ThoughtFerry: Quick Capture Privacy Policy
Last Updated: September 27, 2026
Quick Summary
ThoughtFerry is a local-first Android quick-capture and routing app. Captures stay on the device unless you explicitly export them or route them to a destination you choose. The app uses Google Play Billing and a Quazmoz-controlled verifier for optional Lifetime Pro, and it includes RevenueCat, Google Mobile Ads, and Google UMP only for an optional rewarded path to temporary Pro. Core capture never requires an ad or a ThoughtFerry account.
App-Specific Details
Specific data handling practices for ThoughtFerry: Quick Capture.
- Stores captures, staged attachments, route configuration, delivery state, preferences, and bounded entitlement state locally on the Android device.
- Google Tasks is optional and user-authorized. ThoughtFerry uses Google Identity and the Google Tasks API directly; captured text or URLs are sent to Google only when you deliberately route a capture to Tasks.
- HTTPS webhooks are sent directly from the device to the endpoint you configured. Sensitive endpoint and header values are protected with Android Keystore-backed storage and excluded from normal diagnostics and route exports.
- Google Play handles the optional one-time Lifetime Pro purchase. ThoughtFerry sends the Play purchase token and product ID to a Quazmoz-controlled Supabase verifier; capture content is never sent to that verifier.
- The optional rewarded-Pro flow uses Google Mobile Ads, Google UMP, and RevenueCat for consent, ad delivery, server-side reward verification, and temporary entitlement state. Capture content is not sent to those services for the rewarded feature.
- Voice input uses the Android speech-recognition activity you explicitly launch. ThoughtFerry does not request RECORD_AUDIO or retain raw audio; the configured recognizer may process audio under its own privacy practices and returns recognized text to the app.
- Export is user-initiated and writes a Markdown file to a location you choose. ThoughtFerry does not upload exports in the background.
- ThoughtFerry does not include unrelated product analytics, a crash-reporting upload SDK, custom capture cloud sync, or a ThoughtFerry account.
Detailed Official Policy
Full technical and legal disclosure for ThoughtFerry: Quick Capture.
ThoughtFerry Privacy Policy
Last updated: September 27, 2026
Canonical published location: <https://consultant.quinnfavo.com/privacy/thoughtferry>
Publication gate: republish this exact policy at the canonical URL before submitting the 0.2.3 release candidate, then verify the public page matches this source. Publication evidence for an earlier source snapshot does not qualify a later release candidate.
This document is the source of truth for the page published at that URL. The URL is also what the app links to from Settings → Privacy policy, and what must be entered as the privacy-policy URL in the Play Console listing. Keep all three in step: publish this text at that URL before release, and re-publish whenever this file changes.
ThoughtFerry is a local-first Android capture and routing utility developed by Quazmoz. This policy describes the behavior of the current application, its production entitlement-verification service, and the optional rewarded-ad path used only from the Pro screen.
Summary
ThoughtFerry is designed so that capture content stays local unless you deliberately route it to a destination you selected.
ThoughtFerry does not include unrelated product analytics, crash-reporting, or cloud-sync SDKs and it does not create or require a ThoughtFerry account. It now includes RevenueCat, Google Mobile Ads, and Google's User Messaging Platform (UMP) solely to offer an optional rewarded path to temporary Pro. A rewarded ad is never required to capture, read, recover, export, or delete your content, and ThoughtFerry does not load or show rewarded advertising because you captured something or because a delivery/recovery operation failed. The ad flow can be initiated only from the Pro/upgrade screen.
ThoughtFerry uses Google Play Billing for the optional lifetime Pro purchase. When a purchased entitlement is reconciled, the app sends the Google Play purchase token and expected ThoughtFerry product ID to a Quazmoz-controlled verification service hosted on Supabase. That billing service verifies the purchase with Google Play and may acknowledge an eligible purchase. It is separate from capture routing: capture text, URLs, attachments, webhook secrets, Google Tasks account details, and document contents are not sent to the billing-verification service.
ThoughtFerry can also connect to Google Tasks when you explicitly choose a Google account and task list. For that feature, ThoughtFerry requests `https://www.googleapis.com/auth/tasks` for Google Tasks operations and `https://www.googleapis.com/auth/userinfo.email` only to resolve the verified primary Google Account email used to bind the destination to the exact account you selected. ThoughtFerry sends the text/URL content you deliberately route as a task directly to the Google Tasks API. This Google Tasks traffic does not pass through Quazmoz infrastructure.
