Privacy

Privacy policy

Thynkr is a guided-thinking app. This policy explains the information handled by the iPhone and iPad app, why it is used, and the choices available to you.

Effective date

2026-07-23

Who operates Thynkr

Legal operator: Miguel Fierro Muñoz

Postal address: Canal de la Mancha 2800, Col. Francisco I. Madero, C.P. 52172, Metepec, Estado de México, Mexico

Privacy-request email: thynkrapp@gmail.com

Information Thynkr handles

When you use Thynkr without an account

The core ritual can be used as a guest. Ritual drafts, conclusions, private reflections, Journey progress, Realm progress, and preferences are stored on your device unless you connect an account. Deleting the app may remove device-only information.

When you connect an Apple account

Sign in with Apple may provide an account identifier, name, and email according to the choices you make with Apple. Thynkr and its infrastructure provider use this information to create and authenticate your account.

Account-backed sync stores a user identifier, profile name, settings, ritual sessions and drafts, ritual questions you write, conclusions, private reflections, Journey entries, Realm progress, and related timestamps or revision information. This provides recovery and consistency across your devices.

Progress and usage information

Realm progress, completion history, preferences, and prompt interactions support your Stats, Journeys, recommendations, and sync. They are used for app functionality and product personalization, not advertising or cross-app tracking.

Onboarding location and age eligibility

Onboarding asks you to select your country, choose a city from a canonical autocomplete, and confirm that you are at least 16. The canonical city catalog is derived from GeoNames data under CC BY 4.0 so Worldwide comparisons use consistent city identities. It does not require GPS, precise device location, or IP-derived location. The values stay on your device unless you connect an account, when they are also stored with your profile.

Analytics and crash diagnostics

Thynkr does not include a third-party advertising, session-replay, crash-reporting, or general-purpose product-analytics SDK. RevenueCat's subscription SDK records App Store purchase status and limited paywall interactions—including impressions, dismissals, purchase-flow cancellations, and paywall-control use—so Thynkr can measure and improve subscription conversion. These events may include the RevenueCat app-user identifier, paywall and Offering identifiers, session identifier, platform and SDK versions, locale, display settings, and the control used. They do not include ritual questions, conclusions, private reflections, Ether thoughts, or Shared Ritual content. Apple may provide the operator with aggregated App Store performance information and opt-in crash diagnostics through App Store Connect and Xcode Organizer. Those Apple reports are subject to user sharing choices and Apple's privacy thresholds.

Supabase authentication and API security logs may retain an account identifier, authentication event, IP address, user agent, request route and status, and timestamp. Thynkr uses these operational diagnostics for authentication, abuse prevention, security, troubleshooting, and service reliability—not advertising or cross-app tracking.

Reflective nudges

On supported devices, Thynkr can use an Apple on-device model. For a signed-in ritual, when that model is unavailable, Thynkr may request one constrained reflective question through Supabase and OpenAI. The nudge service sends only the ritual question, Realm, difficulty, language, and a one-way hashed safety identifier. It excludes the raw account identifier, name, email, location, conclusion, private reflection, and Shared Ritual content.

Supabase stores limited account-linked request state, quota, model, attempt, token, timestamp, error-code, and successful-nudge data for idempotency, limits, and abuse prevention. OpenAI is instructed not to store the response for later retrieval. A signed-out, offline, failed, or unavailable request uses a built-in nudge.

Anonymous Shared Ritual synthesis

After every accepted participant deliberately submits a Shared Ritual reflection, Thynkr sends the shared question and the submitted reflections through Supabase to OpenAI to prepare one short aggregate analysis. Participant names, display names, account identifiers, emails, locations, device information, private solo journal text, and invite codes are excluded. Reflections are sent without attribution, OpenAI is instructed not to store the request or response for later retrieval, and Supabase retains only the resulting synthesis plus limited service-only model, attempt, token, timestamp, lease, and error-code metadata.

Purchases

For Release builds with subscriptions, Apple processes payment information. RevenueCat receives App Store purchase and subscription-status information to validate purchases, grant Deep Thynkr access, restore purchases, support subscription management, and provide subscription analytics. RevenueCat also processes the limited paywall interactions described above. Signed-in customers are identified with their Supabase user identifier, so purchase and paywall interaction history can be linked to the account. Thynkr does not receive complete payment-card or banking details.

Optional hosted feedback agent

The Thynkr website and the app’s Settings > Feedback section offer an optional link to a Stetos-hosted feedback agent. In the app, a privacy warning appears before you choose to leave Thynkr. Choosing the link opens a separate Stetos session; Thynkr does not embed that session or pass an account identifier, ritual text, invite code, payment detail, or other Thynkr content in the link. Text or voice you voluntarily provide there is submitted directly to Stetos and is subject to the notice and controls presented in that session. Do not use the feedback agent for private reflections, authentication information, payment information, or urgent safety concerns.

Not collected

Thynkr does not collect raw microphone audio, an unsaved on-device speech transcript, advertising identifiers, precise device location, or complete payment-card or banking details. Apple on-device model prompts and responses are not collected as a separate analytics stream.

