Your reading is yours.
ThoughtDrop uses a reader account to sync across devices. It is not an everything-is-local service. Deployment and merchant contact details must be finalized before live sales.
Your account and synced collection
Better Auth handles Google or Apple sign-in. We store your account ID, name, email (including an Apple private-relay address), provider identity, encrypted provider tokens, and revocable sessions in PostgreSQL. Your settings, topics, schedule, saved snapshots, and loved snapshots sync to your account. Save and Love are separate choices. These essential sync records do not require analytics consent and are retained until removed or your eligible account data is deleted.
What stays on your Mac
Device-specific display selection and local caches stay on the Mac. Native session credentials are stored in Keychain. ThoughtDrop does not collect other windows, screen contents, browsing activity, or search text. Local reading history is not retrospectively uploaded when you enable activity.
Payments
Dodo Payments processes checkout, payment methods, receipts, and billing contact information. We send your account name and email to create your billing customer and retain customer, subscription, checkout, and payment references plus verified subscription dates and status. We do not store payment card numbers. Cancelling does not delete your saved or loved ideas.
Optional reading activity
Reading activity is opt-in and off by default. If enabled, we store your account ID with a random event ID, idea ID and revision, a read event type, and its timestamp. This is account-linked, not anonymous. It powers the count of reads in the last 30 days; it does not automatically change your chosen topics. Events older than 30 days are excluded from that count and deleted by the daily retention job. We do not record raw search strings.
Turning activity off
Saving consent as off immediately deletes your server-side reader events in the same transaction and stops new uploads; the Mac discards pending events. Synced saves, loves, and settings are unaffected. You can sign out other devices from your account page. Contact the merchant support address on your receipt for export or deletion of eligible account data; accounting and legal records may need longer retention.
Operational and legacy records
Session and network metadata may be processed by the host, Google or Apple, and Dodo. Expired sessions and device codes are pruned daily. Successfully processed commerce webhook references are retained for 90 days; unresolved failures remain for support. Editorial release and audit records are retained. Operators must suppress query strings, request bodies, cookies, and authorization headers in logs and protect database backups. Legacy one-time test licenses retain keyed license hashes, installation IDs, and activation references separately; they do not create a reader subscription.