Last updated 15 September 2026
Privacy
Thriving holds the details of your life so you don't have to. That only works if you can see exactly what happens to them, so this page is written in plain language. It covers the Thriving app and this website.
Who is responsible
The controller of the data described here is the operator of Thriving, a sole proprietorship in Switzerland, identified with a postal address in the Legal notice. For anything to do with your data, write to [email protected] .
The short version
- Your information is used to run Thriving for you. It is not sold, and it is not used to advertise to you.
- If you connect a Google account, Thriving asks only for read-only permissions. It has no permission to send, delete or change anything in your mailbox or calendar.
- AI reads what you give it to propose structure. By default nothing is written into your record until you confirm it.
- We do not use your content to train AI models, and our AI providers are contractually prohibited from doing so.
- You can export or delete everything from inside the app.
This website
If you join the early-access list, we store the email address you give us in order to invite you and to send occasional writing about mental load. The list is held by MailerLite, an EU email provider. Every email includes an unsubscribe link, and unsubscribing removes you from the list.
The site is served by Cloudflare, which keeps short-lived server logs (including IP addresses) for security and to keep the site running. We do not run analytics on this site and set no advertising or tracking cookies. Fonts are served from this domain.
Trying it on this page
If you use the demo in the banner, the text you type or dictate is sent to our AI provider (currently Anthropic) so it can be turned into structured items and shown back to you. We do not store what you type, and it is not linked to you or to any email address you give us. Our provider processes it under its API terms, which exclude training on your input.
To stop the demo being abused, we keep a count of requests per IP address for up to 24 hours. Nothing else is kept.
If you dictate instead of typing, the speech is transcribed by your browser using its vendor's speech service (for example Apple's or Google's), not by us. No audio reaches Thriving.
The app: what is collected
- What you tell it — voice recordings, typed notes, photographs and scans of documents, and the structured items (tasks, events, bills, documents, orders, renewals) created from them.
- What you connect — if you link a Google account, the emails and calendar entries needed to find obligations in them, and the access token that keeps the connection alive (stored encrypted).
- Your account — the email address and name provided by Apple or Google when you sign in, and the identifiers our authentication provider needs to keep you signed in.
- Your device — a push-notification token, the app version and iOS version, and Apple's device-attestation result used to protect the pre-account demo.
- Purchases — whether you have a trial or a paid plan, and the subscription state Apple (or Stripe, for web checkout) reports to us. We never receive your card number.
- How the app performs — counts, types, durations and outcomes of actions, tied to an internal account id, and crash reports. Our logging removes the content of what you captured before anything is written.
What it is used for, and on what basis
Swiss law and, for people in the EU and UK, the GDPR each require a lawful basis for processing. Ours are:
- To provide the service you asked for (performance of a contract): turning what you say, write, scan and receive into structured items; reminding you about them; answering questions about your own record; keeping you signed in; and running your subscription.
- With your consent: connecting a Google account; processing health-related content you choose to add (see below); sending you the early-access and writing emails. You can withdraw consent at any time, in the app or by email, without affecting what happened before.
- Our legitimate interests, balanced against yours: keeping the service secure and preventing abuse; diagnosing failures; understanding how the app is used so we can improve it, using metadata rather than content; and defending legal claims.
- Legal obligations: keeping accounting records for the period Swiss law requires, and answering lawful requests from authorities.
We do not use your content for advertising, and we do not sell or rent it.
Sensitive information
Thriving does not ask for sensitive information, but a life contains some: medical bills, insurance letters, school and health documents about your children. When you choose to add such content, you consent to its processing as described here, for the sole purpose of organising it for you. Under Swiss law and the GDPR this counts as explicit consent to processing sensitive personal data. You can delete any such item at any time.
Other people's information
Your record will contain information about other people — your children, partner, landlord, doctor, the sender of an email. You are responsible for having a legitimate reason to hold it, which for ordinary household and family administration you normally do. Thriving processes it only on your behalf and only to organise your own life.
Audio and documents
Voice recordings are deleted once they have been transcribed. Documents are kept because you will need them later; you choose whether their extracted text stays searchable, and you can delete any document together with everything extracted from it.
AI processing
Thriving sends your content to AI providers to transcribe speech, read documents and propose structure. Each provider processes it on our instructions under a data processing agreement, is contractually prohibited from training on it, and retains it only for the short period its terms allow for abuse monitoring (at most 30 days). We prefer providers that process in Europe where they offer it. Our providers receive a bounded payload for each request and have no access to your account, database or files.
