Privacy Policy
Last updated 2026-09-29 · There & Then is a personal project, currently in invite-only beta.
There & Then is a place to capture your memories. This policy explains, in plain language, what we collect, how it is protected, and — importantly — what we are honest about not protecting. These are good-faith beta policies, not a substitute for legal advice.
What we collect
- The notes you write or dictate, and when you captured them. A dictated note reaches us as text, the same as a typed one — we never receive the audio.
- Photos you attach to a memory (up to four each).
- Location you attach to a note: GPS coordinates and a place label.
- Account details from your sign-in provider: email, display name, and avatar.
- Basic device and security information: a device identifier, browser family, and IP address, used to keep your account secure.
- Search data derived from your notes: a semantic search index (numeric embeddings) and automatic category tags, both built on our own servers, so you can search, ask questions about, and see breakdowns of your memories.
- A record of your use of the two features that cost us money per use: when you ask a question and how much processing it needed, and when you search for a place name. We record the counts and sizes, never the text of your question, the answer, or what you searched for. We use this to understand what the service costs to run and to plan pricing. It is deleted with your account.
How your data is protected
- Everything travels over an encrypted connection (HTTPS/TLS) between your device and our servers.
- Your data is stored on infrastructure with encryption at rest — our host encrypts the physical storage devices.
- Your note content is additionally encrypted at the application layer (AES-256-GCM, per-account keys): in our database it exists only as ciphertext. A stolen copy of the database or a leaked database backup does not reveal what you wrote.
- Photos you attach are protected the same way as your notes — encrypted at the application layer (AES-256-GCM, per-account keys) and stored as ciphertext, so the stored file is not a viewable image without our keys. Before a photo leaves your device it is re-encoded, which strips embedded metadata such as GPS location from the image file.
- Your notes are isolated per user, enforced in the database (Postgres row-level security) — not just by the application. If you use shared spaces, a note you place in a space is visible to that space's members (and only them) until you move it back; shared notes are always labeled with their space and author.
- Sign-in is OAuth-only; we never see or store a password.
- While you are using Ask, your recent conversation — your questions and There & Then's answers, which quote text from your notes — is kept in your browser's local storage on your own device so it survives moving around the app or reopening it. It is discarded once it is more than 30 minutes old — the next time you open There & Then — when you start a new conversation, or when you sign out.
- While you are typing a note, the text you have not yet saved is also kept in your browser's local storage on your own device, so it is not lost if the page reloads, the tab is closed, or your phone closes the app in the background. It never leaves your device until you save the note. It is discarded when you save the note, when you sign out, or once it is more than seven days old, and it is only ever shown back to the account that typed it.
How you sign in
You sign in with Google or with Apple — we never handle a password, and we never receive one. The provider tells us a permanent identifier for your account there, your email address, and whether it has verified that address. We store all three. If a provider will not vouch for an address, we refuse the sign-in rather than trust it.
- You can have more than one way in, and more than one address. Both are managed from Account. A second sign-in method is worth having: there is no password to fall back on, so if you lose access to the only one you have, we cannot recover the account for you.
- Adding a sign-in method requires being signed in already. If you try to sign in a new way using an address that is already on an account, we refuse, and tell you which method that account uses. Signing in as an address is not by itself enough to join it to an existing account — otherwise anyone who later acquired an address you used to hold could walk into it.
- If you end up with two accounts, they stay separate. We have no way to join them together at the moment — not automatically, and not on request. Get in touch if it happens and we will work out what to do; the honest answer today is that the simplest route is usually to keep using the one that has your memories in it.
- Apple's Hide My Email gives us a relay address ending
@privaterelay.appleid.cominstead of your real one. We treat it as your address and send to it; Apple forwards it on. We never learn the address behind it, and if you turn forwarding off at Apple, mail from us stops arriving.
Other people: friends and shared spaces
There & Then is private by default. Nothing you capture is visible to anyone else until you deliberately move it into a shared space. Two things are worth stating plainly, because they are the only ways another person sees anything of yours.
- Friends are mutual. A connection exists only after one person asks and the other accepts. Anyone who already knows your email address can send you a friend request; until you accept, they learn nothing about you, and a pending request in either direction shows only a display name — never an email address.
- Once you are friends, they can see the email address on your account — the address you actually sign in with, which is not necessarily the one an invite was sent to. This is so you can tell people apart when you share with them. It is visible in the app to that friend only: there is no directory, no search by name, and we never publish it.
- If you invited someone and they joined, you can see the address they signed up with, alongside the address you sent the invite to. They accepted an invite you sent them personally. The reverse is not true — joining with someone's invite does not show you their address.
- Shared spaces show a note to that space's members, and only them, from the moment you move it in until you move it back. Shared notes are always labeled with their space and their author, and leaving a space (or the space being deleted) returns your notes to your private vault.
- Unfriending ends the connection and stops the email address being shown. It does not remove either of you from spaces you both joined — that is managed per space — and it does not prevent someone who knows your email address from sending a new request. There is currently no block feature; if someone is bothering you, use the contact form.
What we are honest about
There & Then is not end-to-end encrypted. To provide features like search, Ask, and maps, our server holds the encryption keys and decrypts your notes in memory when needed — and your location history and timestamps are not encrypted at the application layer. That means a valid legal order, or someone who fully compromised our server (including complete server images held by our hosting provider), could reach your content. We are not a zero-knowledge service, and we would rather tell you that plainly than imply otherwise.
