Privacy Policy
Last updated: September 10, 2026
Who is responsible
The controller for the processing described here is:
- Nathaniel Walser, Switzerland
- Email: themia@nathaniel-walser.com
Themia is a desktop widget application for Windows, developed and operated as a one-person business. There is no data protection officer: the scale of processing described below does not require one, and the controller answers privacy requests personally.
The short version
Themia runs on your computer. Your widget settings, notes, layouts, files and connected-account data stay on that machine — they are never uploaded to us, and we hold no copy of them. What does leave your device is listed below, in full.
What stays on your device
Stored under %APPDATA%\com.themia.desktop\ on your own machine, and never transmitted to us:
- Widget settings, screens and layouts
- Content you type into widgets: notes, habit and mood entries, countdowns, clipboard history
- Files and folders shown by the Folder widget, read from disk on demand
- Credentials and OAuth tokens for accounts you connect, encrypted at rest with Windows DPAPI (per-user and machine-bound)
Deleting that folder, or uninstalling Themia, removes all of it. We cannot delete it for you, because we never had it.
Accounts you connect
The Email, Calendar, Contacts, OneDrive, GitHub and comparable widgets talk directly from your machine to the provider you chose (Microsoft Graph, Google, an IMAP/CalDAV server, GitHub). Nothing is proxied through us. We are not a recipient of your messages, events, contacts or files, and we cannot read them.
Your relationship with those providers is governed by their own privacy policies, not this one.
What we process, and why
Anonymous usage analytics (app)
- What: a random install identifier (a UUID generated on your machine, of which only a SHA-256 hash is transmitted), app version, Windows version, architecture, device brand and model, screen resolution, language, region, time zone, colour scheme, session counts and lengths, the subsystem name of any error, and movement between app screens.
- Never: email addresses, account names, licence keys, file paths, window or widget contents, view or monitor names, error message text, or the raw install UUID.
- Legal basis: your consent (Art. 6(1)(a) GDPR), asked for when Themia first runs. Analytics are off until you agree, and nothing is even stored on your device for this purpose before then.
- Withdrawing: Settings → General → Data → "Share anonymous usage data". It takes effect immediately and applies going forward.
- Recipient: TelemetryDeck GmbH (Germany), acting as our processor.
Website analytics
- What: pages viewed, the site that referred you, any campaign parameters in the link you followed, plus a small number of specific actions: clicking a download or purchase button, the download and newsletter prompts appearing or being dismissed, and subscribing to the newsletter. Also the country, region and city your IP address resolves to, device type, operating system and browser, and page-performance measurements. No cross-site tracking and no advertising tags. We do not use Google Analytics or Google Ads.
- What is stored on your device: nothing. Our website analytics sets no cookie, no session storage entry and no local storage entry. So that several pages read in one sitting count as one visit rather than several, Vercel derives a short-lived identifier from the incoming request on its own servers and discards it after 24 hours; it is never written to your device, we never see it, and it cannot recognise you on another site or on a later day. We set no advertising or cross-site identifiers of any kind, and we do not fingerprint your browser or hardware.
- Legal basis: our legitimate interest in understanding which pages are useful and which buttons people actually press (Art. 6(1)(f) GDPR). Nothing is read from or written to your device, and the identifier behind the visit count is held by our processor for a day and cannot be used anywhere else, so none of this can be assembled into a profile of you.
- Recipient: Vercel Inc. (USA), acting as our processor. It hosts the site, measures it, and records the page-performance numbers. Nothing goes to a separate analytics company.
Buying a licence
- What: your email address, payment and billing details, country, and the licence key issued to you.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and, for invoices and tax records, a legal obligation (Art. 6(1)(c) GDPR).
- Recipient: Lemon Squeezy LLC (USA) is the merchant of record: it takes the payment, issues the invoice and handles tax, and is an independent controller for that. We never see your card details.
- The app validates your licence key against Lemon Squeezy when you activate it.
