices file that returns the same bytes to everyone; transport encryption; the operating system's file encryption on your device; the optional App Lock; and screen-capture prevention on the app's private screens.
The honest weaknesses are the ones named above: the rows on your device are plaintext, the database is carried into your iCloud or Google backup, App Lock is off by default, an offline reinstall can temporarily prevent subscription status from being restored, and our only way to warn you about anything reaches you only when you open the app.
No system is completely secure.
13. Changes
We will update the effective date and provide notice appropriate to the significance of a change, through the in-app notice channel described in section 11.
14. Contact
Privacy questions and rights requests: josipmiljak@proton.me
Postal address: OPERATOR_LEGAL_NAME
Enkeltmandsvirksomhed, Denmark
OPERATOR_ADDRESS
Support: josipmiljak@proton.me
If you or someone else may be in immediate danger, contact local emergency services or a qualified crisis service. Do not use the privacy mailbox for an emergency.