Thinline

Privacy policy

Last updated: 14 August 2026

1. Who is responsible

OPERATOR_LEGAL_NAME, an Enkeltmandsvirksomhed in Denmark, postal address OPERATOR_ADDRESS (“Thinline”, “we”, “us”) is responsible for the personal data described in this notice.

Privacy contact: josipmiljak@proton.me
Postal address: OPERATOR_LEGAL_NAME
Enkeltmandsvirksomhed, Denmark
OPERATOR_ADDRESS

Data Protection Officer: We have not appointed a DPO. We are not a public authority, we do not monitor people on a large scale as a core activity, and we do not process special-category data on our systems as a core activity.

EU representative: Not appointed. We are established in Denmark, in the EU.

2. What Thinline does

Thinline is a private self-reflection app. It lets you track categories based on the seven deadly sins, write notes and journal entries, work through a panic flow, view patterns, and buy a subscription. It is not medical care, professional counseling, addiction treatment, crisis support, or pastoral authority.

There is no account. You do not give us an email address, a phone number or a name, and we do not create a user record for you.

The app is intended for adult self-reflection. You must be at least 16 years old to use Thinline. We do not ask for your date of birth, and the app is not directed at children.

3. Where your data lives

Everything you write in Thinline is stored in a database file on your phone and is never sent to us. That covers the categories you track, every tap you log, note text, journal entries, panic-flow notes and step recaps, and your app settings.

Authored panic-flow copy ships inside the app. The app fetches only our public operational-notices file from the marketing site's static hosting. That request carries no identifier and no content of yours. Thinline is not fully offline: it also talks directly to RevenueCat for subscriptions and Expo for updates, but there is no Thinline application server.

Panic-flow media. A drawing, a voice note or a photo taken during a panic session exists only for that session. It is held in temporary files on your phone and deleted when you leave the flow. It is never uploaded and never saved into your history. Only the words you type on the closing screen, and the timings of the steps, are kept — on your phone.

How the file on your phone is protected. The rows in it are not separately encrypted by Thinline. The protections are the operating system's own file encryption (iOS Data Protection, Android file-based encryption), which ties the file to your device passcode, and the optional in-app App Lock, which requires biometrics or your device passcode before Thinline will show anything. App Lock is not a subscription-only control; once enabled, it remains in force before the paid access utility surface and its export control. Anyone who can unlock your phone, or who extracts the file from an unlocked or unprotected device, can read what is in it.

Device backups. The database is deliberately included in iCloud Backup on iOS and Android Auto Backup on Android. Because we hold no copy, a device backup is one of only two ways you get your history back after losing a phone — the other is the export archive described in section 8. The consequence is that your Thinline data goes into Apple's or Google's backup service under their terms and their account security, and you can turn that off in your device settings.

4. What we actually receive

WhatWhenData
Static notices requestThe app checks for operational noticesThe network metadata any web request carries; locale resolution happens on the device
App update checkThe app startsThe build's runtime version, channel and platform, sent to Expo's update service
SubscriptionYou buy, restore or hold a subscriptionAn anonymous identifier RevenueCat generates on your device, and the purchase and entitlement data described in section 6

Network metadata means the things a static host or vendor sees for any request: IP address, approximate time, and request headers. We do not operate our own application logs of these requests. Cloudflare may retain ordinary request metadata for the marketing site and notices file under Cloudflare's terms.

We do not receive your tracked categories, your counts, your notes, your journal entries, your panic records, or any media. We could not produce them if we were asked to.

Because of the app's religious framing and the personal nature of what people write, the data on your device may reveal religious beliefs, health, sex life or other highly sensitive information. That is exactly why none of it is sent to us.

5. Why we process data and our legal bases

PurposeDataLegal basis
Serve operational notices as a static public fileNetwork metadataLegitimate interests (GDPR Article 6(1)(f)): operating and securing a public static file that returns the same bytes to everyone
Provide and support paid subscriptionsAnonymous RevenueCat identifier, purchase and entitlement dataContract (GDPR Article 6(1)(b)): providing the paid access you purchase through Apple or Google
Respond to rights requests and legal dutiesThe request and our correspondenceLegal obligation (GDPR Article 6(1)(c)) where the law requires us to respond, and otherwise legitimate interests (Article 6(1)(f)) in handling the request

Special-category data. We do not receive the tracker, journal, or panic content on your phone. That content may include special-category information about you; it is not processed on any system of ours. We do not claim an Article 9 condition for data we actually receive. Ordinary network metadata and anonymous purchase identifiers are not treated as special-category data.

We do not rely on consent for the processing in the table above. If we ever ask for consent for a new purpose, you may withdraw it without affecting processing already carried out lawfully.