Update checks
- What: Themia periodically asks GitHub whether a newer release exists. That HTTPS request necessarily reveals your IP address to GitHub, which may appear in its server logs.
- Legal basis: our legitimate interest in shipping security and bug fixes to installed copies (Art. 6(1)(f) GDPR).
- Recipient: GitHub, Inc. (USA), as an independent controller for its own logs.
Newsletter
- What: the email address you enter, and whether our mails were delivered.
- Legal basis: your consent (Art. 6(1)(a) GDPR), given by submitting the form. Every mail carries an unsubscribe link, and unsubscribing withdraws that consent.
- Recipient: Lemon Squeezy LLC (USA), acting as our processor.
Support and other email
- What: whatever you write to us, plus your address and the message metadata.
- Legal basis: answering a support request is either performance of the contract (Art. 6(1)(b) GDPR) or our legitimate interest in helping users (Art. 6(1)(f) GDPR).
- Recipient: Microsoft Corporation (USA / Microsoft Ireland), as our email provider.
Who receives data
The full list. We do not sell personal data, and we do not share it for advertising.
- TelemetryDeck GmbH — Germany — app analytics (processor)
- Vercel Inc. — USA — website hosting, website analytics and page-performance measurement (processor)
- Lemon Squeezy LLC — USA — payments, licensing, newsletter (merchant of record; processor for the newsletter)
- GitHub, Inc. — USA — release downloads and update checks
- Microsoft Corporation — USA / Ireland — our support mailbox
We may also disclose data where the law requires it.
Transfers outside the EEA
We are based in Switzerland, which the European Commission recognises as providing an adequate level of protection. The US-based providers listed above are engaged under the European Commission's Standard Contractual Clauses and, where the provider participates, the EU–US Data Privacy Framework. App analytics data stays in the EU: TelemetryDeck processes it in Germany.
How long we keep things
- App analytics: retained by TelemetryDeck for as long as the product is measured; the data identifies an installation, not a person, and cannot be traced back to you by us.
- Website analytics: kept by Vercel and visible to us for up to 12 months. Nothing at all is kept in your browser.
- Purchase and licence records: kept for as long as the licence is valid, and for the retention period tax law imposes on the merchant of record (generally 10 years).
- Newsletter: until you unsubscribe.
- Support email: up to 24 months after the conversation ends.
Your rights
If the GDPR applies to you, you have the right to request access to your personal data, to have it corrected or erased, to have processing restricted, to receive it in a portable format, and to object to processing based on our legitimate interests. Where processing rests on consent, you may withdraw that consent at any time without affecting what was lawful before.
Write to themia@nathaniel-walser.com and we will answer within one month. In practice the only records tied to you are your purchase (held by the merchant of record) and, if you subscribed, your newsletter entry — app analytics carry no identifier we can link back to you, which is also why the fastest way to stop them is the switch in Settings rather than a request to us.
You also have the right to lodge a complaint with a supervisory authority: in the EEA, the data protection authority of your country of residence; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
Swiss law
Because we are established in Switzerland, the Swiss Federal Act on Data Protection (FADP) applies to this processing alongside the GDPR. The rights described above — access, correction, deletion, objection — exist under the FADP too, and the same contact address serves both.
Security
Everything Themia sends travels over TLS. Credentials and OAuth tokens are encrypted at rest on your machine with Windows DPAPI, so the stored file cannot be read by another Windows account or on another computer. Widgets are blocked from reaching private, loopback and local-network addresses unless you deliberately enable it, which limits what a malicious feed or server can reach.
Children
Themia is not directed at children under 16, and we do not knowingly collect their personal data.
Changes to this policy
We update this page when the processing changes, and the revision date above always reflects the current version. Material changes to anything that relies on your consent will be asked for again rather than announced quietly.
Contact
Questions about this policy, or a request about your data: themia@nathaniel-walser.com.