PRIVACY POLICY
Thinned — Miniature Painting Journal
Effective date: 30 June 2026
This Privacy Policy explains how we handle your personal data when you use Thinned, a journal app for tabletop miniature painters, available on iOS, Android and macOS.
We have written this in plain English. It is not legal advice — it is a transparency notice about what we do with your data.
The short version (for everyone, including younger users): Thinned is a place to keep your miniature-painting journal. We ask for your email so you can have an account, and we store the things you make in the app. We
don't show ads, we
don't track you across other apps, and we
don't sell your information. Your projects, photos and notes are private to you unless you choose to share a recipe. You can delete your account and everything in it at any time from Settings. If anything here doesn't make sense, ask a parent or carer — or email us at
support@thinned.app.
1. Who we are (the data controller)
The controller responsible for your personal data is:
Yggdrasil Ventures Limited (United Kingdom), the developer and operator of Thinned.
Yggdrasil Ventures Limited
124 City Road
London EC1V 2NX
United Kingdom
Contact: support@thinned.app
We are a UK-established business, so we do not require a UK representative. We are not required to appoint a Data Protection Officer, and we have not done so, because the legal triggers for a mandatory DPO do not apply to our processing.
2. The personal data we collect, why, and our lawful basis
We collect personal data directly from you when you create an account, use the app, make a purchase, or contact us. We do not buy data about you or collect it from third parties (other than the sign-in providers you choose to use — see Section 3).
Under UK GDPR we must have a "lawful basis" for each use of your data. Here is exactly what we process and why:
Account and authentication
- What: your email address (required) and, if you choose it, a username. You can sign in with email and password, Sign in with Apple, or Sign in with Google.
- Why: to create and secure your account and let you log in.
- Lawful basis: Contract (UK GDPR Art 6(1)(b)) — we need this to provide the service you have signed up for.
Providing an email address is necessary to create an account; without it we cannot provide the service. All other fields are optional.
Your profile (all optional, empty by default)
- What: username, a bio (up to 1,000 characters), a free-text "location" field (up to 200 characters — this is text you type, not your device location or GPS), and an avatar image.
- Why: to let you personalise your profile if you wish.
- Lawful basis: Contract (Art 6(1)(b)).
Note on the "location" field: it is plain text you optionally type (for example, a city name). We do not collect device location or GPS data. We have flagged this field for removal as it is not needed.
Your content
- What: projects, painting sessions (including notes, durations and timeline notes), recipes (steps and notes), custom paints, paint inventory (ratings and comments), and any recipes you choose to share publicly via a 6-character share code.
- Why: to store and display the content you create in the app, and (for shared recipes) to make a recipe viewable by anyone with the share code, because you chose to share it.
- Lawful basis: Contract (Art 6(1)(b)). For publicly shared recipes, this is also carried out on the basis of your own act of choosing to share them.
Images
- What: avatar images, and project / session / recipe images.
- Where stored: all of your images — your avatar and your project, session and recipe images — are stored in private storage buckets, accessible only to you as the owner. (Avatar upload is not available in this version.)
- Why: to store and display the images you add.
- Lawful basis: Contract (Art 6(1)(b)).
Pro purchase and entitlement
- What: your Pro entitlement status, processed through our payments processor RevenueCat. We also keep a minimal server-side webhook audit log containing only an event id, event type, timestamp, product and entitlement. We deliberately do not retain names, emails, transaction ids, prices or country in this log.
- Why: to deliver the one-time Pro purchase (a single GBP 8.99 in-app purchase) and unlock the corresponding features; and to keep the records we are legally required to keep.
- Lawful basis: Contract (Art 6(1)(b)) to provide Pro; and Legal obligation (Art 6(1)(c)) to keep transaction and tax records.
Feedback and bug reports
- What: free-text messages (up to 2,000 characters), which may optionally be linked to your account.
- Why: so we can respond to you and improve the app.
- Lawful basis: Legitimate interests (Art 6(1)(f)). Our specific legitimate interest is responding to your feedback and improving our product. We have balanced this against your rights and consider the impact minimal.
Crash and error diagnostics
- What: technical crash and error reports, sent via Sentry. We scrub personal data before it is sent — emails, tokens and JWTs are redacted, and personal-data capture is off by default. An opaque user id may be attached purely to group related errors.
- Why: to keep the app stable and secure and to diagnose faults.
- Lawful basis: Legitimate interests (Art 6(1)(f)). Our specific legitimate interest is maintaining the stability and security of the app. We have completed a legitimate interests assessment, and the data is minimised and scrubbed to protect you.
We do not process any special-category data (such as health data). Photos in the app are of miniatures and painting work and may only incidentally include a person; we do not use them to identify anyone.
3. Who we share your data with (recipients and processors)
We do not sell your data. We use a small number of trusted service providers ("processors") who handle data on our behalf and under contract. We share only what each provider needs:
| Provider |
Role |
What it receives |
| Supabase |
Database, authentication, file storage and server functions |
Your account data, content, images and authentication data — i.e. the data needed to run the app. |
| RevenueCat |
In-app purchase and entitlement management |
Purchase / entitlement data needed to deliver and verify your Pro purchase. |
| Sentry |
Crash and error monitoring |
Scrubbed technical diagnostics (with an opaque user id for grouping). No emails, tokens or JWTs. |
| Apple |
Identity provider for Sign in with Apple |
If you use it, Apple provides your email/name to authenticate you. |
| Google |
Identity provider for Sign in with Google |
If you use it, Google provides your email/name to authenticate you. |
Apple and Google act here as the sign-in providers you choose to use to authenticate.
