Our Privacy Promise
Your time audit data is yours alone. We never see what you track, how you tag it, or what you write in your notes — that data stays on your device (and your iCloud if you choose to sync). The only information that leaves your device is anonymous, hashed usage signals that tell us things like whether a feature was used, never what you used it for. ThenAudit is designed as a local-first application that keeps your time tracking entries, reflections, and audit results private, storing everything on your device by default. We collect only the minimum information necessary to deliver the app and optional premium features.
What We Collect
Information You Provide
- Time Tracking Data: Your 15-minute interval entries, including time slots, activities, and associated reflection categories (Aligned, Maintenance, Leak, Recovery) are stored locally on your device.
- Audit Data: Your weekly episodic audits, patterns, insights, and notes are stored locally on your device.
- Premium Purchases: When you subscribe to premium features, Apple handles payment processing. We receive a transaction identifier through RevenueCat but never see your payment details.
- Support Communications: If you contact us for support, we may receive your email address and any information you choose to provide.
Information Collected Automatically
- Device Information: Basic device type and iOS version for app compatibility (collected by Apple, not us).
- Crash Reports: Anonymous crash data through Apple's standard crash reporting (opt-in via iOS Settings).
- Premium Subscription Status: Verification of subscription status through RevenueCat's privacy-compliant service.
- Anonymous Usage Analytics: We collect anonymized, non-personally-identifiable usage signals to understand how the app is used and improve the experience. This includes events such as whether onboarding was completed, which lifecycle phases were reached, and which features were used. The content of your audits — your time entries, activity descriptions, reflection tags, and notes — is never sent to our servers or any third party. All user identifiers are cryptographically hashed before leaving your device — we never see or store your actual identity. Analytics are processed by TelemetryDeck, a privacy-focused analytics provider based in the EU. No advertising identifiers, location data, or personal information are collected or transmitted.
What We Don't Collect
- Personal identifiers beyond what's necessary for premium features
- Location data
- Third-party advertising identifiers
- Health or fitness data beyond time audit categories
- Contact lists or social graphs
- Biometric data
How We Use Information
Core App Functionality
- Store your time tracking and audit data locally on your device
- Enable iCloud sync between your devices (Premium feature, optional)
- Process premium subscription status through RevenueCat
- Deliver notification nudges at your configured times (local notifications only)
- Generate audit insights and patterns based on your tracked data
Support & Improvement
- Respond to support requests you initiate via email
- Fix bugs reported through crash reports
- Ensure app compatibility with iOS updates
- Improve the time audit methodology based on aggregate, anonymized patterns
- Product Improvement: We analyze anonymous, aggregate usage patterns to understand where users encounter friction, which features provide value, and how to improve the app experience. This data is never linked to your identity and cannot be used to identify individual users.
Data Storage & Security
Local-First Architecture
- All time tracking entries, audit data, and personal reflections live on your device using iOS's secure local storage
- No ThenAudit servers store your personal time audit data
- Data persists through app updates but is removed if you delete the app
- Your data remains under your control at all times
iCloud Sync (Premium Feature)
- If enabled, uses Apple's encrypted iCloud infrastructure
- Syncs only between devices logged into the same Apple ID
- Apple's end-to-end encryption protects data in transit and at rest
- You can disable iCloud sync at any time in app settings
Security Measures
- All local data is protected by iOS's built-in security features
- Data is sandboxed and inaccessible to other apps
- No audit content is transmitted to third-party servers — only anonymous usage signals (via TelemetryDeck) and subscription status (via RevenueCat)
- Regular security reviews of our minimal third-party dependencies
Third-Party Services
RevenueCat (Premium Subscriptions)
Purpose: Manages premium subscription verification
Data Shared: Anonymous app user ID and transaction identifiers
Privacy Policy: https://www.revenuecat.com/privacy
Purchase events from RevenueCat are correlated with anonymous usage analytics through a shared cryptographic hash to verify subscription delivery and improve the overall app experience. This correlation uses only anonymous identifiers — no personal information is shared between services.
TelemetryDeck (Product Analytics)
Purpose: Anonymous, privacy-first product analytics
Data Shared: Cryptographically hashed identifiers and anonymous event data — TelemetryDeck cannot identify you personally
Privacy Policy: https://telemetrydeck.com/privacy
TelemetryDeck is GDPR-compliant, based in the European Union, and does not sell or share data with third parties.
Apple Services
- App Store: Handles app distribution and payment processing
- iCloud: Provides optional sync functionality for premium users
- CloudKit: Powers iCloud sync with end-to-end encryption
- Privacy Policy: https://www.apple.com/privacy
Your Privacy Rights
Access and Control
- View: All your data is visible within the app
- Export: Premium users can export their audit data
- Delete: Remove individual entries or clear all data in Settings
- Portability: Your local data travels with your device backups
California Privacy Rights (CCPA)
- Right to know what information we collect
- Right to delete your information
- Right to opt-out of data sales (we never sell your data)
- Right to non-discrimination for exercising privacy rights
European Privacy Rights (GDPR)
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
To exercise any of these rights, contact us at privacy@houseofthen.com.
Children's Privacy
ThenAudit is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
Data Retention
Local Data
- Time tracking and audit data remains on your device indefinitely
- Deleted data is immediately removed and cannot be recovered
- App deletion removes all local data permanently
Support Communications
- Support emails are retained for service quality and legal compliance
- Deleted after resolution unless legally required to maintain
Subscription Records
- Managed by RevenueCat according to their retention policies
- Necessary for subscription management and fraud prevention
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last Updated" date, providing in-app notification for significant changes, and requesting consent where legally required. Your continued use of ThenAudit after changes indicates acceptance of the updated policy.
Contact Us
House of Then, LLCEmail: privacy@houseofthen.com
Website: https://houseofthen.com
For the most responsive support: use the in-app support feature (premium users) or email us directly with "ThenAudit Privacy" in the subject line.
This Privacy Policy is governed by the laws of California and the United States. By using ThenAudit, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.