Privacy Policy

Last updated 15 September 2026

Thala is a pain diary, so most of what you put into it is health information about you. This policy explains exactly what is collected, why, where it is stored, and how to get rid of it.

The short version

  • Your pain, mood and sleep entries are stored so the app can show them back to you. Nothing else.
  • They are never sold, never shared with advertisers, insurers or employers, and never used to track you across other apps or websites.
  • They are never sent to our analytics or crash-reporting tools.
  • Nothing is stored on your phone to track you, and there is no advertising or cross-app tracking of any kind.
  • Deleting your account deletes all of it, permanently, straight away.

1. Who we are

Thala (“Thala”, “we”, “us”) is the data controller for the personal data described here. Thala is operated by Thala (sole trader, United Kingdom).

For any privacy question or request, write to privacy@thala.online.

2. What we collect

Account information

When you create an account we collect your email address and a password, plus the first and last name you choose to give. Passwords are handled by our authentication provider and stored only as a salted hash. We never see or store your password in a readable form.

If you use Sign in with Apple, we receive whatever Apple passes on: a unique identifier and either your real email address or Apple’s private relay address, depending on your choice. We cannot see your Apple ID password.

Health information you enter

This is the heart of the app, and it is special category data under UK and EU data protection law. It includes:

  • The body locations where you have pain, when each pain started, and whether it followed an acute injury (and when)
  • Your daily entries: the highest and lowest pain level (0–10) for each pain, roughly when in the day each occurred, and whether it hurts right now
  • The qualities you use to describe the pain
  • How you felt that day, chosen from a two-level feeling wheel
  • A sleep score for the night before
  • Stressful events you record, including any you note as present when a pain began
  • Any free-text notes you write on a day’s log

Device and technical information

  • Push notification token. If you turn on notifications, Apple issues a token for that device which we store so we can send you a notification when there is something new to read. It identifies a device, not you personally, and is deleted when the device stops accepting notifications or when you delete your account.
  • Diagnostics. If the app crashes or hits an error, our crash reporting tool records the error, a stack trace, the app version, and your device model and OS version. The report is labelled with your account identifier so we can tie it to a support conversation. It does not include your IP address, a screenshot, or anything you have entered.
  • Usage analytics. We record a short, fixed list of things that happen as you use the app: that you signed up, that you added a pain, which screen you opened, that you finished a check-in, and how many steps it took. These are recorded by our server, not by the app. There is no analytics software on your phone and nothing is stored on your device for this. Each record is labelled with your account identifier, so it is linked to your account. It never includes an answer you gave: no pain levels, no body locations, no moods, no sleep scores, no notes. Deleting your account deletes these too.

What never leaves the app’s own database

Your pain levels, moods, sleep scores, stressful events and notes are never included in analytics events or crash reports. Our analytics and error-monitoring providers do not receive your health data. The list of things analytics may record is fixed in the software itself, so it cannot quietly grow to include an answer you gave.

3. Why we use it, and our legal basis

WhatWhyLegal basis (UK/EU GDPR)
Account informationTo create your account, sign you in, and keep your data attached to youPerformance of a contract (Art. 6(1)(b))
Health information you enterTo store your diary, show it back to you as charts and history, and generate the insights and evidence in the appYour explicit consent (Art. 9(2)(a)), together with performance of a contract (Art. 6(1)(b))
Push notification tokenTo tell you when a new insight or piece of evidence is availableYour consent (Art. 6(1)(a)), given at the iOS permission prompt
DiagnosticsTo find and fix crashes and errorsLegitimate interests (Art. 6(1)(f)): keeping the app working
Usage analyticsTo understand which parts of the app are used, so we know what to improveLegitimate interests (Art. 6(1)(f)): improving the product

Because your diary entries are handled on the basis of your explicit consent, you can withdraw that consent at any time by deleting your account. Withdrawing consent does not affect anything done before you withdrew it.

4. How insights are generated

The insights and evidence the app shows you are produced by fixed rules running over your own entries, for example comparing your weekend days with your weekdays. They are not produced by profiling you against other users, are not used to make any decision about you, and have no legal or similarly significant effect. There is no automated decision-making within the meaning of Art. 22.

5. Who we share it with

We do not sell your data, and we do not share it with advertisers, data brokers, insurers or employers. We do not track you across other companies’ apps or websites, and we do not ask for permission to do so.

We do use a small number of service providers who process data on our behalf, under contract, and only on our instructions:

ProviderWhat they doWhat they hold
SupabaseAuthentication and the application databaseYour account details and all of your diary entries
RailwayHosting for the application serverProcesses your data in transit and keeps short-lived server logs. No copy of your diary
ResendSending account emails, such as a password reset codeYour email address and the contents of that message
Apple (APNs)Delivering push notificationsThe device token and the notification text
SentryCrash and error monitoringDiagnostic data as described above, labelled with your account identifier. No health data, no IP address
PostHogProduct analyticsUsage events labelled with your account identifier. No health data
VercelHosting this website, and counting visits to itPage-view counts for the website only. No cookies, and nothing linked to your account or to the app

We may also disclose data if we are legally required to (for example in response to a valid court order) or to establish or defend legal claims.

6. Where your data is stored

Your account and diary data are stored in the United Kingdom / European Economic Area. Where a provider processes data outside the UK or EEA, that transfer is covered by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, as set out in that provider’s data processing agreement.

All data is encrypted in transit, and encrypted at rest by our hosting providers.

We take an encrypted backup of the database once a day, so that a technical failure does not cost you your diary. Backups are held in the same region as the database and are kept for 7 days, after which they are destroyed. They are used only to restore the service after a failure.

7. How long we keep it

  • Your account and diary entries are kept for as long as your account exists. The whole point of the app is the long view, so nothing is aged out automatically.
  • Diagnostic data (crash and error reports) is kept for 90 days.
  • Usage analytics is kept for 24 months.
  • Server logs, which record the time and address of each request but not its contents, are kept for 30 days.
  • Database backups are kept for 7 days.
  • When you delete your account, your account and every entry attached to it are deleted immediately (see below), and we ask our analytics provider to erase your usage records at the same time. Backups taken before you deleted still contain your data until they age out on the 7-day cycle above; they are never used to restore a deleted account.

8. Deleting your account

You can delete your account from inside the app, at Account → Delete account. You will be asked to confirm it is you, with your password or by signing in with Apple again if that is how you created the account. Deletion is immediate and irreversible: your account, profile, pains, daily logs, moods, notes, notifications and device registrations are all removed. There is no recovery period and no way for us to restore it afterwards.

Step-by-step instructions are on the account deletion page.

9. Your rights

If you are in the UK or the EEA you have the right to: get a copy of your data; have inaccurate data corrected; have your data deleted; restrict or object to how we use it; receive it in a portable format; and withdraw consent at any time.

Most of these you can exercise yourself in the app: you can view and edit your entries, and delete everything. For anything else, email privacy@thala.online and we will respond within one month.

If you are unhappy with how we have handled your data you can complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EEA.

10. Children

Thala is not intended for children. You must be at least 16 years old to create an account. If we learn that we hold data from a child under 16, we will delete it.

11. Changes to this policy

If we change how we handle your data we will update this page and change the date at the top. If the change is significant, such as a new category of data or a new purpose, we will tell you in the app before it takes effect.

12. Contact

Privacy questions and requests: privacy@thala.online
Everything else: support@thala.online