Privacy Policy
This Privacy Policy explains how ZenThoughts handles personal data. It is a privacy notice, not a request for blanket consent and not a waiver of your rights.
1. Who We Are
The controller responsible for ZenThoughts is:
- Kanstantsin Ausianovich
- Individual developer, Republic of Lithuania
- Email: zenthoughtsapp@gmail.com
In this Policy, “ZenThoughts,” “I,” and “my” refer to the service and its developer, as applicable.
2. Scope
This Policy applies to the ZenThoughts mobile application, its account and backend services, and the website pages that publish this Policy and the Terms of Use. ZenThoughts is offered globally, including in the European Union and European Economic Area (“EU/EEA”), the United Kingdom, and the United States.
The legal website is static and does not use JavaScript, analytics, advertising, tracking pixels, or cookies. Third-party sites linked from ZenThoughts have their own privacy practices.
3. Age Eligibility
ZenThoughts is intended for people aged 13 and older. It is not directed to children under 13, and I do not knowingly allow a child under 13 to create an account or submit personal data.
If you are 13 or older but below the age at which you may consent to relevant data processing or enter into these Terms by yourself under local law, use ZenThoughts only with the involvement and authorization of a parent or legal guardian where required.
If you believe a child provided personal data contrary to these rules, contact zenthoughtsapp@gmail.com. I will investigate and delete the data where required.
4. Information We Process
Persistent identifiers described below are pseudonymous rather than truly anonymous when they can distinguish a device, installation, or customer record.
| Category | Data | Where and linkage | Purpose |
|---|---|---|---|
| Account and profile | Name, email address, internal ZenThoughts user ID, authentication provider | DigitalOcean Droplet and PostgreSQL in Frankfurt, Germany (fra1); linked to your account |
Create and authenticate the account, display the profile, provide account features |
| Authentication and session | Apple or Google identity token and, for Apple, authorization code; ZenThoughts access and refresh session data | Provider credential is transmitted to the ZenThoughts API for exchange and used transiently; ZenThoughts session credentials are stored securely on your device and processed by the service | Sign-in, session security, refresh, reauthentication, logout, account deletion |
| Public comments | Comment body, author display name, timestamps, associated affirmation, account association | DigitalOcean fra1; linked to your account; comment content, display name, and time are visible to other users |
Publish comments, maintain conversations, prevent abuse, enforce Terms, moderate content |
| Synchronized app state | Favorites, collections and titles, preferences, selected styles, likes, share events, associated affirmation identifiers and timestamps | DigitalOcean fra1; linked to your account |
Synchronization, personalization, saved content, engagement features |
| Push notifications | APNs device token, random installation ID, platform, locale, time zone, notification schedule, registration state | DigitalOcean fra1 and Apple Push Notification service |
Deliver requested personalized reminders and manage their schedule |
| Subscriptions and purchases | RevenueCat-generated anonymous App User ID; product identifiers; receipt-derived transaction, entitlement, subscription, purchase, renewal, and expiration status supplied through Apple | RevenueCat and Apple; ZenThoughts does not send your name, email, internal user ID, or purchase records to its own server for this purpose | Validate entitlements, restore purchases, show subscription access, provide subscription support |
| Product analytics | Random PostHog analytics ID, selected feature events, event time, app version, operating-system and device characteristics | PostHog Cloud EU in Frankfurt; not linked by ZenThoughts to your account | Understand feature use and improve the product after opt-in |
| Errors and crashes | Random PostHog analytics ID, error or crash event, stack trace, app version, operating-system and device characteristics, deliberately limited debugging context | PostHog Cloud EU in Frankfurt; not linked by ZenThoughts to your account | Diagnose failures and improve reliability after opt-in |
| Service and security logs | Request time, endpoint, response or error status, and limited network metadata that may include IP address | DigitalOcean fra1 |
Operate and secure the service, prevent abuse, investigate failures |
| Legal acceptance | Accepted Terms/EULA version and acceptance timestamp | DigitalOcean fra1; linked to your account |
Record the agreement that applies to your use of the service |
| On-device data | Catalog cache, settings, selected styles, favorites or collections awaiting synchronization, random provider identifiers, and secure session data | Your device unless a value listed above is synchronized | Offline use, performance, preferences, secure access, support requests |
I receive data directly from you, automatically from the app and device when you use a feature, from Apple or Google during authentication, from Apple and RevenueCat for purchases, and from service providers acting for the purposes described here.
Comments are public. Do not include your own or another person’s contact details, health data, precise location, financial information, credentials, or other sensitive or private information in a comment. If you choose to publish such information, other users may see it, and ZenThoughts may process it to host or moderate the comment.
