Legal

Privacy Policy

Last updated: April 30, 2026

ThoughticaOS ("Thoughtica", "we", "us") is built on the belief that your inner world is yours. This policy explains what data we collect, how we use it, and why we'll never compromise on your privacy.

What We Collect

How We Protect Your Data

All journal entries are encrypted with AES-256 encryption at rest. Authentication uses OAuth 2.0 with HTTP-only secure cookies. All connections use HTTPS with HSTS headers enabled.

Passwords are hashed with bcrypt and never stored in plain text. We cannot read your password even if we wanted to.

How We Use Your Data

We do not use your data for advertising. We do not sell, rent, or share your personal data with third parties.

AI Processing

Your reflections are sent to our AI provider (OpenAI) to generate insights. These prompts are not used to train AI models. We send only the content needed to generate your response, with no personally identifying information attached.

Data Retention

Your data is retained as long as your account is active. If you delete your account, all associated data (reflections, journal entries, mood data) is permanently deleted within 30 days.

Your Rights

Cookies

We use a single HTTP-only authentication cookie to keep you signed in. We do not use tracking cookies, advertising cookies, or third-party cookies.

Contact

Questions about this policy? Email us at thoughticaos@polsia.app.