Legal

Privacy Policy

Effective date: September 9, 2026

Thonest is operated by Flocksy LLC, a Connecticut limited liability company. This policy explains what we collect, how we use it, and who processes it.

Thonest holds two quite different kinds of data, and the difference matters for everything below. Your account and your connected revenue data are private by default: they are yours, nothing is public until you publish it, and connecting a payment provider does not publish anything on its own. A published timeline is the opposite — it is meant to be read, indexed, embedded and shared, and you should assume anything on it can be copied by anyone who sees it.

1. Information we collect

Account information. Name, email address, handle, and a password (stored only as a cryptographic hash — we never store or see the password itself).

Submissions. URLs, statements, and related content you submit to the registry, together with the account that submitted them.

Public records. Statements made publicly by named people, with their source, dates, verification status, and outcome. These concern public figures and public statements, are published in the public interest, and form the registry itself.

Technical data. IP addresses and request metadata in server logs, used for security and rate limiting. We do not run advertising trackers and we do not sell personal data.

Visits and referrers. We record which pages are viewed, the site that referred you, any campaign tags on the link you followed, and the country and region your request came from. We do not store your IP address against these records. Instead we store a one-way hash of it, salted with a secret that changes every day: that lets us count visitors and spot abuse within a day, and stops the record identifying anyone after it. If you create an account, we keep the referrer and landing page from your first visit so we know what introduced you to Thonest.

What you do on a record. If you comment, react, or watch a record, we store that alongside your account. Comments are public — published under your account name and readable by anyone, including people who are not signed in. Reactions are counted, never named: a record may show how many people reacted, and we never publish who they were. What you watch is private. A record may show how many people are watching it; your watchlist is visible only to you, and we never publish it or share it with the person a record is about.

Contributor credit. When you submit a record, your account name is shown on it as the person who found and submitted the source. If you would rather not be credited publicly, email us before submitting.

Usage analytics. We use Google Analytics to understand which pages are read and whether the product works — for example, how many people who open a profile go on to record a prediction. It sets cookies and collects a truncated IP address, approximate location, device and referrer. We have switched off Google Signals and ad personalization, so this data is not used to build an advertising profile of you or followed across devices. We do not send your account details, email address or the contents of what you submit to it.

Session recordings and heatmaps. We use Hotjar to see how pages are actually used — where people click, how far they scroll, and where they get stuck. It records page interactions and may replay them as an anonymised session. Text you type into the form where a payment key is pasted is suppressed at source and never reaches Hotjar. We do not send your account details, email address or connected revenue figures to it.

Advertising measurement. We run ads on X (formerly Twitter), and X’s conversion pixel is present on every page so we can tell which ads lead to a signup. It sets cookies and reports page visits and signups back to X, which may match them to an X account. It is an advertising tool, and unlike the tools above it does feed a network that personalises ads. We do not send your account details, email address or connected revenue figures to it. You can limit this in your X privacy settings, and browser tracking protection or an ad blocker will stop it loading at all.

Local storage. A session token is stored in your browser to keep you signed in.

2. How we use information

To operate the registry: verifying submissions against their sources, creating and displaying records, resolving locked tests, sending account emails (such as password resets, and — only for records you choose to watch — deadline reminders and settlement outcomes, which stop when you stop watching), preventing abuse, and improving the Service.

3. Artificial intelligence

Thonest uses third-party AI models to read submitted sources, extract candidate statements, transcribe audio and video, propose resolution tests, and check quotes against sources. Content you submit — including URLs and the text or media they contain — is processed by Anthropic (Claude) for extraction and verification and by Google (Gemini) for audio and video transcription, under their respective data terms. AI output is machine-checked against sources before anything is published; no record is published solely on an AI’s authority.

4. Service providers

We use third parties to run the Service: Vercel (hosting), Prisma Postgres (Prisma Data’s hosted database service, where registry and account data is stored), Postmark (transactional email), the Internet Archive (independent archival of sources), Google Analytics (usage measurement, configured as described in Section 1), Hotjar (heatmaps and session recordings), X Corp. (advertising conversion measurement, as described in Section 1), and the AI providers listed above. Each receives only what it needs to perform its function.

4a. Payment provider data

If you connect Stripe, we hold an access credential for your account, encrypted at rest, and we use it only to read subscription data. We store the credential so that measurements can continue on a schedule; we never store card numbers, bank details, customer payment methods, or the personal details of your customers.

What we retain from those reads is a periodic snapshot: monthly recurring revenue, the number of paying customers, the currency, and a breakdown of which subscriptions were counted or excluded. Individual customer identities are not part of what we keep or publish.

Snapshots relied on by a locked goal are permanent. They are the evidence that settles it, and they remain after you disconnect. Disconnecting ends future collection immediately. If you disconnect before locking any goal, you may ask us to delete the snapshots taken up to that point and we will do so.

5. Blockchain anchoring

No readable names or statement text are intentionally written to the blockchain. Thonest publishes cryptographic hashes to the Base public blockchain that commit to off-chain records, allowing anyone to verify a record has not been altered. Those blockchain entries are permanent and outside anyone’s control, including ours.

6. Permanence and your rights

The registry is append-only by default: published records are corrected by appending public correction events, not by silent editing. Consistent with our Terms, we may restrict or withdraw a readable record from public display when required by law, the Terms, or our published policies; withdrawals are documented transparently when legally permitted, and hashes already anchored to the public blockchain remain. If a record about you is inaccurate, use the dispute process — corrections are public and fast. For account data (your email, name, and credentials), you may request access, correction, or deletion at any time by emailing hello@thonest.com. Deleting an account does not remove public records of public statements, which remain in the registry with their provenance.

What happens to your activity. Deleting your account removes your reactions and your watchlist, and stops every notification. Your comments are deleted with it — the text goes, and any replies underneath keep their position so a thread does not collapse into nonsense. You can delete an individual comment yourself at any time without deleting your account. Records you submitted stay in the registry, because they document someone else’s public statement rather than anything about you; ask us and we will remove your name from the contributor credit on them.

7. Legal bases and regional rights

Where GDPR or similar laws apply, we process account data to perform our contract with you, and public records under legitimate interest in maintaining an accurate public record of public statements, and journalistic/archival purposes in the public interest. Where such laws apply, you may have rights to access, rectify, port, restrict, or object; contact us to exercise them. California residents: we do not sell or share personal information as defined by the CCPA/CPRA.

8. Retention and security

Account data is kept while your account exists. Registry records are kept indefinitely — permanence is the product. Passwords are hashed with a memory-hard algorithm; access to production systems is restricted; transport is encrypted.

9. Age

Creating an account requires you to be at least 18 or the age of majority where you live, as stated in the Terms. The public, read-only site is not directed to children under 13, and we do not knowingly collect information from children under 13.

10. Changes and contact

Material changes will be posted here with a new effective date. Questions: hello@thonest.com · Flocksy LLC, d/b/a Thonest · PO Box 1691, Pawcatuck, CT 06379, United States.

See also our Terms of Service.