Every AI output is a proposal. By default, Thriving does not change your record without your confirmation. The one exception is a narrow one: the status of an order (shipped, delivered) may be updated automatically from an email that comes from a verified sender on our retailer list and passes authentication checks. Nothing else is automatic.
Email and document content is treated as untrusted data throughout. The system is designed so that text inside a message cannot instruct it to take an action, and anything that looks like an instruction is flagged for your review. No such design is perfect, so we ask you to read what the app proposes before you confirm it.
Google user data
If you connect a Google account, Thriving requests read-only scopes only
(gmail.readonly, calendar.readonly and basic profile). Data
received from Google APIs is used solely to identify obligations — bills, renewals,
deadlines, appointments and awaited replies — and present them to you for confirmation.
Only the messages and entries relevant to that purpose are retained, and email snippets
are stored in bounded form.
Thriving's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, not transferred for advertising, and not used to train generalised AI models. You can disconnect a Google account at any time from inside the app, which stops all access and deletes the stored token.
Who receives your data
Service providers that make the product work, each under a data processing agreement and only for what they are contracted to do. At the date above they are:
- Railway — application hosting and database (EU region)
- Amazon Web Services — file storage (Frankfurt)
- Clerk — authentication
- Anthropic, OpenAI and Google — AI processing and transcription, depending on the task
- Sentry — crash and error reporting (EU)
- PostHog — usage analytics without content (EU)
- Apple — sign-in, push notifications and App Store billing
- Stripe — web checkout, where offered
- Cloudflare — website hosting; MailerLite — the early-access list
We may update this list as providers change; the current version is always on this page and available on request.
Beyond providers, we disclose data only where we have to: to comply with a law, court order or lawful request from an authority; to protect the rights, safety or property of Thriving, its users or others; or, if Thriving is sold, merged or restructured, to the successor, who takes it over under this policy.
Nobody at Thriving reads your content in the ordinary course of business. Support and diagnostic tools show job states and metadata, not what you said or uploaded. If solving a problem you report requires looking at a specific item, we ask for your consent for that item first, access is time-limited, and it is logged. We may also access content where the law requires it or to investigate abuse of the service.
Where it is stored, and how it is protected
Data is stored in the European Union and encrypted in transit and at rest. Access to each user's records is enforced by the database itself, not only by application code. Connected-account tokens are stored encrypted. Some providers process data outside Switzerland and the EU; where they do, transfers rely on the European Commission's standard contractual clauses with the Swiss addendum, or on an adequacy decision.
No system is perfectly secure. If a breach affecting your data occurs, we will inform the competent authority and, where the law requires it, you.
How long it is kept
- Your record: for as long as your account exists.
- Deleted items: 30 days in Recently Deleted so you can undo, then removed.
- Voice recordings: deleted as soon as they are transcribed.
- Dismissed AI suggestions: 30 days.
- Connected-account tokens: until you disconnect the account or delete yours.
- Crash reports and technical logs: up to 90 days.
- Usage analytics: kept in aggregate form; individual event data up to 12 months.
- Early-access list: until you unsubscribe.
- Purchase and accounting records: ten years, as Swiss law requires.
When you delete your account, your data is removed from live systems immediately and from backups within 90 days, except records we are legally required to keep.
Your rights
Under Swiss data protection law and, where it applies, the GDPR, you can ask for a copy of your data, have it corrected or deleted, restrict or object to its processing, withdraw consent, and receive it in a portable format. Export and account deletion are built into the app (Settings → Privacy & Data), and you can always write to [email protected] . We may ask you to confirm your identity, and we answer within the statutory period, normally 30 days.
If you are unhappy with how we have handled your data, we would like to hear it first. You also have the right to lodge a complaint with a data protection supervisory authority.
No automated decisions
Thriving makes no decisions about you that have legal or similarly significant effects. AI proposes; you decide.
Children
Thriving is for adults. It is not directed at children and we do not knowingly create accounts for anyone under 16; if we learn that we have, we delete the account. You may record information about your own children — it belongs to your account and is governed by this policy.
Changes
If this policy changes in a way that affects you, we will tell you by email or in the app before the change takes effect, unless the change is required by law or is needed to address a security issue, in which case it may take effect immediately. The date at the top always shows the current version.
Contact
[email protected] — postal address in the Legal notice.