Legal
Privacy Policy
This policy explains how THINKPOD STUDIOS LIMITED ("Thinkpod Studios", "we", "us") collects and uses personal data through our website and our mobile applications. We keep it in plain English and we keep it current.
1. Who we are
The data controller for the website and applications described in this policy is:
THINKPOD STUDIOS LIMITED
Registered in Northern Ireland, Company No. NI737566
Registered office: 31 Vale Road, Greysteel, Londonderry, Northern Ireland, BT47 3BL
Email: studio@thinkpodstudios.co.uk
We are not currently required to appoint a Data Protection Officer. All privacy questions and requests should be sent to the email address above, which is monitored by the people responsible for data protection at the company.
2. Scope
This policy covers:
- this website, https://thinkpodstudios.co.uk; and
- mobile applications published by THINKPOD STUDIOS LIMITED on the Apple App Store and Google Play.
Where a specific app collects data beyond what is described here, its store listing and in-app notices will say so, and this policy will be updated before that app is released.
3. Information we collect on the website
3.1 Correspondence
The only way to contact us through this site is by email. When you email us, we receive whatever you choose to send — typically your email address, your name and the content of your message. We use it to reply to you and to keep a record of our correspondence.
3.2 Technical and server logs
The website is served by our hosting provider, Cloudflare. As part of delivering and securing the site, Cloudflare processes technical request data such as your IP address, user agent (browser and device information) and details of the pages requested. This processing exists for security (for example blocking malicious traffic) and reliable delivery of the site.
3.3 No analytics or advertising cookies
This website itself sets no analytics cookies and no advertising cookies. See our Cookie Policy for the full picture, including the strictly-necessary cookies Cloudflare's security layer may set.
4. Information we collect in our apps
The following describes the categories of data our mobile apps may process. Any individual app may use only a subset of these; each app's store listing declares exactly what that app collects.
4.1 Account information
Only if an app offers user accounts: your email address and a display name you choose. We use these to create and secure your account and to let you sign in across devices. Apps without accounts collect none of this.
4.2 User content
Content you create inside an app (for example notes, entries, settings or files, depending on the app) is stored on your device. If the app offers sync and you enable it, a copy is also stored on our servers so it can be restored and shared across your devices. Your content remains yours — see our Terms of Use.
4.3 Device and technical data
To make the app work and to diagnose problems, we may process: device model, operating system version, app version, language setting, crash state, and a non-advertising install identifier (a random identifier scoped to the app installation, used to de-duplicate diagnostics — not to profile you and not shared with advertisers).
4.4 Usage analytics
If enabled for a given app, we collect aggregated feature-usage events (for example, "how many installs used the export feature this week") to understand which features matter. This never includes advertising identifiers and is not used to build individual profiles.
4.5 Crash and diagnostics reports
If an app crashes, a diagnostic report (stack trace, device model, OS and app version, and the crash state) may be collected so we can fix the bug. Crash reports are not used for any other purpose.
4.6 App permissions
Our apps request system permissions only when a feature needs them. Every permission is optional, requested in context, and revocable at any time in your device's system settings — the app will keep working, minus that feature. Permissions an app may request include:
| Permission | Purpose |
|---|---|
| Notifications | Reminders and alerts you have asked the app to send. Never used for marketing without separate consent. |
| Camera / photo library | Only where an app lets you attach or scan images; images are processed for that feature alone. |
| Files / storage | Only where an app lets you import or export documents you choose. |
4.7 What we do NOT do
- We do not sell personal data — to anyone, ever.
- We do not include advertising SDKs in our apps.
- We do not track you across other companies' apps or websites.
- We do not collect precise location data.
5. Purposes and lawful bases
Under UK GDPR we must have a lawful basis for each use of personal data:
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Replying to your enquiries | Email correspondence | Legitimate interests (responding to people who contact us) or steps prior to entering a contract |
| Providing app features you use | Account information; user content; device & technical data | Performance of a contract (our Terms of Use with you) |
| Securing the website and apps | Server/security logs; device & technical data | Legitimate interests (protecting our services and users from abuse and fraud) |
| Fixing bugs and crashes | Crash & diagnostics reports | Legitimate interests (maintaining working, safe software) |
| Understanding aggregate feature usage | Usage analytics (aggregated, where enabled) | Consent, where sought in-app; otherwise legitimate interests in improving the product, using aggregated non-identifying events |
| Sending optional notifications | Notification token; account information | Consent (the system permission prompt), withdrawable in settings at any time |
| Keeping business and tax records | Correspondence; billing records | Legal obligation (UK company, tax and accounting law) |
6. Who we share data with
We share personal data only with service providers who process it on our behalf under contract, and only as needed:
- Cloudflare, Inc. — website hosting, content delivery and security for this site.
