Thought River Privacy Policy
Effective Date: August 7, 2026
Thought River is a mobile app and related service operated by Gobitron, LLC ("Gobitron," "we," "us," or "our"). Thought River provides a private visual practice for noticing a thought, lightly naming it, and making space around it. This Privacy Policy explains how we handle information when you use Thought River, its website, account features, testing programs, or support.
Quick summary
- Thought River is for people age 13 and older and is not directed to children under 13.
- A Guest River practice can be used without an account. The Guest thought label itself and River state stay on the device unless the app clearly asks you to use an account feature and confirms that the data was saved. Bounded, label-free product events may still be sent as described below.
- An account can store encrypted thought labels, structured practice facts, and private Thought Journey history. Encryption protects stored labels, but it is not end-to-end encryption.
- Releasing a thought removes it from the present River. It does not delete a deliberately registered Thought Journey history entry. History and account deletion are separate controls.
- Thought labels may be captured and saved by Thought River, but we never send them to PostHog or include them in other product analytics or crash diagnostics.
- We do not sell personal information or share it for cross-context behavioral advertising. We also do not disclose personal information to another company for its own advertising, marketing, profiling, or independent product development. Limited service providers process information only for us as described below.
- We may use only anonymous information derived from thought labels, product usage, or user-selected shape characteristics to research, develop, test, or improve Thought River. Product-development information must not be reasonably linkable to an account, device, or person.
- Thought River is a wellness practice. It is not therapy, treatment, diagnosis, medical advice, crisis care, or emergency support.
Information we handle
Device-local River data
The app may keep thought labels, current intensity, familiarity and practice state, visual identities, post-practice choices, appearance and audio preferences, first-use guidance state, and an optional daily reminder time on your device. The current daily River reminder is scheduled by the operating system on that device. Its selected time and cue are not sent to our server.
You can clear Guest River saved thoughts in the River menu. Deleting the app or clearing its storage may also remove device-local data. Device-local data that was never saved to an account cannot be restored by us.
Account and authentication data
If you create an account, we process information needed to identify and secure it, such as your email address, display name, internal user ID, authentication provider, verification status, session data, time zone, account settings, IP address, user agent, and security or rate-limit records. You may sign in with Apple, Google, or a verified email address and password when those options are available.
Apple and Google provide the account information you authorize them to share. For email accounts, authentication and email providers process the information needed to verify your address and deliver verification or password-reset messages. Passwords, provider tokens, and complete verification or reset links are not included in product analytics.
Account River, practice, and Thought Journey data
When an account feature is enabled and the app confirms a save, we may process:
- the thought label you entered, encrypted before managed database storage;
- an opaque thought or occurrence ID and a meaning-free visual identity;
- the intensity, optional Tone or Body Presence, and other choices you deliberately make;
- practice type, start and end times, duration, cycles, completion or exit state, and optional post-practice response;
- registration time, capture-local date and time zone, release and deletion events, and synchronization revisions; and
- factual Trends, recurrence, rhythm, or Insight results calculated from structured records.
The service can decrypt a stored label when needed to return it to the signed-in account that owns it. Default Thought Journey period views are label-free; the app requests a label only when you choose to reveal it. This is not end-to-end encryption. We do not use raw or account-linked thought labels to diagnose you, infer a medical condition, make an automated decision about you, personalize a practice based on the label's meaning, or train a general-purpose AI model.
We may in the future create anonymous information derived from account-backed thought labels and associated characteristics, such as product usage or user-selected visual or shape characteristics, to research, develop, test, and improve Thought River features. Only the resulting anonymous information may be used for product development. It must first be separated from account, device, and other identifiers and processed so it cannot reasonably be linked back to a person. We will not attempt to reidentify it or combine it with information that would make it linkable. Raw, encrypted, pseudonymized, or otherwise linkable thought labels do not qualify and are not used for product development. Before introducing a materially different use, including a feature that interprets a person's label or changes their experience based on its meaning, we will update this policy and obtain consent when required by law.