In short, three layers exist: the host encrypts the physical disks, we encrypt your note content inside the database, and the server — which must run search and maps for you — can decrypt that content transiently while doing so.
What the operator can see. Some information is not encrypted at the application layer, because running the service requires reading it: how many notes you have, when you captured them, where, if you attached a location, the email addresses on your account, and when you last signed in. This is visible to the operator only — not to other users, and not to the public. It travels over an encrypted connection, sits on storage our host encrypts, and is reachable only through authenticated administrative access. It is used to run and support the service, not to analyse your memories.
AI features and third-party processing
There & Then includes an AI-powered "Ask" feature that answers questions about your own notes. Two different kinds of processing are involved:
- Search indexing runs on our own servers. The semantic index that makes your notes searchable is built by a model we host ourselves — no outside company receives your notes to build it.
- Photos are not analyzed. Today your photos are kept only for you to look back on — their contents are not read, indexed, or sent to any AI provider, and they do not feed search or Ask. If that ever changes (for example, describing what's in a photo so it can be searched), we will update this policy before doing so.
- Dictation is done by your browser, not by us. When you tap the microphone, the speech-to-text is performed by your web browser's own speech service, and all we receive is the finished text. Depending on the browser, that service may send your voice to the company that makes it to be converted — for example Google in Chrome, Microsoft in Edge, or Apple in Safari, which may instead do it on your device. That happens under that company's terms, not ours: we never receive, store, or have any way to hear the audio. If you would rather no one else processes your voice, type the note instead.
- Answering a question uses a third-party AI provider. When, and only when, you use the Ask feature, we transmit a limited portion of your content — the small set of notes relevant to your question (their text, timestamps, and any location labels), together with your question — to Anthropic (provider of the Claude models) so it can compose the answer. We send only what is needed to answer that question, never your full account, and nothing is sent unless you use the feature. Under our agreement with Anthropic, this content is processed solely to generate your answer, is not used to train any AI model, and is retained by Anthropic only transiently, for security and abuse-prevention, under its API terms.
Other services that process data on our behalf: Google (sign-in, and maps/geocoding — so Google receives location when a map loads), Apple (sign-in), Cloudflare (network edge), and our hosting provider. We do not sell your data and we do not run ads.
Transparency
If we ever receive a legal request for your data, we will notify you where we are legally permitted to, and we will resist requests that are overbroad or improper. If there is ever anything to report, we will publish a transparency summary.
Canary: as of 2026-09-29, we have received zero legal requests, subpoenas, or national-security letters concerning user data, and we have never been asked to weaken or bypass our encryption. We refresh this statement with each policy update — treat its absence or staleness as meaningful.
Your control
- You can export or delete all of your data yourself, anytime — "Export my data" downloads everything as a file, and "Delete my account" (both at the bottom of the app) erases your account and every memory from the live service, immediately and irreversibly. Before you confirm, we show you exactly what will go, including what it means for any spaces you share. You can also delete any individual memory from its edit screen. For anything else, use the contact form.
- We keep your data until you ask us to delete it. What happens next is set out under What deleting your account removes — including the parts that take longer to disappear.
- There & Then is not directed to children under 13.
- If this policy changes, we will update the date above and, for material changes, note it in the app.
What deleting your account removes
Deleting your account is immediate and permanent in the service itself. We would rather tell you exactly where the edges are than leave you with a promise that is slightly bigger than the truth.
Gone straight away. Your notes and their stored ciphertext, your photos (including the stored files), the keys that decrypt them, your email addresses, sign-in methods, devices, friendships, any space you own, your onboarding and usage records. Notes you wrote and placed in someone else's shared space go with you. Notes other people wrote in a space you owned are returned to them first — deleting your account never deletes anyone else's memories.
- Backups take longer, and this is the real limit. We keep encrypted backups of our database on a rolling schedule — daily for a week, weekly for a month, and monthly for up to six months — so we can recover from a disaster. A deleted account stays inside those snapshots until they age out, up to about six months. We do not reach into a backup to edit one account out of it: a backup that can be rewritten is not a backup you could trust in the moment it matters. In those snapshots the content of your notes is still ciphertext, and the key that decrypts it is deliberately not kept with them; your photos are stored separately and are not in these backups at all. Identifying details such as your email address, and the times and places attached to notes, are readable there until the snapshot expires.
- Invitations. An invitation you redeemed leaves a record that it was used, but your address is removed along with your account. An invitation you sent keeps the address you sent it to — that address belongs to the person you invited, and their invitation may still be outstanding.
- Messages you send us. A message sent through the contact form is correspondence with us, not part of your account, so deleting your account does not delete it. It holds the name and address you typed. Ask us and we will delete it.
- Technical logs. Routine server logs — IP addresses, which pages and endpoints were requested, and a line recording that an account was deleted — are kept for at most about two weeks and then discarded. They are not included in the backups above.
- Other companies. Deleting here does not reach into records held by Google or Apple about your sign-ins, or Cloudflare's network logs. Ask them directly.
If you need your data gone from the backups sooner than the schedule above, get in touch and we will tell you honestly what is possible.
Contact
Questions about privacy? Use the contact form.