Thought River

Thought River Privacy Policy

Effective Date: August 7, 2026

Thought River is a mobile app and related service operated by Gobitron, LLC ("Gobitron," "we," "us," or "our"). Thought River provides a private visual practice for noticing a thought, lightly naming it, and making space around it. This Privacy Policy explains how we handle information when you use Thought River, its website, account features, testing programs, or support.

Quick summary

Information we handle

Device-local River data

The app may keep thought labels, current intensity, familiarity and practice state, visual identities, post-practice choices, appearance and audio preferences, first-use guidance state, and an optional daily reminder time on your device. The current daily River reminder is scheduled by the operating system on that device. Its selected time and cue are not sent to our server.

You can clear Guest River saved thoughts in the River menu. Deleting the app or clearing its storage may also remove device-local data. Device-local data that was never saved to an account cannot be restored by us.

Account and authentication data

If you create an account, we process information needed to identify and secure it, such as your email address, display name, internal user ID, authentication provider, verification status, session data, time zone, account settings, IP address, user agent, and security or rate-limit records. You may sign in with Apple, Google, or a verified email address and password when those options are available.

Apple and Google provide the account information you authorize them to share. For email accounts, authentication and email providers process the information needed to verify your address and deliver verification or password-reset messages. Passwords, provider tokens, and complete verification or reset links are not included in product analytics.

Account River, practice, and Thought Journey data

When an account feature is enabled and the app confirms a save, we may process:

The service can decrypt a stored label when needed to return it to the signed-in account that owns it. Default Thought Journey period views are label-free; the app requests a label only when you choose to reveal it. This is not end-to-end encryption. We do not use raw or account-linked thought labels to diagnose you, infer a medical condition, make an automated decision about you, personalize a practice based on the label's meaning, or train a general-purpose AI model.

We may in the future create anonymous information derived from account-backed thought labels and associated characteristics, such as product usage or user-selected visual or shape characteristics, to research, develop, test, and improve Thought River features. Only the resulting anonymous information may be used for product development. It must first be separated from account, device, and other identifiers and processed so it cannot reasonably be linked back to a person. We will not attempt to reidentify it or combine it with information that would make it linkable. Raw, encrypted, pseudonymized, or otherwise linkable thought labels do not qualify and are not used for product development. Before introducing a materially different use, including a feature that interprets a person's label or changes their experience based on its meaning, we will update this policy and obtain consent when required by law.

The app may also keep an encrypted, account-scoped cache and pending-delivery queue on a signed-in device for offline use. The device key is kept in secure storage. Signing out conceals the account cache on that device; deleting the account or completing the app's deletion cleanup removes it.

Product analytics

Thought River sends bounded, label-free product events to our server. Guest events may use a randomly generated install ID. Signed-in events use our internal user ID. Events may include app and build version, runtime channel, screen or entry point, practice flow and state, duration and count fields, intensity band, label mode or a coarse label-length bucket, reminder permission or open state, and a local practice date. They do not include the label itself.

Product analytics must not include thought labels, encrypted label values, email addresses, display names, passwords, provider tokens, complete links, screenshots, session replay, advertising identifiers, or other free-form River content. We persist validated events first and may send them to PostHog for aggregate product analysis. Mobile autocapture, advertising profiles, and session replay are not enabled. If a Guest install later becomes an account, we may keep a limited install-to-account link for up to 90 days so conversion measurement and attributable deletion requests work correctly.

Thought labels may be captured and saved by Thought River, but we never send them to PostHog. Anonymous information derived from labels for future product development is maintained outside the PostHog product-analytics stream.

Crash and diagnostic data

A build configured for crash reporting may send privacy-filtered error data to Sentry. This can include the app release and build, runtime environment, operating system and device diagnostics, a generic error category, and bounded action breadcrumbs such as selecting a River bubble or starting a practice. It is configured not to send a user profile, thought label, original exception message, request or response content, screenshots, view hierarchy, performance traces, or replay.

