Privacy Policy
The short version
- Thrennel is a private, invite-only journal. Your journal is stored encrypted with a key that only your password or recovery code can unlock.
- There are no ads, no analytics, no tracking pixels and no third-party cookies. Your data is never sold or shared for advertising.
- When you use AI features, the text needed for that task is processed by AI models on the operator’s own computers or, if those are offline, by Anthropic’s Claude API.
- You can export your journal at any time from Settings and ask for your account to be deleted.
1. Who runs Thrennel
Thrennel (at thrennel.com) is run by Thrennel (“the operator”, “we”, “us”). The operator is responsible for your personal data under this policy (the “controller” under data protection law).
Contact: admin@thrennel.com
2. What we collect, and why
| Data | Why | Legal basis (EU/UK) |
|---|---|---|
| Account: username, password (stored only as a salted one-way hash, never in readable form), sign-up date, the invite code you used, your time zone, and the date and version of the Terms you accepted. | To create and secure your account, and to show your days in your own time zone. | Performance of our agreement with you (contract) |
| Your journal: everything you write or import (thoughts, notes, links, text read from images, imported files), and what the app derives from it (summaries, topics, connections, search index, action items, progress and milestones). | This is the service: storing, organising and searching your journal. | Contract |
| Waitlist requests: your email address, the optional note you leave, the date and the request status. Also whether you agreed to this policy when asking. | To send you an invite when a spot opens. We do not use it for marketing. | Your request (steps before a contract) and consent |
| Feedback: the message you send from Settings, with your username and the time. | To answer you and fix problems. | Legitimate interest in running and improving the service |
| Connection data: your IP address. The server holds it in memory for up to one hour, and its logs record it with each request. | To limit repeated sign-in and sign-up attempts (brute-force protection), and to keep the service secure and fix problems. | Legitimate interest in security |
| A sign-in cookie and a few browser-storage items, described in the Cookie Policy. | To keep you signed in and remember your settings. | Strictly necessary for the service you asked for |
We do not collect your real name, phone number, location, contacts, payment details or advertising identifiers, and we do not use analytics or tracking tools. Thrennel does not ask for or require any of this.
A journal can contain very personal things, such as health, beliefs or relationships. Write only what you are comfortable storing. We process this content only to provide the service to you, at your direction.
3. How your journal is protected
Your journal is encrypted on the server’s disk with a key created from your password, and separately from your recovery code. The key itself is never stored in readable form. It is held only in the server’s memory while you are signed in, and it is discarded when you sign out or your session expires.
Please understand what this does and does not mean:
- Stored journal files and backups are unreadable without your password or recovery code.
- If you lose both your password and your recovery code, your journal cannot be recovered by anyone, including the operator.
- It is not end-to-end encryption. While you are signed in, the server decrypts your entries to show them to you and to run features such as search and AI. Data sent to AI services (section 4) is readable by them for that task.
- Account records (usernames and password hashes), waitlist requests and feedback messages are stored on the server without this extra journal encryption, protected by the server’s access controls.
Connections to Thrennel use HTTPS. No system is perfectly secure; if a breach affects your personal data, we will tell you and any authority as the law requires.
4. AI features and who processes your data
When an AI feature runs (for example summarising a day, answering a question in Ask, sorting entries into topics, writing a weekly review, or reading an imported link or image), the text or image needed for that task is sent, in this order of preference, to:
- AI models on computers owned by the operator, reached over a private encrypted network (Tailscale). These run open-source models; nothing is sent to an outside AI company.
- Anthropic’s Claude API (Anthropic, PBC, USA), only if the operator’s computers are unavailable. Anthropic processes the data to return a result under its commercial terms, which say API data is not used to train its models; it may keep it for a limited time under its own policies, for example for safety monitoring.
Search works by turning entries into numerical “embeddings” with a model that runs on the Thrennel server itself.
The operator does not use your journal to train AI models and does not read it.
Other services involved
- Hosting: Oracle Cloud Infrastructure, in a data centre in the United States (Ashburn, Virginia), stores the server and its data.
- Network: Tailscale provides the secure connection between the internet and the server, and between the server and the operator’s computers.
- Links you import: when you paste a link, the Thrennel server fetches that page, or for YouTube the video’s details and transcript, from the site that hosts it. That site sees the server’s address, not yours.
- Dictation: the microphone button uses your browser’s built-in speech recognition. Depending on your browser, your voice may be sent to the browser maker (for example Google for Chrome, Microsoft for Edge or Apple for Safari) to be turned into text. Thrennel only receives the resulting text. The app asks before you use it the first time.
- Fonts are served from Thrennel’s own server, so loading a page sends nothing to a font provider.
We share personal data with nobody else, except where the law requires it (for example a valid court order), and we would tell you about such a request unless legally prevented.
5. How long we keep it
- Your journal: until you delete entries or your account is deleted.
- Backups: the server takes an encrypted daily snapshot. The newest 14 are kept on the server and copies on the operator’s own computer, so a deleted item can survive in backups for up to about 14 days before it rotates out. Journal content in backups stays encrypted.
- Waitlist requests: until you are invited and sign up, or until you ask us to remove you.
- Feedback: until the operator dismisses it, and never more than the 500 most recent messages.
- IP addresses: held in the server’s memory for up to one hour. The server’s logs, which record the IP address of each request, are size-limited and overwritten automatically as they fill.
6. Your choices and rights
- Access and portability: download your whole journal as Markdown or JSON from Settings → Export your journal at any time.
- Correction: edit any entry in the app, or ask us to correct your account details.
- Deletion: delete entries yourself in the app. To delete your whole account and journal, contact us from your account or at the contact above; we will do it within 30 days and confirm.
- Waitlist: ask us at any time to remove your email.
If you are in the EU, EEA or UK, you also have the right to restrict or object to processing, to withdraw consent at any time (without affecting earlier processing), and to complain to your local data protection authority. Thrennel stores data in the United States; by using it you understand your data will be processed there, under the safeguards described in this policy.
If you are in California (and similar US states): we do not sell or “share” personal information for cross-context behavioural advertising, and do not use sensitive personal information except to provide the service you asked for. You may ask what we hold about you, and ask us to correct or delete it. We will not treat you differently for using these rights.
Do Not Track and Global Privacy Control: Thrennel does not track you across websites and has no advertising or analytics, so there is nothing to switch off. These signals are respected by default.
We answer requests within 30 days (45 days where California law allows). We may need to confirm the request comes from the account owner, usually by asking you to send it while signed in.
7. Age
Thrennel is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you believe a minor has an account, contact us and we will delete it.
8. Changes to this policy
If we change this policy, we will update the date at the top. If a change is significant, we will tell you in the app before it takes effect.
9. Contact
Questions or requests about your data: admin@thrennel.com. Signed-in users can also use Settings → Feedback.