Your thoughts belong to you. They are stored so the app can show them back to you, sent to an AI model only to be organized, and never sold, used for advertising, or used to train AI models. You can export or erase everything yourself at any time.
Controller within the meaning of Art. 4(7) GDPR: Matti Venghaus, Kiefholz 5, 44287 Dortmund, Germany (Sole trader (Einzelunternehmer), no commercial register entry). Contact: smt.sortmy@gmail.com. Data protection contact: smt.sortmy@gmail.com. No Data Protection Officer is appointed, because the statutory thresholds of Art. 37 GDPR / §38 BDSG are not met.
Account data (email, name if you give one, language, timezone) — to give you an account and show the app in your language. Legal basis: performance of the contract (GDPR Art. 6(1)(b)).
Your thoughts, to-dos and ideas — the core of the service. Legal basis: performance of the contract.
Voice input — recorded in your browser, sent for transcription, and discarded. The recording is never written to our database or file storage; only the transcribed text you then confirm is kept. Legal basis: performance of the contract.
Usage counters and rate-limit counters — to enforce plan limits and protect the service from abuse. Legal basis: legitimate interest (Art. 6(1)(f)) and contract.
Technical logs — our server writes short log lines containing an account id, a request id and an error or event type when something fails or a rate limit is hit. Thought content is never logged. Web-server request logs (including IP addresses) are produced by our hosting provider, not by the application. Legal basis: legitimate interest (Art. 6(1)(f)).
Payment data — handled by Stripe. We store only the subscription status, plan and period. Card details never reach our servers. Legal basis: contract and legal obligation.
Thoughts are free text and may reveal health, beliefs, political opinions, sexual orientation, ethnic origin or trade-union membership — special categories under Art. 9(1) GDPR. We process them only on the basis of your explicit consent under Art. 9(2)(a) GDPR, which you give before the first thought is sorted and can withdraw at any time in Settings; withdrawal has effect for the future only (Art. 7(3) GDPR). Without that consent the app does not send any thought to the AI provider. We do not ask for such information and do not analyse it beyond organizing what you wrote. Please avoid entering data about other people that they would not expect you to store.
Providing the data is not a statutory requirement, but without account data and thought content the service cannot be provided. There is no automated decision-making producing legal effects (Art. 22 GDPR).
The text you submit — and, for voice notes, the audio — is sent from our server to the Lovable AI gateway, which forwards it to the model provider (currently Google Gemini models for structuring and an OpenAI-hosted speech model for transcription). We send only the text or audio itself plus the short organizing instruction; no account id, email, database id or IP address is included in the request. In to-do mode the titles of your open to-dos are included so an entry can be recognised again, and in Idea Matching the titles of your existing ideas — each labelled with a throwaway reference such as “t1”, never with a database identifier. If Idea Matching is off, no idea titles are sent at all. The result is returned to you and the structured version you confirm is stored; the raw input is kept for 30 days. We do not use your content to train any model and we do not profile you, and no automated decision with legal effect is made about you. Whether and for how long the gateway or the model provider itself retains a request is governed by their terms, not by our code — see their published documentation.
Each provider, the data it can see, its processing location and the state of its data processing agreement (DPA / AVV under Art. 28 GDPR) are listed on the subprocessors page listed.
The app loads no third-party fonts, scripts, pixels or analytics: fonts are served from our own domain and the only external script is the payment provider's checkout, which loads on the Settings page when you start a purchase. These providers act as processors under contract. Where processing involves transfers outside the EU/EEA, it relies on the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. The operator must confirm the exact hosting region and agreements before launch.
You have the right to access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent where processing is based on it. Access and portability are built into the app: Settings gives you a full machine-readable export. Erasure is built in too: you can delete individual items, all content, or your whole account. Deleting your account removes your profile, to-dos, ideas, idea thoughts, raw inputs, rate-limit counters and subscription records from our database and deletes the login itself. The customer and invoice records held by the payment provider remain there for as long as tax law requires; database backups roll off according to the hosting provider's backup schedule.
Where processing relies on legitimate interest, you may object at any time under Art. 21 GDPR. You can also complain to a supervisory authority. Competent authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.
Data is encrypted in transit. Each row in the database is bound to its owner and access rules are enforced by the database itself, so one account cannot read another's data. Server functions additionally verify your session on every request, and requests are rate-limited. No system is perfectly secure; if a breach affects you, we will notify you and the authority as required.
We use only what is necessary to keep you signed in and remember your language choice. Concretely, the browser stores your login session, your language preference, and — if you write a thought before signing in — that draft, so it is not lost. No advertising cookies, no analytics, no cross-site tracking, no ad networks, and nothing that would require a consent banner.
The service is not intended for children under 16.
If this notice changes materially, we will tell you in the app before the change takes effect.