Data stored on your device
ThoughtFerry may store locally:
- text and URLs you enter, share, or add from a returned speech-recognition transcript;
- app-private attachment bytes, or a verified persisted Android document URI permission for an attachment you deliberately select;
- local capture, delivery request, and delivery-attempt status/history;
- user-created route configuration such as a selected Markdown document tree, a selected Google Tasks task-list identifier/title, and opaque/versioned references to secret-backed destination configuration;
- encrypted webhook endpoint values, encrypted webhook header values, and the selected Google Tasks account name in Android Keystore-backed secret storage;
- delivered-content retention preferences;
- durable draft state needed to recover meaningful in-progress capture text and attachment ownership;
- app-private Sharesheet handoffs until the normal draft store safely adopts them;
- a bounded local Lifetime Pro entitlement cache containing verification state, product ID, and last verification time.
The Lifetime Pro cache does not intentionally store the raw Google Play purchase token. Google Tasks access tokens are used to authorize Google API requests and are not intentionally persisted by ThoughtFerry's route configuration or local delivery history.
ThoughtFerry does not persist its own rewarded-ad grant or locally authoritative eight-hour reward timer. Temporary Pro is accepted only after RevenueCat reports a currently active entitlement or its AdMob server-side verification flow returns a verified entitlement and server-provided expiration. RevenueCat and Google SDKs may maintain their own SDK caches, pseudonymous installation/user identifiers, consent state, advertising-related identifiers where permitted, and operational state under their respective SDK behavior and privacy terms.
Voice input and speech recognition
Voice input is optional and starts only after you deliberately tap Voice input in the Capture composer.
ThoughtFerry launches Android's configured speech-recognition activity and requests a free-form recognition result. Under the current implementation:
- ThoughtFerry does not request Android microphone permission;
- ThoughtFerry does not instantiate a microphone recorder or `SpeechRecognizer` service directly;
- ThoughtFerry does not receive, retain, upload, log, or back up raw microphone audio through this voice-input path;
- the configured Android speech-recognition app/service owns microphone capture and its own permission, network, and processing behavior;
- Android documentation warns that implementations of the standard recognition activity may stream audio to remote servers, so ThoughtFerry does not claim recognition is offline or that spoken audio remains on-device;
- the recognition provider may process spoken audio and related operational data under that provider's own settings, terms, and privacy practices;
- ThoughtFerry receives the returned recognized text, appends it to the existing local draft without silently overwriting existing content, and lets you edit it before saving or routing.
A returned voice transcript is treated like text you typed into the composer. Voice recognition alone does not create a durable capture, choose a destination, trigger a Google Tasks/webhook/document operation, or unlock Pro. Content can leave ThoughtFerry only later through the same explicit capture/routing behavior described elsewhere in this policy.
If the recognizer is unavailable, is cancelled, returns no usable text, or cannot complete, ThoughtFerry leaves the existing draft unchanged. ThoughtFerry does not add a third-party speech SDK or an always-listening/background microphone feature.
Google Play Billing and Lifetime Pro verification
ThoughtFerry offers an optional one-time Pro product through Google Play:
- product: `thoughtferry_pro_lifetime`;
- purchase option: `lifetime`.
Google Play handles the payment transaction and payment credentials under Google's terms. ThoughtFerry does not receive your credit-card or bank-account number from Google Play.
When ThoughtFerry discovers a purchased Pro entitlement, it sends over HTTPS to the configured ThoughtFerry verification service:
- the Google Play purchase token;
- the expected ThoughtFerry product ID.
The verification service uses Google Play's Android Publisher API to confirm that the token belongs to the ThoughtFerry package, represents the expected lifetime product/option, is in a purchased and entitling state, and is acknowledged. If an eligible purchase has not yet been acknowledged, the service may acknowledge it through Google Play before returning success.
This processing is used only for purchase verification, fraud/abuse resistance, entitlement restoration/reconciliation, and providing Pro functionality. The current verification function does not intentionally write raw purchase tokens to a ThoughtFerry database or emit them to application logs.
Supabase hosts the Edge Function infrastructure used by Quazmoz for this verification service, and Google processes purchase verification/acknowledgement through the Google Play Developer APIs. Those service providers may process operational metadata under their own service terms and privacy/security practices.
