Thought River Privacy Policy
Effective Date: September 22, 2026
Thought River is a mobile app and related service operated by Gobitron, LLC ("Gobitron," "we," "us," or "our"). Thought River helps you turn a written or voice Reflection into a personal Moment that you can review, save, and return to. This Privacy Policy explains how we handle information when you use Thought River, its website, account features, testing programs, or support.
Quick summary
- Thought River is for people age 13 and older. The app asks for a device-local confirmation before the Reflection flow starts. It does not ask for a birth date. The confirmation remains on the device until app data is cleared or a new legal-contract version requires confirmation.
- You can use the first Reflection route without an account. The app asks you to sign in to edit a saved Moment or create more Moments from the same Reflection.
- A Reflection can contain private and sensitive information. We process only the voice or text you choose to submit, its transcript when you use voice, the generated clarification, and the Moment you choose to save.
- Reflections and Moments are private. Thought River does not publish or share them with other users, therapists, or professionals.
- We use service providers to host private content and to provide transcription, model processing, and Moment audio when needed. We do not permit those providers to use Reflection content for advertising or to train general-purpose models.
- We do not sell personal information or use it for cross-context behavioral advertising. Product analytics and crash reports do not include Reflection text, recordings, transcripts, clarifications, Moment text, or screenshots.
- Thought River is a personal reflection practice. It is not therapy, treatment, diagnosis, medical advice, crisis care, or emergency support.
Information we handle
Reflection and Moment content
When you use Thought River, we process the content you choose to provide and the content needed to provide the requested feature. This can include:
- written Reflection text or a voice recording;
- a transcript and limited processing facts for a voice Reflection;
- the generated clarification and your changes to it;
- the Direction you choose and the generated Moment text, cues, timing, and audio needed for playback;
- your review, preview, save, edit, and deletion actions; and
- a saved Reflection title, summary, and related Moment information.
Your Reflection can include sensitive information about emotions, relationships, health, or therapy. Do not enter another person's private information unless you have permission. We use this content only to provide, secure, and support the Thought River features you request. It is not published, used for advertising, or used to make decisions about employment, credit, insurance, housing, health care, or other similar decisions.
Thought River uses automated processing to prepare a clarification and Moment from the Reflection you deliberately submit. You can review the clarification and Moment before you save it. We do not use raw or account-linked Reflection content to train a general-purpose AI model.
Guest and account-backed use
The first Reflection route can use a technical guest session. This session does not require your name or email address, but its private content is linked to the session and is not anonymous. A guest can save one Moment and return to it. The app requests sign-in when a guest edits that saved Moment or creates more Moments from the same Reflection.
If you sign in or create an account, Thought River can transfer the guest Reflection and its saved Moment to your account. Account-backed Reflections appear in Your Reflections and can be available on another device when you sign in with the same account.
If you create an account, we also process information needed to provide and secure it. This can include your name, email address, internal user ID, authentication provider, verification status, session information, account settings, device and browser information, IP address, and security or rate-limit records. Apple, Google, and email providers process the information needed for the sign-in method you choose. Passwords, provider tokens, and complete verification or reset links are not included in product analytics.
Device, analytics, and diagnostics data
We process limited device and product-use information to run and improve the service. This can include the app and build version, runtime channel, device and operating-system information, internal user or install ID, screen or entry point, feature state, duration or count fields, and safe error codes.
We send only bounded, content-free product events for product analysis. We do not send Reflection text, recordings, transcripts, clarifications, Moment titles, Moment text, cues, passwords, email addresses, provider tokens, screenshots, session replay, or advertising identifiers in these events. We do not enable mobile autocapture or session replay.
If crash reporting is active, it can receive privacy-filtered diagnostic data such as the app release and build, operating-system and device diagnostics, a generic error category, and bounded action breadcrumbs. It is configured not to include Reflection or Moment content, user profiles, screenshots, view hierarchy, or request and response content.
Advertising measurement
In supported public iOS releases, we use Meta's app SDK to measure installs and app activation from ads for Thought River. It starts only after the device-local age confirmation. Meta receives an app-install identifier, install and activation information, and technical app, device, and network information. Network requests also expose an IP address to the receiving service. We restrict this integration to analytics and conversion measurement.
We disable automatic app-event logging and collection of Apple's advertising identifier (IDFA). We do not send Meta your Thought River account ID, name, email address, Reflection or Moment content, or completion events. Our product completion reports are separate from this advertising measurement.
App Store campaign links can contain a campaign code that identifies an ad. Apple provides campaign reports subject to its reporting thresholds. These codes identify the campaign, not your Reflection or Thought River account.
