Privacy Policy

Last updated 2026-09-29 · There & Then is a personal project, currently in invite-only beta.

There & Then is a place to capture your memories. This policy explains, in plain language, what we collect, how it is protected, and — importantly — what we are honest about not protecting. These are good-faith beta policies, not a substitute for legal advice.

What we collect

How your data is protected

How you sign in

You sign in with Google or with Apple — we never handle a password, and we never receive one. The provider tells us a permanent identifier for your account there, your email address, and whether it has verified that address. We store all three. If a provider will not vouch for an address, we refuse the sign-in rather than trust it.

Other people: friends and shared spaces

There & Then is private by default. Nothing you capture is visible to anyone else until you deliberately move it into a shared space. Two things are worth stating plainly, because they are the only ways another person sees anything of yours.

What we are honest about

There & Then is not end-to-end encrypted. To provide features like search, Ask, and maps, our server holds the encryption keys and decrypts your notes in memory when needed — and your location history and timestamps are not encrypted at the application layer. That means a valid legal order, or someone who fully compromised our server (including complete server images held by our hosting provider), could reach your content. We are not a zero-knowledge service, and we would rather tell you that plainly than imply otherwise.

In short, three layers exist: the host encrypts the physical disks, we encrypt your note content inside the database, and the server — which must run search and maps for you — can decrypt that content transiently while doing so.

What the operator can see. Some information is not encrypted at the application layer, because running the service requires reading it: how many notes you have, when you captured them, where, if you attached a location, the email addresses on your account, and when you last signed in. This is visible to the operator only — not to other users, and not to the public. It travels over an encrypted connection, sits on storage our host encrypts, and is reachable only through authenticated administrative access. It is used to run and support the service, not to analyse your memories.

AI features and third-party processing

There & Then includes an AI-powered "Ask" feature that answers questions about your own notes. Two different kinds of processing are involved:

Other services that process data on our behalf: Google (sign-in, and maps/geocoding — so Google receives location when a map loads), Apple (sign-in), Cloudflare (network edge), and our hosting provider. We do not sell your data and we do not run ads.

Transparency

If we ever receive a legal request for your data, we will notify you where we are legally permitted to, and we will resist requests that are overbroad or improper. If there is ever anything to report, we will publish a transparency summary.

Canary: as of 2026-09-29, we have received zero legal requests, subpoenas, or national-security letters concerning user data, and we have never been asked to weaken or bypass our encryption. We refresh this statement with each policy update — treat its absence or staleness as meaningful.

Your control

What deleting your account removes

Deleting your account is immediate and permanent in the service itself. We would rather tell you exactly where the edges are than leave you with a promise that is slightly bigger than the truth.

Gone straight away. Your notes and their stored ciphertext, your photos (including the stored files), the keys that decrypt them, your email addresses, sign-in methods, devices, friendships, any space you own, your onboarding and usage records. Notes you wrote and placed in someone else's shared space go with you. Notes other people wrote in a space you owned are returned to them first — deleting your account never deletes anyone else's memories.

If you need your data gone from the backups sooner than the schedule above, get in touch and we will tell you honestly what is possible.

Contact

Questions about privacy? Use the contact form.