Frühbucher-Angebot: Themia Pro $24 $19

Privacy and data handling

What Themia stores on your device, what leaves it, and what we can and cannot see.

Diese Seite ist noch nicht übersetzt und wird auf Englisch angezeigt.

Themia is a desktop app. Almost everything it shows you is read on your machine and stays there. This page is the detailed version of that claim: what is stored, what leaves the device, who receives it, and what we are able to see.

What we hold no copy of

There is no Themia account, no Themia server holding your content, and no sync service.

  • Widget settings, layouts, screens — a JSON file per subsystem under %APPDATA%\com.themia.desktop\.
  • Widget content you type — notes, habit and mood entries, countdowns, clipboard history. Same directory, same machine.
  • Files and folders shown by the Folder widget — read from disk on demand, never copied or uploaded.

Uninstalling or deleting that directory removes the lot. We cannot delete it for you, because we never had it.

Accounts you connect

The Email, Calendar, Contacts, OneDrive, GitHub and similar widgets talk directly from your machine to the provider (Microsoft Graph, Google, an IMAP/CalDAV server, GitHub). Nothing is proxied through us and no message, event or contact ever reaches our infrastructure.

Credentials and OAuth tokens are stored locally and encrypted at rest with Windows DPAPI — per-user and machine-bound, so the file is unreadable by another Windows account and unreadable if copied to another machine.

What actually leaves the device

WhatWhere it goesContains
Update checkGitHub ReleasesA standard HTTPS request; GitHub sees your IP
Licence activationLemonSqueezyYour licence key
Usage analytics (optional)TelemetryDeckSee below
Provider trafficThe provider you connectedYour account data, direct

Usage analytics

Off until you say otherwise. Themia asks once, the first time it runs, and sends nothing before you answer — not even the install ID below, which is only created if you agree. Ignoring the question counts as a no for as long as it goes unanswered. You can change your mind either way in Settings → General → Data → “Share anonymous usage data”; it takes effect immediately.

If you do agree, this is sent, at most once a day plus one signal per app launch:

  • A random install ID — a UUID generated on first run, of which only the SHA-256 hash ever leaves the machine. It is not derived from any hardware or account identifier, so it identifies an install, not a person or a device.
  • App version, Windows version, architecture, device brand/model, screen resolution, language, region, timezone, colour scheme.
  • How often the app is used: session count, distinct days used, session lengths.
  • Error sources (the subsystem that failed), navigation between app screens, and a licence-activation event carrying the tier.

Never sent: email addresses, account names, licence keys, file paths, window or widget contents, view or monitor names, error message text, or the raw install UUID.

The receiving service is TelemetryDeck, an EU (German) analytics provider that hashes the identifier a second time server-side.

Website

The site runs Vercel Web Analytics and Speed Insights, and nothing else. No Google Analytics, no Google Ads, no advertising tags, no tracking cookies — a test in the site’s own build fails if one is reintroduced.

Asking us about your data

Write to themia@nathaniel-walser.com and we will tell you what exists and remove what we can. Realistically, the answer for most requests is that the only records tied to you are your licence purchase (held by LemonSqueezy as the merchant of record) and an anonymous analytics install ID that we cannot connect back to you — which is why the fastest way to stop analytics is the switch in Settings rather than a request to us.

Certifications

We hold none, and we make no compliance claims.

  • HIPAA — Themia is not a healthcare product, we sign no Business Associate Agreement, and Themia should not be used to store or transmit protected health information. (HIPAA has no certification scheme; any vendor claiming to be “HIPAA certified” is describing something that does not exist.)
  • GDPR — no formal Article 42 certification exists that we could hold. What we can say is factual, and the privacy policy says it in full: your content stays on your device, connected-account traffic never passes through us, analytics are anonymous and asked for rather than assumed, and the analytics processor is EU-based.

If you need contractual assurances for a procurement process, email us and say what your organisation requires rather than relying on this page.