Our servers and hosting providers may also process standard request and security logs, including timestamps, IP addresses, user agents, routes, response status, and bounded error or request IDs. We prohibit thought labels, credentials, tokens, and request bodies from River logs.

Notifications

The current daily Thought River reminder is optional, off by default, and scheduled locally on your device. If a separate account notification feature is available and you enable it, we may process your notification preference, device platform, push token, and a bounded device identifier so the provider can deliver and troubleshoot that notification. You can change notification permission in device settings. Thought labels are not included in notification payloads.

Website interest, support, testing, and research

If you request early access or product updates through the Thought River website, we process the email address, page path, contact consent, submission time, and standard request/security logs needed to receive and protect that request. We use the email only for the early-access and occasional product updates described beside the form. You can ask us to remove you from that list at any time.

If you contact support, join TestFlight or another controlled test, complete a survey, or participate in research, we process the contact details, app and device information, feedback, and other information you choose to provide. Please do not send thought labels, passwords, provider tokens, verification or reset links, or screenshots that expose private content unless we specifically request a safe and necessary item.

The production Thought River experience does not read or transmit your phone contact list, email or text-message contents, or social graph. It has no public feed, direct messaging, or active sharing or circle workflow.

How we use information

We use information to:

Where applicable law requires a legal basis, we process information to perform our agreement with you, with your consent, for our legitimate interests in operating and securing the service, or to meet a legal obligation. You may withdraw consent for future processing where consent is the basis, but that does not make earlier processing unlawful.

How we disclose information

We do not sell personal information or disclose it to other companies for their own advertising, marketing, profiling, or independent product-development purposes. We disclose only the information needed to:

Current providers may include Apple, Google, Vercel, a managed PostgreSQL provider, Resend, PostHog, Sentry, Expo, and email or support providers. They process different, limited categories for their assigned purpose. We require service providers to protect information consistently with this policy and applicable law and not use it for their own advertising.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use third-party advertising networks or make private River content visible to other Thought River users. Service providers acting under our instructions are not permitted to use Thought River information for their own advertising, marketing, profiling, or product development.

Retention and deletion

We keep information only as long as reasonably needed for the purpose described here, including account operation, synchronization, security, support, legal obligations, and dispute resolution.

When you delete your account in the app, we delete the account, authentication records, sessions, active River data, private History, structured practices, calculation records, push devices, and first-party account analytics. We also delete first-party Guest analytics that are still linked through an unexpired conversion record and take reasonable steps to remove downstream data that is still attributable to the account. Data that was never linked to the account may not be identifiable as yours.

Where available, we request revocation of Sign in with Apple authorization. A temporary provider failure may require a limited encrypted revocation record to remain until the request succeeds; it is not used to restore product data. An offline device cannot receive a remote deletion signal until it reconnects. Managed backup copies may remain for a limited provider-controlled recovery window and are isolated from ordinary use until they expire or are overwritten.

Your choices and rights

Depending on where you live, you may have the right to request access, correction, export, deletion, restriction, or objection concerning your personal information, or to withdraw consent. You may also have the right to appeal a decision or complain to a privacy regulator. We will not discriminate against you for exercising a privacy right.

You can:

We may need to verify account control before completing a request. We will respond within the period required by applicable law. If we cannot fulfill all or part of a request, we will explain why when the law requires it.

Security

We use measures designed to protect information, including encrypted transport, application-layer encryption for stored thought labels, account-scoped access controls, secure device storage, bounded telemetry, and provider access controls. No security measure or storage system can guarantee absolute security. Please use a secure sign-in method and contact us if you believe your account or information may have been compromised.

International processing

Gobitron operates from the United States. We and our service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for international transfers.

Children

Thought River is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided personal information, email us so we can investigate and delete it as appropriate. Users under the age of legal majority should use Thought River only with a parent or guardian's permission where required by law.

Changes to this policy

We may update this policy as Thought River or legal requirements change. We will change the Effective Date and provide additional notice in the app, on the website, or by email when a change is material and notice is required.

Contact

Gobitron, LLC operates Thought River. For privacy questions or requests, email support@thethoughtriver.com or visit Thought River Support.