Thrennel

Privacy Policy

Last updated October 7, 2026

The short version

1. Who runs Thrennel

Thrennel (at thrennel.com) is run by Thrennel (“the operator”, “we”, “us”). The operator is responsible for your personal data under this policy (the “controller” under data protection law).

Contact: admin@thrennel.com

2. What we collect, and why

DataWhyLegal basis (EU/UK)
Account: username, password (stored only as a salted one-way hash, never in readable form), sign-up date, the invite code you used, your time zone, and the date and version of the Terms you accepted. To create and secure your account, and to show your days in your own time zone. Performance of our agreement with you (contract)
Your journal: everything you write or import (thoughts, notes, links, text read from images, imported files), and what the app derives from it (summaries, topics, connections, search index, action items, progress and milestones). This is the service: storing, organising and searching your journal. Contract
Waitlist requests: your email address, the optional note you leave, the date and the request status. Also whether you agreed to this policy when asking. To send you an invite when a spot opens. We do not use it for marketing. Your request (steps before a contract) and consent
Feedback: the message you send from Settings, with your username and the time. To answer you and fix problems. Legitimate interest in running and improving the service
Connection data: your IP address. The server holds it in memory for up to one hour, and its logs record it with each request. To limit repeated sign-in and sign-up attempts (brute-force protection), and to keep the service secure and fix problems. Legitimate interest in security
A sign-in cookie and a few browser-storage items, described in the Cookie Policy. To keep you signed in and remember your settings. Strictly necessary for the service you asked for

We do not collect your real name, phone number, location, contacts, payment details or advertising identifiers, and we do not use analytics or tracking tools. Thrennel does not ask for or require any of this.

A journal can contain very personal things, such as health, beliefs or relationships. Write only what you are comfortable storing. We process this content only to provide the service to you, at your direction.

3. How your journal is protected

Your journal is encrypted on the server’s disk with a key created from your password, and separately from your recovery code. The key itself is never stored in readable form. It is held only in the server’s memory while you are signed in, and it is discarded when you sign out or your session expires.

Please understand what this does and does not mean:

Connections to Thrennel use HTTPS. No system is perfectly secure; if a breach affects your personal data, we will tell you and any authority as the law requires.

4. AI features and who processes your data

When an AI feature runs (for example summarising a day, answering a question in Ask, sorting entries into topics, writing a weekly review, or reading an imported link or image), the text or image needed for that task is sent, in this order of preference, to:

  1. AI models on computers owned by the operator, reached over a private encrypted network (Tailscale). These run open-source models; nothing is sent to an outside AI company.
  2. Anthropic’s Claude API (Anthropic, PBC, USA), only if the operator’s computers are unavailable. Anthropic processes the data to return a result under its commercial terms, which say API data is not used to train its models; it may keep it for a limited time under its own policies, for example for safety monitoring.

Search works by turning entries into numerical “embeddings” with a model that runs on the Thrennel server itself.

The operator does not use your journal to train AI models and does not read it.

Other services involved

We share personal data with nobody else, except where the law requires it (for example a valid court order), and we would tell you about such a request unless legally prevented.

5. How long we keep it

6. Your choices and rights

If you are in the EU, EEA or UK, you also have the right to restrict or object to processing, to withdraw consent at any time (without affecting earlier processing), and to complain to your local data protection authority. Thrennel stores data in the United States; by using it you understand your data will be processed there, under the safeguards described in this policy.

If you are in California (and similar US states): we do not sell or “share” personal information for cross-context behavioural advertising, and do not use sensitive personal information except to provide the service you asked for. You may ask what we hold about you, and ask us to correct or delete it. We will not treat you differently for using these rights.

Do Not Track and Global Privacy Control: Thrennel does not track you across websites and has no advertising or analytics, so there is nothing to switch off. These signals are respected by default.

We answer requests within 30 days (45 days where California law allows). We may need to confirm the request comes from the account owner, usually by asking you to send it while signed in.

7. Age

Thrennel is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you believe a minor has an account, contact us and we will delete it.

8. Changes to this policy

If we change this policy, we will update the date at the top. If a change is significant, we will tell you in the app before it takes effect.

9. Contact

Questions or requests about your data: admin@thrennel.com. Signed-in users can also use Settings → Feedback.