5. How We Use Information and Legal Bases
Depending on your location and the feature involved, I rely on the following legal bases:
| Legal basis | Processing |
|---|---|
| Performance of a contract | Account creation, authentication, sessions, profile, synchronization, comments, subscription entitlement, requested notification delivery, support, and core app functionality |
| Consent | PostHog analytics and error/crash reporting; notification authorization where consent is required |
| Legitimate interests | Proportionate security logs, fraud and abuse prevention, service reliability, troubleshooting, enforcing the Terms, and moderating public content, balanced against your rights |
| Legal obligation | Records, disclosures, or retention required by applicable law or a valid legal process |
Acknowledging this Policy does not constitute consent for every processing activity. Where consent is the legal basis, the app requests it separately and you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal.
I do not use personal data for advertising, sell it, disclose it to data brokers, or track you across apps or websites owned by other companies. I do not use the information described here for solely automated decisions that produce legal or similarly significant effects.
6. Analytics and Diagnostics Choices
ZenThoughts uses PostHog Cloud EU in Frankfurt for product analytics and error/crash reporting only after you opt in. Both purposes use a random analytics identifier. ZenThoughts does not send PostHog your name, email address, ZenThoughts server user ID, RevenueCat App User ID, comments, other user-entered content, or deliberately selected sensitive data.
Session replay is disabled. The PostHog project is configured not to capture or retain raw IP addresses as event properties. Event and error properties must be reviewed so that direct identifiers, user content, authentication values, and sensitive information are not included.
You can decline analytics and diagnostics or turn them off later in ZenThoughts settings without losing paid access or core app functionality. Opting out stops future PostHog capture from the app. It does not automatically delete data already processed; use the privacy-request process below if you also want existing provider data deleted.
7. Push Notifications
ZenThoughts requests Apple notification authorization and registers with APNs only as needed to deliver reminders you enable. The server uses your random installation ID, APNs token, locale, time zone, and schedule to request delivery through Apple Push Notification service.
You may change the schedule or disable notifications in ZenThoughts. You may also withdraw system permission in Apple Settings. Disabling system permission prevents notification display, but the saved schedule or device registration may remain until you disable the feature in the app, delete your account, or ask for deletion, as applicable.
Notification permission is optional and is not required to access paid or core app functionality.
8. Subscriptions and Purchases
Apple processes payment, billing, and the underlying App Store transaction records. RevenueCat receives its generated anonymous App User ID and receipt-derived purchase and subscription information to validate entitlements and restore purchases. ZenThoughts does not use your name, email address, or internal server user ID as the RevenueCat App User ID, and the ZenThoughts server does not store purchase records.
“Anonymous App User ID” is RevenueCat’s name for its randomly generated identifier; it may still be personal data because it distinguishes a customer record and is associated with purchase history.
Deleting your ZenThoughts account or asking RevenueCat to delete a customer record does not cancel an Apple subscription or delete Apple’s transaction records. Manage or cancel Apple subscriptions at Apple’s subscription management page.
9. Service Providers and Recipients
I disclose data only as needed for the purposes in this Policy:
| Provider | Role |
|---|---|
| Apple | Sign in with Apple, App Store billing and transaction records, device services, and APNs delivery |
| Google identity authentication when you choose it | |
| DigitalOcean | Droplet and PostgreSQL infrastructure in Frankfurt, Germany (fra1) for account and service data |
| PostHog | Processor under a signed data processing agreement for opt-in analytics and error/crash reporting in PostHog Cloud EU, Frankfurt |
| RevenueCat | Subscription entitlement validation, purchase restoration, and subscription support using its generated App User ID |
Providers process data under their own legal obligations and applicable agreements with the controller. I may also disclose information when required by law, to protect users or the service, to investigate fraud or security incidents, or in connection with a lawful transfer of the service, subject to applicable notice and data-protection requirements.
10. International Transfers
Primary ZenThoughts backend data and PostHog Cloud EU data are hosted in Frankfurt, Germany. Apple, Google, DigitalOcean, PostHog, and RevenueCat may process limited operational, support, security, or transaction data in other countries where they or their subprocessors operate.
Where cross-border transfer rules apply, I rely on an adequacy decision, contractual safeguards made available by the provider, or another lawful transfer mechanism, as applicable. For transfers handled by PostHog outside the applicable protected area, the signed data processing agreement incorporates the EU controller-to-processor Standard Contractual Clauses (Module 2) and requires equivalent data-protection duties from subprocessors; PostHog remains responsible for their performance. EU hosting does not mean that support or operational access can never occur from outside the EU/EEA.
11. Retention
I retain data only as long as reasonably necessary for the purposes described above:
- Account-linked data is retained while your account is active.
- After account deletion, account data, public comments, and synchronized app state are deleted without undue delay unless limited retention is required for legal obligations, security, fraud prevention, dispute resolution, or establishing, exercising, or defending legal claims.