The app may also keep an encrypted, account-scoped cache and pending-delivery queue on a signed-in device for offline use. The device key is kept in secure storage. Signing out conceals the account cache on that device; deleting the account or completing the app's deletion cleanup removes it.
Product analytics
Thought River sends bounded, label-free product events to our server. Guest events may use a randomly generated install ID. Signed-in events use our internal user ID. Events may include app and build version, runtime channel, screen or entry point, practice flow and state, duration and count fields, intensity band, label mode or a coarse label-length bucket, reminder permission or open state, and a local practice date. They do not include the label itself.
Product analytics must not include thought labels, encrypted label values, email addresses, display names, passwords, provider tokens, complete links, screenshots, session replay, advertising identifiers, or other free-form River content. We persist validated events first and may send them to PostHog for aggregate product analysis. Mobile autocapture, advertising profiles, and session replay are not enabled. If a Guest install later becomes an account, we may keep a limited install-to-account link for up to 90 days so conversion measurement and attributable deletion requests work correctly.
Thought labels may be captured and saved by Thought River, but we never send them to PostHog. Anonymous information derived from labels for future product development is maintained outside the PostHog product-analytics stream.
Crash and diagnostic data
A build configured for crash reporting may send privacy-filtered error data to Sentry. This can include the app release and build, runtime environment, operating system and device diagnostics, a generic error category, and bounded action breadcrumbs such as selecting a River bubble or starting a practice. It is configured not to send a user profile, thought label, original exception message, request or response content, screenshots, view hierarchy, performance traces, or replay.
Our servers and hosting providers may also process standard request and security logs, including timestamps, IP addresses, user agents, routes, response status, and bounded error or request IDs. We prohibit thought labels, credentials, tokens, and request bodies from River logs.
Notifications
The current daily Thought River reminder is optional, off by default, and scheduled locally on your device. If a separate account notification feature is available and you enable it, we may process your notification preference, device platform, push token, and a bounded device identifier so the provider can deliver and troubleshoot that notification. You can change notification permission in device settings. Thought labels are not included in notification payloads.
Website interest, support, testing, and research
If you request early access or product updates through the Thought River website, we process the email address, page path, contact consent, submission time, and standard request/security logs needed to receive and protect that request. We use the email only for the early-access and occasional product updates described beside the form. You can ask us to remove you from that list at any time.
If you contact support, join TestFlight or another controlled test, complete a survey, or participate in research, we process the contact details, app and device information, feedback, and other information you choose to provide. Please do not send thought labels, passwords, provider tokens, verification or reset links, or screenshots that expose private content unless we specifically request a safe and necessary item.
The production Thought River experience does not read or transmit your phone contact list, email or text-message contents, or social graph. It has no public feed, direct messaging, or active sharing or circle workflow.
How we use information
We use information to:
- provide the Guest River and account features you choose;
- authenticate accounts and deliver verification or recovery messages;
- synchronize private River and Thought Journey data across signed-in devices;
- calculate factual, label-free Trends and Insights;
- schedule or deliver notifications you enable;
- receive website interest requests, send consented product updates, and operate support and controlled testing;
- prevent abuse, secure the service, diagnose failures, and recover from outages;
- understand aggregate product use;
- create and use anonymous, non-linkable information derived from thought labels, product usage, or user-selected shape characteristics to research, develop, test, and improve Thought River; and
- comply with legal obligations.
Where applicable law requires a legal basis, we process information to perform our agreement with you, with your consent, for our legitimate interests in operating and securing the service, or to meet a legal obligation. You may withdraw consent for future processing where consent is the basis, but that does not make earlier processing unlawful.
How we disclose information
We do not sell personal information or disclose it to other companies for their own advertising, marketing, profiling, or independent product-development purposes. We disclose only the information needed to:
- service providers that support hosting, managed databases and backups, authentication, transactional email, analytics, diagnostics, app distribution, push delivery, and customer support;
- Apple or Google when you choose their sign-in or app-distribution services;
- comply with law, legal process, or a valid request, or protect the rights, safety, and security of users, Gobitron, or others;
- complete a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice; or
- follow your direction or consent.