ThoughtFerry may allow a recently server-verified Lifetime Pro entitlement to remain usable for a bounded offline grace period when Google Play or the verification service is temporarily unavailable. A successful online ownership reconciliation can revoke the local entitlement when the purchase is no longer owned. RevenueCat is not required to recognize or migrate a Lifetime purchase for that purchase to remain Pro; Google Play ownership and ThoughtFerry's existing Lifetime verification path remain independent authority. The Android RevenueCat SDK is configured with `PurchasesAreCompletedBy.MY_APP` and automatic Google Play billing messages disabled so RevenueCat does not acknowledge, complete, or recover ThoughtFerry's Lifetime purchase.
Optional rewarded advertising and temporary Pro
The Pro screen can optionally offer Watch rewarded ad · 8 hours Pro. ThoughtFerry uses:
- Google Mobile Ads to request and display the rewarded ad;
- Google's User Messaging Platform (UMP) to obtain/update advertising consent information and expose privacy choices where required;
- RevenueCat's supported AdMob reward-verification integration to verify the reward server-side and represent temporary Pro as a RevenueCat entitlement.
ThoughtFerry does not grant temporary Pro from AdMob's local `onUserEarnedReward` callback and does not create a local eight-hour entitlement. The RevenueCat project must be configured so the verified temporary entitlement is `thoughtferry_pro_rewarded` and expires after eight hours. The Android app treats the expiration returned by RevenueCat only as an upper bound that can revoke access; it cannot locally create, extend, or renew the entitlement.
The rewarded flow is optional. No banner ads, interstitial ads, rewarded interstitials, or app-open ads are intentionally used. ThoughtFerry does not automatically load/show an ad during capture, Sharesheet intake, Local Inbox access, recovery, export, a WorkManager failure, a route failure, or a delivery-error flow.
When the optional ad flow is used, Google/AdMob/UMP and RevenueCat may process advertising, consent, device/app, IP/network, pseudonymous identifier, ad interaction, and reward-verification/operational data as supported by their SDKs and your consent/settings. Exact behavior can vary by region, consent state, device, Google Play services configuration, and SDK/service configuration. ThoughtFerry does not send capture text, route bodies, webhook secrets, Google Tasks task content, attachments, or local Inbox contents to AdMob or RevenueCat for the rewarded feature.
A Lifetime owner normally does not receive the rewarded CTA. Lifetime ownership cannot be revoked by RevenueCat, AdMob, UMP, temporary entitlement expiry, or temporary reward-verification failure.
Capture content and Sharesheet privacy
Capture content is local-first. It is not sent to the ThoughtFerry billing-verification service, RevenueCat, or AdMob as part of entitlement/reward processing.
When another app shares content to ThoughtFerry:
- the Sharesheet receiver validates the share;
- accepted attachment bytes are copied into ThoughtFerry-owned private staging before the handoff is issued;
- the share payload is stored in app-private handoff storage;
- the launcher receives only a random handoff token, not raw shared text or app-private attachment paths/URIs;
- existing/restoring composer content wins over a newer incoming share;
- the normal draft store adopts the shared content before the handoff is removed.
The exported Sharesheet boundary treats external Android `ContentProvider` implementations as untrusted. Runtime failures from provider metadata/file callbacks are contained and converted to a safe unreadable/rejected share result rather than being allowed to escape as a process crash.
Never-presented abandoned handoffs may be cleaned after 24 hours. Presented/pending-adoption content is retained until safe adoption/acknowledgement or app-data removal. Sharesheet admission uses bounded count/text limits and does not evict existing unresolved content to admit a newer share.
Sharesheet handoff storage is excluded from Android cloud backup/device transfer.
Data transmitted to destinations you choose
Content leaves ThoughtFerry's local capture store only when you configure/select a destination requiring an external operation and use the normal capture action.
If temporary Pro expires while a webhook or Google Tasks delivery is queued, ThoughtFerry preserves the capture and immutable destination snapshot locally and stops a new paid connector attempt before secrets/network/OAuth execution. The request is recorded as requiring action rather than being falsely marked delivered or silently redirected. Regaining Pro and explicitly retrying can resume the preserved destination. An already-admitted connector attempt that has crossed the durable entitlement boundary may finish and record its truthful outcome; later retries check entitlement again.
Markdown/document provider
ThoughtFerry can write captured content to an Android Storage Access Framework document tree that you select. The Android/document provider you choose may independently sync or process those files according to that provider's settings and privacy terms.