- Data in backups is removed as backups are overwritten through the normal backup cycle and is not restored to active systems except for disaster recovery, subject to applicable legal requirements.
- Minimal security and operational logs are retained only while needed for security, abuse prevention, troubleshooting, and legal obligations.
- Terms/EULA acceptance evidence is retained only while needed to establish the applicable agreement or resolve a legal claim.
- On-device data remains until you use an available reset or deletion control, clear app data, or remove the app, subject to synchronization already completed.
- PostHog and RevenueCat records follow the provider and verified controller-deletion processes described below. Apple retains App Store transaction records under its own policy and legal obligations.
Retention may vary because the criterion depends on account status, feature use, security needs, provider behavior, backup replacement, and applicable law. I do not use an unsupported fixed retention period where those facts control the appropriate duration.
12. Account Deletion and Privacy Requests
If you created a ZenThoughts account, you may initiate permanent account deletion from the account settings in the app. All users with accounts may use this control regardless of location. Account deletion removes the account and associated personal data controlled by ZenThoughts, including public comments, except for narrowly limited information that must lawfully be retained. When applicable, ZenThoughts also requests revocation of the Sign in with Apple credential associated with the deleted account.
Before deleting an account, cancel any Apple subscription you no longer want. Account deletion does not cancel billing, and deleting an account immediately may remove access to features while Apple billing continues.
You may also email zenthoughtsapp@gmail.com to request access, correction, deletion, restriction, portability, or objection where applicable. Describe the request and the account or device context needed to locate the data. I may ask for information reasonably necessary to verify that you are the relevant user and to prevent unauthorized disclosure or deletion.
Requests are handled without undue delay and within the period required by applicable law. A request may be limited or refused only where the law permits, such as when identity cannot reasonably be verified, the request adversely affects another person’s rights, or retention is legally required. I will explain an applicable refusal unless the law prevents that explanation.
13. Provider Data Requests
ZenThoughts provides one Contact Privacy Support action. It opens an email addressed to zenthoughtsapp@gmail.com and prefills the random PostHog analytics ID and RevenueCat anonymous App User ID currently available on your device. You can review, edit, or cancel the email before sending it. The IDs are not sent to me merely because you open the action.
These IDs help locate pseudonymous provider records without exposing your name, email address, or ZenThoughts server user ID to PostHog or RevenueCat. After verifying the request as reasonably necessary, I will use the providers’ administrative tools or APIs to request deletion of records controlled through those services where applicable.
Deleting a RevenueCat customer record clears that provider record but does not cancel an Apple subscription or delete Apple’s transaction history. If you continue using purchase features, make a new purchase, or restore purchases, RevenueCat may create or restore a customer record so that the entitlement can function. You may make another deletion request when appropriate.
14. Your Regional Rights
EU/EEA and United Kingdom
Where the GDPR or UK GDPR applies, you may have rights to access, correct, erase, restrict, or receive a portable copy of personal data; object to processing based on legitimate interests; withdraw consent; and complain to a supervisory authority. These rights are subject to statutory conditions and exceptions.
You may complain to the State Data Protection Inspectorate of the Republic of Lithuania, another competent EU/EEA supervisory authority, or the competent UK authority.
United States
Depending on your state and whether the relevant law applies to this service, you may have rights to know, access, correct, delete, or obtain a copy of personal data and to appeal certain decisions. Some state privacy statutes apply only when business or processing thresholds are met. This Policy does not claim that every statute applies, but you may contact me and I will respond as required by applicable law.
ZenThoughts does not sell personal data, share it for cross-context behavioral advertising, use it for targeted advertising, or process it for profiling that produces legal or similarly significant effects.
15. Security
I use reasonable technical and organizational measures appropriate to the service, including secure transport, access restrictions, limited provider access, and secure on-device session storage. No transmission or storage system is completely secure, so absolute security cannot be guaranteed.
If a personal-data breach creates a notification obligation, I will notify the competent authority and affected users as required by applicable law.
16. Third-Party Services and Links
ZenThoughts may link to Apple subscription management, authentication providers, service-provider policies, or other external resources. Those services are operated by third parties and their own terms and privacy policies apply. I am not responsible for independent third-party content or practices, except to the extent applicable law makes me responsible for selecting, instructing, or overseeing a processor or otherwise prohibits that limitation.
17. Changes to This Policy
I may update this Policy when the app, providers, processing purposes, legal requirements, or user controls change. The updated document will show a new effective date. Material changes will receive an in-app or other prominent notice where appropriate, and renewed consent will be requested when required by law.
18. Contact
For privacy questions or requests, contact:
- Kanstantsin Ausianovich
- Republic of Lithuania
- zenthoughtsapp@gmail.com