Our legitimate interests are operating the public notices channel, keeping the static site available and secure, and handling privacy or support mail we cannot otherwise identify. The data involved is ordinary request metadata or correspondence you send us. It does not include what you write in the app.

6. Who receives data

We do not use third-party advertising, behavioral-analytics or crash-reporting SDKs, and we send no marketing email. The complete list of parties that receive anything is:

Cloudflare R2 object storage, OpenAI, Resend and Twilio were used by earlier versions of Thinline and are no longer used by any part of the service. There is no AI feature, no media upload, and no email or SMS sent to app users.

We do not sell personal data.

7. Where data is processed

We are established in Denmark. Cloudflare, RevenueCat, Apple, Google, and Expo may process data in the United States and other countries under their own terms. Each publishes its own transfer safeguards, which often include Standard Contractual Clauses or an adequacy decision. We do not claim custom transfer contracts of our own beyond those vendors' standard terms.

Your tracked content is not transferred anywhere by us, because we never receive it. If you enable a device backup, Apple or Google process that backup in the locations set out in their own terms.

8. Your data on your device: keeping it, exporting it, deleting it

There is no onboarding, free tier, or device-local trial. If RevenueCat verifies that no active pro entitlement exists, the app presents its paid launch purchase screen after the splash and any App Lock handoff instead of mounting the ordinary screens. Active pro includes a subscription, an eligible monthly or annual store trial while active, or the lifetime purchase. Export and delete-all remain available through the data-control surface without payment or a time limit.

After RevenueCat confirms active paid access, the app keeps a local confirmation timestamp and continues access for seven days from that confirmation. This is intended to cover unavailable entitlement checks, but it can also delay lockout after a subscription cancellation. A successful inactive store response overrides that grace. After deleting and reinstalling while offline, the app may lack both that timestamp and RevenueCat's cached state; an existing purchaser may then remain on the wall until the device gets online and restores purchase status.

9. How long we keep data

What we holdHow long
Everything you write in the appWe never hold it. It stays on your device until you delete it there, and we cannot delete it for you.
Static-host request logsWe do not operate our own application logs. Cloudflare may retain ordinary request metadata under Cloudflare's terms.
Authored panic copy and noticesNot personal data. Panic copy ships in the app. Published notices remain in source control as operational records.
Purchase and entitlement records at RevenueCat, Apple and GoogleHeld by them under their own terms and retention. We do not keep a parallel customer database.
Rights-request correspondenceFor as long as needed to handle the request and any related complaint or legal duty, then deleted.

10. Your choices and rights

Depending on applicable law, you may request access, correction, erasure, restriction, objection, portability, or withdrawal of consent, and may complain to a supervisory authority.

Because we hold no user record, most of these rights have nothing on our side to act on. There is no account to look you up by, and asking us for a copy of your tracker data would produce nothing — the export in section 8 is how you get it, and it runs entirely on your phone.

Contact josipmiljak@proton.me. We may ask for proportionate verification and will normally respond within one month under GDPR, subject to lawful extensions or exceptions.

Lead supervisory authority: Datatilsynet (Denmark), datatilsynet.dk. You may also have a right to contact the supervisory authority where you live or work.

Subscriptions are cancelled through Apple or Google, not through us.

11. How we can reach you

We have no email address, phone number or push token for anyone using the app, so there is exactly one channel: a notice the app fetches and shows you when you open it. We use it for things like a security incident, a change of price, or the service shutting down.

Its limitation is real and worth stating: a notice only reaches people who open the app after it is published. Someone who has stopped using Thinline will not see it. If you want to be reachable another way, there is currently no way for us to offer that without collecting a contact detail we have chosen not to collect.

12. Security

The measures we rely on are: no Thinline application server and no remotely stored user content; a static public notices file that returns the same bytes to everyone; transport encryption; the operating system's file encryption on your device; the optional App Lock; and screen-capture prevention on the app's private screens.

The honest weaknesses are the ones named above: the rows on your device are plaintext, the database is carried into your iCloud or Google backup, App Lock is off by default, an offline reinstall can temporarily prevent subscription status from being restored, and our only way to warn you about anything reaches you only when you open the app.

No system is completely secure.

13. Changes

We will update the effective date and provide notice appropriate to the significance of a change, through the in-app notice channel described in section 11.

14. Contact

Privacy questions and rights requests: josipmiljak@proton.me
Postal address: OPERATOR_LEGAL_NAME
Enkeltmandsvirksomhed, Denmark
OPERATOR_ADDRESS
Support: josipmiljak@proton.me

If you or someone else may be in immediate danger, contact local emergency services or a qualified crisis service. Do not use the privacy mailbox for an emergency.