Privacy policy

Last updated: August 2026

The short version

Everything you write in Thought.care is encrypted inside your browser before it ever leaves your device. Our servers store ciphertext — encrypted blobs we mathematically cannot read. No one at Thought.care, no provider in between, can open your words. Your password never leaves your browser in readable form, and we cannot reset it (only you can, with your recovery key).

What we store

  • Account record: your email address and a password verifier, so you can sign in.
  • Encrypted data: your thoughts, notes, passwords and challenges as AES-256-GCM ciphertext. With free accounts this data stays on your device; with Lifetime sync it is stored encrypted on our server — still unreadable to us.
  • Share cards: only the anonymous stats you explicitly choose to publish (for example, “I released 3 thoughts today”). Never your words.
  • Technical logs: minimal security events (sign-ins, license activations) needed to keep accounts safe.

Cookies

One session cookie (keeps you signed in), one language cookie (remembers your chosen language inside the app) and a dark-mode preference stored in your browser. That is all. No advertising cookies, no cross-site trackers, no fingerprinting.

Advertising pixels (public pages only)

If you arrive from an ad, public marketing pages may load Meta/Google measurement pixels so we can tell whether an ad worked. Pixels never load inside your private space, and they never see anything you write. The Knowledge library and the ritual itself are pixel-free.

Payments

Lifetime is sold through Gumroad. Payment details are handled entirely by Gumroad — we never see your card. We receive your license key and the email you used at checkout.

Your control

Export or delete everything, anytime, from Settings. Deleting your account removes the account record and all synced ciphertext. Free-tier data lives only on your device and is removed when you clear your browser data.

Contact

Questions about this policy: contact us.