Nudge processing and fallback

Thynkr prefers Apple on-device generation when available. A signed-in ritual may use the constrained Supabase/OpenAI fallback described above when the on-device model is unavailable. A built-in nudge keeps the ritual usable when the request cannot run or fails.

How information is used

Thynkr uses information to:

  • provide, restore, and synchronize rituals, Journeys, preferences, and progress;
  • authenticate accounts and support account deletion;
  • personalize question recommendations from completed practice;
  • provide optional on-device, constrained cloud-generated, or built-in reflective nudges;
  • validate purchases and maintain subscription access when subscriptions are enabled;
  • deliver content-free reminders that you request;
  • prevent abuse, enforce service limits, and maintain security; and
  • maintain reliability using aggregate Apple-provided performance and opt-in diagnostic reports.

Thynkr does not use this data for targeted advertising, does not sell it, and does not combine it with third-party data to track you across apps or websites.

Service providers

  • Apple for Sign in with Apple, system capabilities, App Store distribution, payments, aggregate analytics, and opt-in diagnostics.
  • Supabase for authentication, account-backed storage, database access controls, Edge Functions, and notification infrastructure.
  • OpenAI for one constrained reflective question when a signed-in user requests a nudge and Apple’s on-device model is unavailable, and for an anonymous aggregate analysis after all Shared Ritual participants submit.
  • RevenueCat for purchase validation, subscription entitlement, restore, and customer-management features when subscriptions are enabled.
  • Stetos only if you choose the optional hosted feedback-agent link from the website or the app’s Settings > Feedback section.

These providers may process information outside your country. Thynkr relies on their contractual safeguards and other lawful transfer mechanisms where required. Their own terms and privacy notices also apply.

Shared features

Ether and asynchronous Shared Rituals are available in the current beta. Synchronous multiplayer is not implemented. Shared Rituals store participant identifiers, display names, the shared question, submitted reflections exchanged between participants, ritual state, reports, and blocks. Invitations expire after seven days and retrievable ritual content expires after 30 days.

When a Shared Ritual completes, its question and intentionally submitted reflections are processed without participant attribution to create the anonymous synthesis described above. The synthesis is available only to accepted participants through the same membership-controlled Shared Ritual service.

For Shared Ritual notifications, Supabase stores an account-linked APNs device token, environment, locale, app version, and activity timestamps. Push payloads contain state and routing identifiers, not question or reflection text. Push tokens are removed on sign-out or account deletion and may be removed after inactivity.

An Ether offer enters a short-lived account-linked moderation intake and upload counters remain in a separate account-side record. Approval copies only the allowed thought, language, Realm, country/city, day bucket, and moderation fields, then deletes the intake author/session link. The accepted thought may remain after account deletion, but it stays removable for moderation, safety, legal requests, or personal-information leaks. City is withheld until at least five accepted thoughts share that country/city cohort. Free text plus a city can still identify a person, so Thynkr does not claim absolute anonymity.

Retention and deletion

Guest information remains on your device until you delete it in the app, delete the app, or migrate it to a connected account.

Account-backed information is retained while your account is active. In-app deletion requests immediate deletion of the Supabase Auth user and cascading account-owned records, then clears local credentials and the account namespace. A verified support-assisted request is targeted for completion within 30 days.

Push tokens are retained until sign-out, deletion, or removal after 90 days of inactivity. Resolved support/privacy correspondence is retained for 12 months, ordinary authentication/security logs for up to 90 days, minimal deletion-completion/legal records for up to 24 months, and deleted data in encrypted backups until normal rotation completes, targeted within 35 days.

Apple and RevenueCat may retain transaction records for tax, financial, refund, fraud, and legal duties. Deleting a Thynkr account does not cancel an App Store subscription. Legal holds, abuse investigations, and mandatory recordkeeping can require limited information to remain longer.

Your choices and rights

You can use the core ritual without an account, decline optional permissions, disable reminders, turn off on-device nudges, keep shared features unused, sign out, and initiate account deletion from Settings.

Depending on where you live, privacy rights may include access, correction, export, restriction, objection, deletion, withdrawal of consent, or a complaint to a data-protection authority. Email thynkrapp@gmail.com to make a request. Thynkr may need to verify that the request relates to your account.

Children

Thynkr is intended only for people aged 16 or older and is not directed to children under 16. If you are under 16, do not create an account or use Thynkr.

If you believe a person under 16 provided information, email thynkrapp@gmail.com so it can be reviewed and removed where appropriate.

Security

Thynkr uses account authentication, encrypted network transport, user-scoped database access controls, and restricted server functions. No system is completely secure, and this policy does not promise absolute security.

Changes to this policy

Thynkr may update this policy when the product, providers, or legal requirements change. The revised policy will carry a new effective date, with additional notice where required.

Contact

Miguel Fierro Muñoz
Canal de la Mancha 2800
Col. Francisco I. Madero
C.P. 52172, Metepec, Estado de México, Mexico
thynkrapp@gmail.com

For the current contact-channel status, see Thynkr Support.