In addition to the processors above, one category of data is made public by your own choice: any recipe you choose to share, which becomes viewable by anyone holding its 6-character share code. Everything else — including your images — stays private to your account.
Each of our processors operates under a data processing agreement:
4. International data transfers
Some of our providers are located outside the UK. Here is where your data goes and how it is protected in each case:
- Supabase (hosting) — Zurich, Switzerland. Switzerland benefits from both UK and EU adequacy decisions. This means it is not a restricted transfer and no additional safeguards (such as Standard Contractual Clauses) are required.
- Sentry — EU (Frankfurt, Germany). Your diagnostic data stays within the EU. This is not a restricted transfer.
- RevenueCat — United States. RevenueCat is not certified under the EU-US / UK Data Privacy Framework. Transfers to RevenueCat are therefore protected by Standard Contractual Clauses together with the UK International Data Transfer Addendum (IDTA), and we hold a Transfer Risk Assessment (TRA) supporting the transfer. You can request a copy of the safeguards we rely on for this transfer by contacting us at support@thinned.app.
Where you choose Sign in with Apple or Sign in with Google, Apple or Google processes your email and name to authenticate you under their own terms as independent providers (a global/US-based flow). This is not a transfer made by us as controller, but we note it here for completeness.
5. How long we keep your data (retention)
| Data |
Retention |
| Your account and all your content |
Kept until you delete your account, then erased immediately. |
| Webhook purchase-audit log (minimal) |
Deleted with your account; otherwise retained for 90 days. |
| Feedback and bug reports |
Deleted with your account; otherwise retained for 24 months. |
| Records we must keep by law (e.g. tax/transaction records) |
Retained for the period required by law (typically 6 years). |
| Sentry diagnostic events |
30 days. |
| Authentication / session tokens |
Held on your device until you log out. |
Account deletion is complete. When you delete your account in the app, we remove all your database records (via cascading deletion), all four storage buckets, your RevenueCat subscriber record, and we revoke the Sign in with Apple grant.
6. Your rights
Under UK data protection law you have the following rights over your personal data:
- Access — ask for a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data. (You can edit most of this yourself in the app.)
- Erasure — delete your account and data. You can do this yourself at any time using in-app account deletion.
- Restriction — ask us to limit how we use your data.
- Data portability — receive the data you provided in a portable form. You can use the in-app ZIP backup / export, or ask us for a manual export.
- Objection — object, on grounds relating to your particular situation, to processing we carry out on the basis of legitimate interests (feedback handling and crash diagnostics).
Because none of our processing relies on consent, there is no consent for you to withdraw.
How to exercise your rights: use the in-app tools where available, or contact us at support@thinned.app.
We will respond within one calendar month. For complex or numerous requests we may extend this, and we will tell you if we do. Where we need to confirm your identity or seek clarification about a request, the law (including the Data (Use and Access) Act 2025) allows us to pause the response clock until you provide what we have asked for.
Complaints: if you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.
7. Automated decision-making and profiling
We do not carry out any automated decision-making that produces legal or similarly significant effects, and we do not profile you.
8. Children's data
Thinned is not directed at children, but we recognise it may be accessed by under-18s. We therefore apply child-appropriate protections to all users — the simplest way to comply with the UK Age Appropriate Design Code (the Children's Code).
In practice this means:
- profiles default to private;
- all optional fields are empty by default and clearly marked optional;
- we do no profiling and no behavioural advertising;
- we collect no device-location data (the "location" field is free text, and is flagged for removal as surplus); and
- we collect no age data.
We treat children's protection as a "higher protection matter" in line with our data-protection-by-design obligations. Because our processing relies on contract and legitimate interests rather than consent, parental-consent mechanisms are not triggered.
9. No selling, no tracking, no analytics
To be completely clear:
- We do not sell or share your personal information.
- We do not use your data for cross-app, cross-site or advertising tracking.
- We use no analytics, attribution or tracking SDKs.
- There is no advertising identifier (IDFA), no App Tracking Transparency prompt, and no behavioural profiling.
For users in the United States: we do not "sell" or "share" personal information as those terms are used under US state privacy laws, and we believe we fall outside the scope of laws such as the CCPA/CPRA.
10. Storage on your device
Some data is stored only on your device and is never transmitted to us, including:
- a local database of your projects, sessions and recipes;
- app settings and a cached entitlement (Pro) flag; and
- your authentication / session tokens, held securely in the operating system's Keychain (iOS/macOS) or Keystore (Android) until you log out.
This device-local storage and these tokens are strictly necessary to provide the app you have asked for. Under the Privacy and Electronic Communications Regulations (PECR), strictly necessary storage of this kind does not require a cookie banner or consent prompt — we disclose it here purely for transparency.
11. Security
We take the security of your data seriously. Our measures include:
- Row-Level Security on every database table, so users cannot access each other's data;
- private storage buckets scoped to the owner;
- privileged keys and secrets used only server-side, never inside the app;
- encryption in transit (TLS);
- PII scrubbing in our crash diagnostics;
- rate limiting on public endpoints; and
- complete in-app account deletion.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you in the app. Please check this page periodically.
Last updated: 30 June 2026