Google Tasks
ThoughtFerry can create a task in a Google Tasks list that you explicitly connect and select. To configure and use this destination, ThoughtFerry uses Google Identity Services to request `https://www.googleapis.com/auth/tasks` for the Google Tasks operations and `https://www.googleapis.com/auth/userinfo.email` only to obtain the verified primary Google Account email needed to bind the destination to the exact account you selected.
For a Google Tasks delivery, ThoughtFerry may send directly to Google services:
- the verified primary Google Account email to Google's UserInfo endpoint during authorization so ThoughtFerry can confirm exact-account identity;
- captured text or URL content, mapped to a Google Task title and, for multi-line content, optional notes;
- the selected Google Tasks list identifier as part of the Tasks API request path;
- an OAuth access token supplied through Google's authorization flow in the HTTP `Authorization` header.
ThoughtFerry also reads the available task-list identifiers/titles from Google Tasks while you configure the route. The selected Google account name is stored locally through Android Keystore-backed secret storage; normal route JSON stores only an opaque/versioned reference to that account name plus the selected task-list identifier/title. ThoughtFerry does not intentionally persist Google Tasks access tokens in its route configuration or delivery history.
Current Google Tasks routing supports text and URL content and does not upload attachments. Google processes Google Tasks account, task, authorization, and API data under Google's applicable terms and privacy practices. Removing a ThoughtFerry route or deleting a local capture does not delete a task that was already created in Google Tasks.
HTTPS webhook
ThoughtFerry can send captured text or URLs to an HTTPS webhook endpoint that you configure and select as the destination. A webhook request may include:
- captured text/URL content;
- capture source/type metadata;
- capture time;
- a random logical delivery identifier used for delivery identity/idempotency;
- local route identity/display metadata;
- user-configured request headers whose values are resolved at execution time from local Android Keystore-backed secret storage.
The webhook operator controls what happens to data after the request reaches that endpoint. ThoughtFerry does not route webhook content through Quazmoz infrastructure. The current webhook connector does not upload attachments.
Webhook endpoint and credential privacy
ThoughtFerry treats the complete user-configured webhook endpoint as sensitive because provider credentials can appear in URL path segments. The raw endpoint and all user-configured webhook header values are encrypted through the Android Keystore-backed secret store. Normal route configuration and immutable request snapshots contain only opaque/versioned references.
Current webhook endpoints must use HTTPS and cannot contain URL userinfo, query strings, or fragments. Raw endpoint/header values are intentionally excluded from normal Room route/request JSON, WorkManager input data, Android SavedState, safe diagnostic codes, backup, and route recipe exports.
Sharing with third parties
ThoughtFerry does not sell user data.
The app may transfer or cause user data to be processed in these circumstances:
- purchase verification data to the Quazmoz verification service/Supabase infrastructure and Google Play as described above;
- optional advertising/consent/reward-verification data to Google Mobile Ads, UMP, and RevenueCat when the rewarded feature is configured/used, as described above;
- capture content and Google account/task-list authorization data to Google when you explicitly connect and use a Google Tasks destination;
- capture content to a document provider or webhook operator only when you explicitly configure/select that destination and initiate or queue delivery;
- spoken audio to the Android speech-recognition provider selected/configured on your device when you deliberately launch Voice input. This audio is captured and processed by that recognizer rather than by ThoughtFerry's own code; the provider may process it online.
A transfer to a service provider acting for Quazmoz is handled according to that provider relationship. Google Play, Google Mobile Ads/UMP, RevenueCat, Google Tasks, a user-selected webhook/document provider, or a configured speech-recognition provider processes data under that provider's own applicable terms and privacy practices.
Permissions and storage access
ThoughtFerry uses Android-scoped APIs rather than broad filesystem access. It does not request `MANAGE_EXTERNAL_STORAGE` and does not use an Accessibility service.
ThoughtFerry does not declare `android.permission.RECORD_AUDIO` for its current Voice input implementation. The configured speech-recognition activity owns microphone access. A future design in which ThoughtFerry directly records or recognizes microphone audio would require a separate permission/privacy review.
The application requires normal Internet access for:
- Google Identity authorization and direct Google Tasks API access when you configure/use a Google Tasks destination;
- user-configured HTTPS webhook delivery;
- Google Play Billing communication contributed by the Billing integration;
- HTTPS purchase verification against the ThoughtFerry verification service;
- RevenueCat temporary-entitlement/reward verification and Google UMP consent-status requests when rewarded Pro is configured;
- Google Mobile Ads rewarded-ad requests only after you explicitly choose the rewarded option on the Pro screen and the applicable UMP state permits an ad request.