Current providers may include Apple, Google, Vercel, a managed PostgreSQL provider, Resend, PostHog, Sentry, Expo, and email or support providers. They process different, limited categories for their assigned purpose. We require service providers to protect information consistently with this policy and applicable law and not use it for their own advertising.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use third-party advertising networks or make private River content visible to other Thought River users. Service providers acting under our instructions are not permitted to use Thought River information for their own advertising, marketing, profiling, or product development.
Retention and deletion
We keep information only as long as reasonably needed for the purpose described here, including account operation, synchronization, security, support, legal obligations, and dispute resolution.
- Device-local Guest River data remains until you clear it, release it where applicable, delete the app, or clear app storage.
- Active account River records remain until you release or delete the thought, clear the applicable history, or delete the account.
- Deliberately registered Thought Journey occurrences remain in private history after release from the present River. They remain until you delete the individual history entry, clear private history, or delete the account.
- Deleting an individual history entry or clearing private history destroys its stored label and removes it from available history. Content-free deletion events and tombstones may remain until account deletion so an offline or older device cannot restore deleted content.
- Account records and linked River content remain until account deletion, subject to narrow legal or security needs described below.
- The install-to-account analytics link expires after 90 days. Other analytics, diagnostic, server-log, support, and security records are retained only for the period reasonably needed for aggregate analysis, debugging, abuse prevention, support, or legal compliance and are then deleted or de-identified.
- Anonymous product-development information may be retained because it cannot reasonably be linked to an account, device, or person. Because it is not linkable, we cannot retrieve or delete it as a particular person's data.
When you delete your account in the app, we delete the account, authentication records, sessions, active River data, private History, structured practices, calculation records, push devices, and first-party account analytics. We also delete first-party Guest analytics that are still linked through an unexpired conversion record and take reasonable steps to remove downstream data that is still attributable to the account. Data that was never linked to the account may not be identifiable as yours.
Where available, we request revocation of Sign in with Apple authorization. A temporary provider failure may require a limited encrypted revocation record to remain until the request succeeds; it is not used to restore product data. An offline device cannot receive a remote deletion signal until it reconnects. Managed backup copies may remain for a limited provider-controlled recovery window and are isolated from ordinary use until they expire or are overwritten.
Your choices and rights
Depending on where you live, you may have the right to request access, correction, export, deletion, restriction, or objection concerning your personal information, or to withdraw consent. You may also have the right to appeal a decision or complain to a privacy regulator. We will not discriminate against you for exercising a privacy right.
You can:
- clear Guest River saved thoughts from the River menu;
- delete a Thought Journey entry from its detail view;
- clear private History from Account and profile by entering the displayed confirmation phrase;
- delete your account through Account and profile;
- change notification permissions in device settings; and
- email support@thethoughtriver.com for access, correction, export, deletion, or other privacy requests.
We may need to verify account control before completing a request. We will respond within the period required by applicable law. If we cannot fulfill all or part of a request, we will explain why when the law requires it.
Security
We use measures designed to protect information, including encrypted transport, application-layer encryption for stored thought labels, account-scoped access controls, secure device storage, bounded telemetry, and provider access controls. No security measure or storage system can guarantee absolute security. Please use a secure sign-in method and contact us if you believe your account or information may have been compromised.
International processing
Gobitron operates from the United States. We and our service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for international transfers.
Children
Thought River is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided personal information, email us so we can investigate and delete it as appropriate. Users under the age of legal majority should use Thought River only with a parent or guardian's permission where required by law.
Changes to this policy
We may update this policy as Thought River or legal requirements change. We will change the Effective Date and provide additional notice in the app, on the website, or by email when a change is material and notice is required.
Contact
Gobitron, LLC operates Thought River. For privacy questions or requests, email support@thethoughtriver.com or visit Thought River Support.