Notifications, support, and website requests
Local notifications are optional and are not needed for the Reflection route. The selected reminder time and cue are not sent to our server. A Reflection-ready notification can use an Expo push token only in development or test builds when you choose that feature. It is not enabled in the current public release. When you contact support, we process the information you provide, including your email address, support request, and attachments. Do not send private Reflection content, passwords, authentication codes, provider tokens, or complete verification or reset links.
If you request updates through the website, we process your email address, your consent, the source path, submission time, and standard security records. We use this information to respond to your request or send the updates you asked to receive.
How we use information
We use information to:
- provide the Reflection, clarification, Direction, Moment, playback, save, editing, and deletion features you request;
- provide account access and synchronize account-backed content;
- protect the service, prevent misuse, and troubleshoot problems;
- respond to support, privacy, and deletion requests;
- send optional notifications or updates that you request; and
- analyze bounded product and reliability information without private Reflection content; and
- measure downloads and activation from ads for Thought River.
We may use synthetic examples and deidentified examples that you provide with appropriate permission to test the service. We do not treat encrypted, pseudonymized, or otherwise account-linkable Reflection content as anonymous.
How we disclose information
We disclose information only as needed to operate the service or meet legal requirements. This can include service providers that provide hosting, private storage, authentication, email, transcription, model processing, Moment audio, analytics, advertising measurement, diagnostics, support, and app distribution. Meta provides the limited advertising measurement described above, and Apple provides App Store distribution and campaign reporting. These providers process information only for the services they provide to us. We select and configure providers under documented privacy, security, access, training, retention, and deletion terms.
We can also disclose information when required by law, legal process, or a valid government request, or when needed to protect users, the service, or others. We can disclose aggregated or properly deidentified information that does not identify you.
We do not sell personal information or share it for cross-context behavioral advertising.
Retention and deletion
We keep information only as long as needed for the purposes in this policy, unless a longer period is required by law or for security.
- Guest Reflection content that is not transferred to an account is deleted after 30 days.
- Account-backed Reflections and Moments remain until you delete the Reflection, use Clear private history, or delete the account.
- Deleting a Reflection removes its source, transcript, clarification, related Moments, generated audio, and live cache entry. Provider and backup copies can remain only for their documented security, abuse, legal, operational, or recovery periods and cannot restore the Reflection to live access.
- Account deletion removes the account, authentication records, sessions, and account-owned Reflection and Moment content. An offline device can complete its local cleanup when it reconnects.
- Clear private history keeps the account, settings, and current River thoughts but removes all account-backed Reflections, Moments, and Thought Journey history. It removes the current device copies and queues private hosted audio for deletion. Content-free retry, tombstone, and deletion receipts can remain under the operational retention periods below.
- First-party and PostHog events are retained for up to 12 months. Sentry crash and diagnostic events are retained for up to 30 days. Request, security, and rate-limit logs are retained for up to 90 days. Managed database recovery snapshots are retained for no more than 7 days.
- Website update requests are retained until you opt out or for up to 24 months without activity. Support cases and attachments are retained for up to 12 months after the case closes. Content-free privacy and deletion evidence can be retained for up to 3 years.
- Fully deidentified product-development information may be retained indefinitely because it cannot reasonably be linked to a person, account, or device.
Your choices and rights
You can review and edit a Reflection or Moment where the app provides that control. You can delete a Reflection from Your Reflections. You can use Clear private history or delete your account through Account and profile. You can change notification permissions in device settings.
For a privacy, access, correction, export, or deletion request, email support@thethoughtriver.com. We may need to verify your account control before we act on a request. Your rights can vary by location. See Thought River Support for help with these controls.
Security
We use measures designed to protect information, including encrypted transport, application-layer encryption for stored Reflection text, private storage for recordings, account-scoped access controls, secure device storage, bounded telemetry, and provider access controls. No method of storage or transmission is completely secure, and we cannot promise absolute security.
International processing
Thought River and its service providers can process information in the United States and other locations where they operate. Those locations can have data protection laws that differ from the laws where you live.
Children
Thought River is not directed to children under 13. If you believe a child under 13 has provided personal information, contact us at support@thethoughtriver.com.
Changes to this policy
We can update this policy as the service or legal requirements change. We will change the Effective Date and provide additional notice when required by law. If a change requires consent, we will request it.
Contact
Gobitron, LLC operates Thought River. For privacy questions or requests, email support@thethoughtriver.com or visit Thought River Support.