Google Mobile Ads may contribute Android advertising-related permissions through its manifest according to the SDK/version and platform behavior. The exact merged release manifest must be reviewed before Play submission and the Play Console Data Safety/ads declarations must match the final SDK behavior.
The app's `INTERNET` permission is not a claim that the configured speech recognizer is offline or online; the recognizer is a separate Android component/provider and may use its own network permissions and processing path.
Normal production network operations require TLS; application cleartext traffic is disabled.
Incoming Sharesheet attachments are accepted only through Android content-provider URIs and are copied into app-private staging before the private handoff is issued. Attachments deliberately selected through Android's document picker may retain a verified persisted URI grant when Android actually grants it and the content can be reopened; otherwise the bytes are copied into app-private storage.
Credentials and security
Webhook endpoint/header values and the selected Google Tasks account name are encrypted at rest with an AES-GCM key managed by Android Keystore. Queued requests preserve exact versioned secret references so changing a route does not silently redirect an already-queued delivery to unrelated credentials/account configuration.
Google Tasks authorization uses Google Identity Services with `https://www.googleapis.com/auth/tasks` for Tasks operations and `https://www.googleapis.com/auth/userinfo.email` for exact-account identity binding. Google Tasks API access tokens are obtained through that authorization flow and are not intentionally persisted in ThoughtFerry's normal route or delivery records.
Billing verification uses HTTPS and a server-side Google Play service account. Google Play service-account credentials are not embedded in the Android application. RevenueCat uses a public mobile SDK key injected at build time; production AdMob application/ad-unit identifiers are also injected at build time. These identifiers are not treated as server secrets. Server credentials used by RevenueCat, AdMob, or the existing billing verifier are not embedded in the app.
ThoughtFerry uses normal platform TLS trust. Production code must not bypass certificate validation.
No software can guarantee absolute security. ThoughtFerry's design prioritizes durable local capture, minimal permissions, bounded external inputs, and deliberate data movement.
Delivery retry behavior
ThoughtFerry may automatically retry only failures recorded as safe enough to retry with duplicate risk `NONE` or `LOW`, and automatic connector execution is capped. Ambiguous outcomes, possible/high duplicate risk, authentication/permission problems, permanent failures, Pro-required states, and exhausted budgets require user review instead of silent replay.
Route recipes
Route recipe export/import is bounded and preview-first. Current webhook recipes omit raw webhook endpoints, custom header values, device-specific secret identities/versions, and Android Storage Access Framework tree grants. Google Tasks routes require account authorization to be established on the receiving device rather than exporting reusable OAuth access credentials.
Exporting your captures
Settings → Export captures writes every capture ThoughtFerry holds to a Markdown file you choose through the Android document picker. This exists because ThoughtFerry excludes its own database, files, and preferences from Android backup and device transfer (see Backup below) and has no sync, so without an export there is no way to keep a copy of your captures off this device.
The export is a deliberate, user-initiated action to a location you pick. ThoughtFerry does not upload it, schedule it, or perform it in the background.
What the exported document contains:
- capture text, and the timestamp, state, source, and content type of each capture;
- the *name* of the destination a capture was routed to, or `Local Inbox`;
- for an attachment: its file name, MIME type, size, and staging state.
What the exported document deliberately omits:
- route configuration and secret references, including webhook endpoint/header material and Google Tasks account identity — route configuration has its own separate, secret-safe recipe export;
- attachment file locations, whether an app-private staging path or a persisted document URI;
- attachment bytes; the bulk Markdown document contains metadata only;
- capture, delivery-request, and delivery-attempt identifiers.
A delivered capture whose body has already been redacted by your retention setting exports as a note saying so, rather than as an empty capture.
Once the file is written, it is an ordinary document in the location you chose and is no longer governed by ThoughtFerry's storage rules.
For an individual readable attachment, Inbox → Local capture → Save copy lets you write its bytes to a document you choose. This is also deliberate and user-initiated. The original remains in ThoughtFerry. If a destination write fails, the selected copy may be incomplete.
Editing and routing a saved capture
A capture held in the Local Inbox that has never been queued for a destination can be edited, or sent to a destination after the fact. Both are local operations until you choose a destination; routing then follows exactly the same rules as routing from the composer, including the immutable configuration snapshot described under Data transmitted to destinations you choose.
