Privacy Policy

Last updated: 29 April 2026

ThinkWell (the "app") is a personal journaling app. This policy explains what data we collect, how we use it, and the choices you have.

Who we are

ThinkWell is operated by Luke Sarfas as an individual developer. For any privacy questions, contact luke@sarfas.com.

Data we collect

Data we do not collect

Device permissions

The app only asks for a device permission when you use the feature that needs it. You can revoke any of them in your device's Settings app at any time without losing access to the rest of ThinkWell.

How your content is used

Your journal entries, and the entities, relationships, and reflection context derived from them, are processed by our AI subprocessor (Anthropic, accessed via AWS Bedrock in the EU) to extract entities, relationships, mood signals, and insights that power the Life Map, Insights, and Reflect features. Prompts containing the relevant content are sent to that subprocessor in the European Union (Ireland). Under the subprocessor's default terms, your content is not used to train any foundation model and is not retained after processing.

Third-party processors

A small number of third parties process data on our behalf or as an independent controller. We use only what we need from each of them.

Spotify integration

If you connect your Spotify account, ThinkWell uses the Spotify Web API under the user-read-recently-played scope to show your most recent plays, so you can attach the track you were listening to to a journal entry.

ThinkWell is not endorsed, certified, or otherwise approved in any way by Spotify. "Spotify" is a trademark of Spotify AB.

Who has access

Within the app, only your signed-in account can read your data. Access is enforced at the identity layer and by fine-grained infrastructure policies that restrict each user's records to their own account ID. At the infrastructure layer, our cloud provider and the app's administrators could technically access records at rest — see the Security section below for the honest picture.

Security

Your journal content is encrypted on your device with authenticated symmetric encryption before being written to local storage. The encryption key is generated on your device and stored in the iOS Keychain (on iPhone/iPad) or Android Keystore, so that another app or an attacker with read access to the filesystem cannot read your entries directly off the device.

When your data syncs to our servers in the European Union (Ireland), it travels over TLS and is stored with provider-managed server-side encryption. This is not end-to-end encryption. That means our cloud provider, and anyone with administrative access to our production accounts, could in principle read the records at rest on the server. We do not access your journal content for any purpose other than delivering the app's features (e.g. entity extraction by our AI subprocessor, described above) and restoring your data on a new device.

If you want stricter guarantees — for example an unreadable-by-anyone-but-you model — you can use the app in offline mode without signing in, in which case nothing leaves your device.

Your rights

If you want to exercise any of these rights and cannot access the app, email luke@sarfas.com.

Data retention

Data is retained for as long as your account exists. Deleting your account removes all associated data — including photos, audio, locations, and any third-party processor records keyed to your account — within 30 days.

Children

ThinkWell is not directed at children under 13 and we do not knowingly collect data from them.

Changes to this policy

If we materially change this policy we will update the "last updated" date above and, where appropriate, notify you in-app.

Terms of Service