Privacy Policy
Last updated 15 September 2026
Thala is a pain diary, so most of what you put into it is health information about you. This policy explains exactly what is collected, why, where it is stored, and how to get rid of it.
The short version
- Your pain, mood and sleep entries are stored so the app can show them back to you. Nothing else.
- They are never sold, never shared with advertisers, insurers or employers, and never used to track you across other apps or websites.
- They are never sent to our analytics or crash-reporting tools.
- Nothing is stored on your phone to track you, and there is no advertising or cross-app tracking of any kind.
- Deleting your account deletes all of it, permanently, straight away.
1. Who we are
Thala (“Thala”, “we”, “us”) is the data controller for the personal data described here. Thala is operated by Thala (sole trader, United Kingdom).
For any privacy question or request, write to privacy@thala.online.
2. What we collect
Account information
When you create an account we collect your email address and a password, plus the first and last name you choose to give. Passwords are handled by our authentication provider and stored only as a salted hash. We never see or store your password in a readable form.
If you use Sign in with Apple, we receive whatever Apple passes on: a unique identifier and either your real email address or Apple’s private relay address, depending on your choice. We cannot see your Apple ID password.
Health information you enter
This is the heart of the app, and it is special category data under UK and EU data protection law. It includes:
- The body locations where you have pain, when each pain started, and whether it followed an acute injury (and when)
- Your daily entries: the highest and lowest pain level (0–10) for each pain, roughly when in the day each occurred, and whether it hurts right now
- The qualities you use to describe the pain
- How you felt that day, chosen from a two-level feeling wheel
- A sleep score for the night before
- Stressful events you record, including any you note as present when a pain began
- Any free-text notes you write on a day’s log
Device and technical information
- Push notification token. If you turn on notifications, Apple issues a token for that device which we store so we can send you a notification when there is something new to read. It identifies a device, not you personally, and is deleted when the device stops accepting notifications or when you delete your account.
- Diagnostics. If the app crashes or hits an error, our crash reporting tool records the error, a stack trace, the app version, and your device model and OS version. The report is labelled with your account identifier so we can tie it to a support conversation. It does not include your IP address, a screenshot, or anything you have entered.
- Usage analytics. We record a short, fixed list of things that happen as you use the app: that you signed up, that you added a pain, which screen you opened, that you finished a check-in, and how many steps it took. These are recorded by our server, not by the app. There is no analytics software on your phone and nothing is stored on your device for this. Each record is labelled with your account identifier, so it is linked to your account. It never includes an answer you gave: no pain levels, no body locations, no moods, no sleep scores, no notes. Deleting your account deletes these too.
What never leaves the app’s own database
Your pain levels, moods, sleep scores, stressful events and notes are never included in analytics events or crash reports. Our analytics and error-monitoring providers do not receive your health data. The list of things analytics may record is fixed in the software itself, so it cannot quietly grow to include an answer you gave.
3. Why we use it, and our legal basis
| What | Why | Legal basis (UK/EU GDPR) |
|---|---|---|
| Account information | To create your account, sign you in, and keep your data attached to you | Performance of a contract (Art. 6(1)(b)) |
| Health information you enter | To store your diary, show it back to you as charts and history, and generate the insights and evidence in the app | Your explicit consent (Art. 9(2)(a)), together with performance of a contract (Art. 6(1)(b)) |
| Push notification token | To tell you when a new insight or piece of evidence is available | Your consent (Art. 6(1)(a)), given at the iOS permission prompt |
| Diagnostics | To find and fix crashes and errors | Legitimate interests (Art. 6(1)(f)): keeping the app working |
| Usage analytics | To understand which parts of the app are used, so we know what to improve | Legitimate interests (Art. 6(1)(f)): improving the product |
Because your diary entries are handled on the basis of your explicit consent, you can withdraw that consent at any time by deleting your account. Withdrawing consent does not affect anything done before you withdrew it.
4. How insights are generated
The insights and evidence the app shows you are produced by fixed rules running over your own entries, for example comparing your weekend days with your weekdays. They are not produced by profiling you against other users, are not used to make any decision about you, and have no legal or similarly significant effect. There is no automated decision-making within the meaning of Art. 22.
5. Who we share it with
We do not sell your data, and we do not share it with advertisers, data brokers, insurers or employers. We do not track you across other companies’ apps or websites, and we do not ask for permission to do so.
We do use a small number of service providers who process data on our behalf, under contract, and only on our instructions:
| Provider | What they do | What they hold |
|---|---|---|
| Supabase | Authentication and the application database | Your account details and all of your diary entries |
| Railway | Hosting for the application server | Processes your data in transit and keeps short-lived server logs. No copy of your diary |
| Resend | Sending account emails, such as a password reset code | Your email address and the contents of that message |
| Apple (APNs) | Delivering push notifications | The device token and the notification text |
| Sentry | Crash and error monitoring | Diagnostic data as described above, labelled with your account identifier. No health data, no IP address |
| PostHog | Product analytics | Usage events labelled with your account identifier. No health data |
| Vercel | Hosting this website, and counting visits to it | Page-view counts for the website only. No cookies, and nothing linked to your account or to the app |
We may also disclose data if we are legally required to (for example in response to a valid court order) or to establish or defend legal claims.
6. Where your data is stored
Your account and diary data are stored in the United Kingdom / European Economic Area. Where a provider processes data outside the UK or EEA, that transfer is covered by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, as set out in that provider’s data processing agreement.
All data is encrypted in transit, and encrypted at rest by our hosting providers.
We take an encrypted backup of the database once a day, so that a technical failure does not cost you your diary. Backups are held in the same region as the database and are kept for 7 days, after which they are destroyed. They are used only to restore the service after a failure.
7. How long we keep it
- Your account and diary entries are kept for as long as your account exists. The whole point of the app is the long view, so nothing is aged out automatically.
- Diagnostic data (crash and error reports) is kept for 90 days.
- Usage analytics is kept for 24 months.
- Server logs, which record the time and address of each request but not its contents, are kept for 30 days.
- Database backups are kept for 7 days.
- When you delete your account, your account and every entry attached to it are deleted immediately (see below), and we ask our analytics provider to erase your usage records at the same time. Backups taken before you deleted still contain your data until they age out on the 7-day cycle above; they are never used to restore a deleted account.
8. Deleting your account
You can delete your account from inside the app, at Account → Delete account. You will be asked to confirm it is you, with your password or by signing in with Apple again if that is how you created the account. Deletion is immediate and irreversible: your account, profile, pains, daily logs, moods, notes, notifications and device registrations are all removed. There is no recovery period and no way for us to restore it afterwards.
Step-by-step instructions are on the account deletion page.
9. Your rights
If you are in the UK or the EEA you have the right to: get a copy of your data; have inaccurate data corrected; have your data deleted; restrict or object to how we use it; receive it in a portable format; and withdraw consent at any time.
Most of these you can exercise yourself in the app: you can view and edit your entries, and delete everything. For anything else, email privacy@thala.online and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EEA.
10. Children
Thala is not intended for children. You must be at least 16 years old to create an account. If we learn that we hold data from a child under 16, we will delete it.
11. Changes to this policy
If we change how we handle your data we will update this page and change the date at the top. If the change is significant, such as a new category of data or a new purpose, we will tell you in the app before it takes effect.
12. Contact
Privacy questions and requests: privacy@thala.online
Everything else: support@thala.online