A capture that has already been queued, delivered, or handed off cannot be edited or re-routed. The destination is the record of what was sent, and a local body that no longer matched it would misrepresent what happened.
Backup
The current version explicitly excludes sensitive capture databases, app-private staged attachments, drafts/preferences/DataStore files, Sharesheet handoffs, connector secret material, and ThoughtFerry's local Lifetime Pro entitlement state from unintended Android cloud backup and device-to-device transfer. ThoughtFerry does not intentionally persist its own rewarded grant; third-party SDK-managed state is governed by the final merged application/SDK backup behavior and must be re-audited when SDK versions change.
A future intentional encrypted backup/sync feature would require a separate design and privacy-policy update.
Retention and deletion
Draft, queued, delivering, failed, or needs-action captures are retained locally unless and until an explicit, delivery-safe deletion can complete. ThoughtFerry does not automatically sacrifice unresolved content merely to reclaim storage.
Delivered captures appear in local history. The default delivered-content policy is Keep forever. You may instead choose a 7-, 30-, or 90-day policy; under those policies only the local delivered capture's text/subject body is redacted after the selected age while delivery evidence remains.
Private staged files and persisted attachment grants are removed only when durable reference checks allow it. Never-presented abandoned Sharesheet handoffs may expire after 24 hours; presented pending-adoption shares are retained as unresolved local content.
Clearing ThoughtFerry app data removes local ThoughtFerry data, the local Lifetime Pro verification cache, and locally held SDK state. It does not cancel or delete the Lifetime purchase record managed by Google Play, nor does it delete data already delivered to Google Tasks, a selected document provider, or a webhook destination. A still-valid temporary RevenueCat entitlement may be recoverable when RevenueCat identifies/reconciles the installation again; ThoughtFerry itself does not maintain a hosted capture account for that purpose.
The billing verification service does not create a ThoughtFerry user account or hosted capture profile. The current function source does not intentionally persist raw purchase tokens in a ThoughtFerry database. Google Play, RevenueCat, Google Mobile Ads/UMP, Google Identity/Tasks, Supabase, configured speech-recognition providers, and user-selected destinations may retain records or operational data according to their respective service roles and policies.
Help, feedback, and sanitized diagnostics
ThoughtFerry includes a user-initiated Help & feedback surface. When you choose Copy diagnostics, ThoughtFerry generates a bounded sanitized technical bundle locally and places that bundle on the Android clipboard only after your deliberate copy action. The app does not automatically upload the bundle, and the bundle remains local until you choose to paste or submit it elsewhere.
The support bundle can include app/version metadata, Android API/device model metadata, a coarse connector type, delivery state, retry/duplicate-risk classification, a coarse provider-availability/result classification, attempt count, and a relevant completion timestamp. The current implementation intentionally omits capture/request/attempt identifiers from the copied bundle.
The support bundle is designed to exclude capture text, subject/body, voice transcript, Google account identity/email, OAuth/access tokens, Google Tasks content/list titles, webhook endpoint/header/secret material, attachment URI/path/bytes, raw purchase tokens/order IDs, arbitrary database rows, arbitrary logcat/raw error dumps, RevenueCat SDK keys, and AdMob identifiers.
When you deliberately choose Report a bug, Request a feature, Contact developer, or Report delivery problem, ThoughtFerry opens the support webpage hosted at `consultant.quinnfavo.com`. The Android app limits the support URL to the support type, `source=android`, a safe context value, and the app version. It does not put capture/delivery identifiers, diagnostics, captured content, account information, webhook details, attachment details, or purchase credentials in the support URL.
Information that you then deliberately type, paste, or submit on the support website is a separate user-initiated web interaction and should be handled according to the disclosures presented by that website.
Children
ThoughtFerry is a general productivity utility and is not intentionally designed to collect personal information from children through a hosted account service. The Play target-audience declaration and ad configuration must remain consistent with the final intended audience and Google advertising policy before rewarded advertising is enabled in production.
Changes
This policy will be updated before shipping functionality that materially changes data collection, sharing, cloud processing, analytics, advertising, authentication, billing, speech/audio handling, Google Tasks integration, external connector behavior, or support-diagnostic behavior.
Contact
Use Help & feedback in ThoughtFerry or the ThoughtFerry support page hosted at `consultant.quinnfavo.com` for privacy questions.
General Privacy Terms
These terms apply across all our applications.
Questions or privacy requests? Contact us at Quazmoz@vivaldi.net