- Apple Inc. and Google LLC — distribution of our apps through the App Store and Google Play and, where an app offers in-app purchases or subscriptions, processing of the purchase transaction. For the purchase itself, Apple and Google act under their own privacy policies; we receive no full payment card details.
- Crash reporting / analytics tooling — only where enabled for a given app, a processor may receive the crash and aggregated usage data described in section 4. We commit to keeping this section current and naming any such provider here before it is used in a released app.
We do not sell or rent personal data. We may disclose data where required by law, court order or a competent authority, and we will challenge requests we believe are unlawful or overbroad.
7. International transfers
Some of our providers process data outside the UK — for example, Cloudflare operates a global network. Where personal data leaves the UK, we rely on one or more of the safeguards recognised by UK law: UK adequacy regulations for the destination country, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or standard contractual clauses with supplementary measures where appropriate.
8. Retention
We keep personal data no longer than needed:
| Data | Retention period |
|---|---|
| Email correspondence | Up to 24 months after our last contact with you, then deleted (unless needed for a legal claim or record we must keep) |
| Server / security logs | Held by Cloudflare on a short rolling retention per its policies; we do not keep separate copies |
| App account data | For as long as your account exists; deleted within 30 days of account deletion |
| Crash & diagnostics data | 90 days |
| Backups | Purged on a rolling 30-day cycle, so deleted data leaves backups within 30 days |
9. Your rights
Under UK GDPR you have the right to:
- Access — ask for a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected and incomplete data completed;
- Erasure — ask us to delete your data ("right to be forgotten") where there is no overriding reason to keep it;
- Restriction — ask us to pause processing while a dispute or check is resolved;
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format;
- Objection — object to processing based on legitimate interests, and to any direct marketing (we currently send none);
- Withdraw consent — at any time, where processing is based on consent (for example notification permissions), without affecting processing before withdrawal;
- Automated decision-making — rights in relation to solely automated decisions with legal or similarly significant effect. We make no such decisions.
To exercise any right, email studio@thinkpodstudios.co.uk. We respond within one month. We may need to verify your identity before acting on a request — we will only ask for what is proportionate to the request.
10. Complaints
You have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO): https://ico.org.uk/ · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113. We would appreciate the chance to resolve your concern first — please contact us at studio@thinkpodstudios.co.uk — but you may go to the ICO at any time.
11. Children
Our website and apps are not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has provided us with personal data, a parent or guardian may contact us at studio@thinkpodstudios.co.uk and we will delete it. The age ratings shown on each app's App Store and Google Play listing apply.
12. Account and data deletion
You can delete your account and associated data at any time, in two ways:
- In the app — once our apps ship, each app with accounts includes a deletion path at Settings → Account → Delete account; or
- By email — send a request to studio@thinkpodstudios.co.uk with the subject line "Account deletion request" from the email address linked to the account.
Deletion is completed within 30 days, including removal from rolling backups. We may retain a minimal record where the law requires it — for example invoices and payment records kept for tax and accounting law — and we retain only what those obligations require, for only as long as they require it.
13. iOS App Tracking Transparency
Our apps do not track users across other companies' apps and websites, and share no data with data brokers or advertising networks. Because there is no tracking as defined by Apple's App Tracking Transparency framework, our apps show no ATT permission prompt. If this ever changes for a future app, that app will request your consent first via the ATT framework, and this policy will be updated beforehand.
14. Google Play Data Safety
For every app we publish on Google Play, the Data Safety declaration on the store listing mirrors this policy: same data categories, same purposes, same sharing. If you ever spot a mismatch, tell us and we will correct it.
15. Security
We protect personal data with measures appropriate to the risk: TLS encryption for all data in transit; encryption at rest where applicable on our servers and backups; least-privilege access, so data is accessible only to those who need it for a specific task; and dependency and security patching as part of routine maintenance. If a personal data breach occurs that risks your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Articles 33 and 34.
16. Changes to this policy
When we change this policy we update the "last updated" date at the top, and the effective date where obligations change. For material changes affecting app users — for example a new data category or a new processor — we will give notice in the app or by email (where we have an address) before the change takes effect. Previous versions are available on request.
17. Contact
Email: studio@thinkpodstudios.co.uk
Post: THINKPOD STUDIOS LIMITED, 31 Vale Road, Greysteel, Londonderry, Northern Ireland, BT47 3BL