Skip to content
Prywatność

Polityka prywatności

Ostatnia aktualizacja: 10 kwietnia 2026

1. Co zbiera Thremark

  • Marks (saved facts) — stored on your device and synced to our server using an anonymous device ID. You can delete all server data at any time from Settings.
  • Chat messages — stored on your device and synced to our server for multi-device access. Messages are forwarded to AI providers for responses.
  • Anonymous session — a device-generated UUID for API session management. No name, email, or Apple ID is sent to our server.
  • Apple ID (optional) — name and email stored on-device only if you use Sign in with Apple. Not stored on server.
  • Files — AI-generated files synced to server. Delete them any time.
  • Notifications & Reminders — push notifications scheduled on server and delivered via APNs. Device token deleted after delivery.
  • Thinking & reasoning models — messages sent to OpenAI or Anthropic reasoning API. Only final response returned.
  • Photos, Camera & Image Generation — attached images sent to AI provider for analysis. Images not permanently stored on servers.
  • Microphone & Voice AI — audio streamed to Google Gemini Live API or OpenAI Realtime API. Audio not stored after processing.

2. Jak dane są przechowywane

  • On your device — marks, chats, messages, and files stored locally via SwiftData.
  • On our server — marks, chats, messages, and files synced to Cloudflare D1 database via anonymous device ID.
  • Semantic search index — marks embedded as numerical vectors (Cloudflare Vectorize) for semantic search.
  • Retention — server messages subject to automatic rotation. Marks and files remain until deleted.

3. Usługi stron trzecich

  • OpenAIChat · Image generation · Live voice · Speech to text. Receives: your message · recent chat history · memory marks · files and images you attach · generation prompts · voice audio. Processed in: United States. Trains on our data: No. Retention: up to 30 days (SOC 2 Type 2, ISO 27001). Policy
  • Google (Gemini)Chat · Image generation · Live voice. Receives: your message · recent chat history · memory marks · files and images you attach · generation prompts · voice audio. Processed in: United States. Trains on our data: No. Retention: up to 30 days (GDPR DPA, SOC 2). Policy
  • Anthropic (Claude)Chat. Receives: your message · recent chat history · memory marks · files and images you attach. Processed in: United States. Trains on our data: No. Retention: up to 30 days (SOC 2, GDPR). Policy
  • Kling (Kuaishou) (Plus and Pro only)Video generation. Receives: generation prompts · the photo you animate. Processed in: Singapore (operator: Kuaishou, China). Trains on our data: Not confirmed. Retention: Not confirmed. Policy
  • Tavily SearchWeb search. Receives: search queries. Processed in: United States. Trains on our data: No. Retention: not stored after processing. Policy
  • CloudflareServers and storage. Receives: your message · memory marks · files · anonymous device ID. Processed in: Global edge network. Trains on our data: No. Retention: not stored after processing (SOC 2, ISO 27001, GDPR SCCs). Policy
  • Apple (APNs)Push delivery · Subscriptions. Receives: push token. Processed in: United States. Trains on our data: No. Retention: not stored after processing. Policy
  • RevenueCatSubscriptions. Receives: anonymous device ID · subscription state. Processed in: United States. Trains on our data: No. Retention: not stored after processing (SOC 2). Policy
  • GitHub (only if you turn it on)Repository sync. Receives: memory marks · files · recent chat history. Processed in: United States. Trains on our data: No. Retention: not stored after processing. Policy
  • PostHogProduct analytics. Receives: anonymous device ID · usage events. Processed in: United States / European Union. Trains on our data: No. Retention: not stored after processing. Policy
  • SentryCrash reports. Receives: anonymous device ID · error reports. Processed in: United States. Trains on our data: No. Retention: not stored after processing. Policy

List last changed: 2026-08-19

3a. Jakie dane Thremark wysyła do usług AI

Za każdym razem, gdy wysyłasz wiadomość, następujące dane mogą być przesyłane do jednego z naszych dostawców AI (Google Gemini, OpenAI lub Anthropic) w celu wygenerowania odpowiedzi:

  • Tekst Twojej wiadomości — aktualna wiadomość, którą właśnie wysłałeś.
  • Ostatnia historia rozmów — poprzednie wiadomości w bieżącej sesji czatu, używane jako kontekst.
  • Memory marks — zapisane przez Ciebie tematy i fakty, wysyłane, aby AI mogło udzielać trafnych, spersonalizowanych odpowiedzi.
  • Załączone pliki i obrazy — pliki lub zdjęcia dołączone do wiadomości.
  • Głos — jeśli korzystasz z wejścia głosowego, audio jest przesyłane strumieniowo do OpenAI Whisper (transkrypcja) lub Google Gemini Live / OpenAI Realtime (rozmowy głosowe).

Imię, adres e-mail ani Apple ID nie są nigdy wysyłane do dostawców AI. Zgodnie z polityką żaden z tych dostawców (OpenAI, Google Gemini, Anthropic) nie wykorzystuje danych API do trenowania ani dostrajania swoich modeli AI. Każdy z nich przechowuje dane przez maksymalnie 30 dni wyłącznie na potrzeby monitorowania bezpieczeństwa, a następnie trwale je usuwa. Wszyscy trzej posiadają certyfikat SOC 2 i są zgodni z RODO, a umowy zobowiązują ich do zapewnienia poziomu ochrony danych wymaganego przez niniejsze zasady. Twoje dane nigdy nie są sprzedawane. Możesz usunąć wszystko w dowolnym momencie w Ustawieniach.

4. Dane, których NIE zbieramy

  • Nie sprzedajemy, nie udostępniamy ani nie monetyzujemy Twoich danych osobowych.
  • Nie śledzimy Twojej lokalizacji.
  • Nie używamy reklamowych SDK ani trackerów.
  • Nie zbieramy nazwy, e-maila ani Apple ID na serwerze.
  • Nie używamy śledzenia między aplikacjami (IDFA nie jest używane).

5. Twoje prawa

  • Delete all data — available in Settings at any time. Removes all marks, chats, messages, and files from device AND server. Irreversible.
  • Delete account — available in Settings if signed in with Apple.
  • Export — export marks via the share sheet.
  • No account required — Thremark works without signing in. Sign in with Apple is optional.
  • GDPR & CCPA — you have the right to access, correct, or delete your data. Contact us at [email protected].

6. Analityka

Używamy PostHog do analizy zachowań z wyłączoną identyfikacją. Żadne dane osobowe nie są zbierane.

7. Dzieci

Thremark nie jest przeznaczony dla dzieci poniżej 13 roku życia. Nie zbieramy świadomie danych od dzieci.

8. Pliki cookie

Nasza aplikacja iOS nie używa plików cookie.

9. Międzynarodowe transfery danych

Dane są przetwarzane na globalnie rozproszonych serwerach Cloudflare. Żądania AI są przetwarzane na serwerach odpowiednich dostawców AI.

10. Podstawa prawna przetwarzania (RODO)

  • Contract performance — to deliver app features.
  • Legitimate interest — for security and fraud prevention.
  • Consent — for push notifications (revocable at any time).

11. Zmiany

Możemy aktualizować tę politykę. Istotne zmiany są ogłaszane przez aktualizację aplikacji.

12. Kontakt

Pytania dotyczące prywatności: [email protected]