Thank You

Privacy Policy

Version 1.0 · effective from April 26, 2026

Contents

  1. Who we are
  2. What data we collect
  3. Why and on what legal basis
  4. How long we keep data
  5. Who we share data with
  6. Transfers outside the EU
  7. Your rights
  8. Message recipients (non-registered)
  9. Cookies
  10. Security
  11. Children
  12. California residents (CCPA)
  13. Changes to this policy

1. Who we are

The operator of the Thank You App service (the "Service") is:

Under Regulation (EU) 2016/679 (GDPR), we are the data controller. We are not required to appoint a Data Protection Officer (DPO) — we do not process special categories of data on a large scale.

2. What data we collect

2.1 About you (the user)

2.2 About your messages

2.3 About recipients in your address book

If you save a recipient to your address book, we store their name, email, and relationship (e.g., "parent", "colleague"). You are responsible for adding recipients and should have a legitimate reason (a personal relationship).

2.4 What we do not collect

3. Why and on what legal basis

DataPurposeLegal basis
Email, name, passwordAccount operationContract performance (Art. 6(1)(b) GDPR)
Message contentDelivery at scheduled timeContract performance
Recipient emailMessage deliverySender's legitimate interest (Art. 6(1)(f))
Login logs (IP, user-agent)Security, fraud prevention, auditLegitimate interest
Email verificationAnti-spam, recipient protectionLegitimate interest
Consent recordProof of consent for authorityLegal obligation

4. How long we keep data

5. Who we share data with (processors)

We never sell your data. To deliver the Service we use the following processors, contractually bound to protect your data:

ProcessorWhat they doLocation
Brevo (Sendinblue)Sending emails (gratitude, verification, reset)France (EU)
GoogleSign-in via Google OAuthUSA
RailwayApplication and database hostingUSA
Plausible AnalyticsAnonymous traffic stats (no cookies, no IPs)Germany (EU)

6. Transfers outside the EU

Some processors (Google, Railway) are based in the USA. Transfers of your data are protected by Standard Contractual Clauses (SCCs) under Art. 46 GDPR and by the EU-US Data Privacy Framework decision where applicable. Brevo and Plausible are in the EU — no extra-EU transfer occurs there.

7. Your rights

Under GDPR you have the following rights:

To exercise your rights, write to tomas.strida@gmail.com. You will receive a response within 30 days.

8. Message recipients (people without an account)

When a user sends you a thank-you message, we process your email address. You are a data subject with the same GDPR rights as registered users.

9. Cookies

Short answer: we do not use tracking cookies, so you don't need any cookie banner.

We use a single cookie:

Third parties:

10. Security

In case of a data breach, we notify affected users and the Czech Personal Data Protection Office within 72 hours per Art. 33 GDPR.

11. Children

The Service is not intended for persons under 16. If we learn we hold data from a younger person without parental consent, we delete it immediately.

12. California residents (CCPA / CPRA)

If you are a California resident, under CCPA you have the right to:

We do not sell or share personal information for targeted advertising. We therefore do not display a "Do Not Sell or Share My Personal Information" link — there is nothing to opt out of.

13. Changes to this policy

We may update this policy from time to time. We notify you of material changes by email and show a dialog on your next sign-in with the new version. Minor edits (typos, grammar) are made without notice.

Version 1.0 · April 26, 2026 · Terms of Service