Last updated: 2026-08-27T00:00:00.000Z

Privacy Policy

Draft pending legal review. Prepared in-house against the Singapore Personal Data Protection Act (PDPA) and reviewed by AI on 2026-08-26. That is not a substitute for a Singapore-qualified lawyer, and checkout does not open until this review is complete. Not legal advice.

This policy explains how JOYFULAI TECHNOLOGY PTE. LTD. (UEN 202347972H) handles personal data. It is written to meet the obligations of the Singapore Personal Data Protection Act 2012.

The short version

Thorp runs on your machine. We never receive your passwords, cookies, session tokens, browsing history or the contents of any browser profile. They are written to %APPDATA%\Thorp and to the browser data directories on your own disk, and they stay there.

For a paid licence, Thorp attempts a background licence heartbeat on startup and roughly every 24 hours until one attempt succeeds in that ISO week; after a success it stops until the next week. A stored record contains an opaque licence ID, the ISO week, the total number of local browser environments, and the time our server received it. It does not contain your name, email, order number, browsing activity or profile contents. A free installation without a paid licence file sends no heartbeat at all.

If you want to verify any of this, capture the application’s network traffic and look.

What we do collect

WhatWhyKept for
Website and API operational logs processed by Cloudflare, which may include IP address, request URL, timestamp, headers, response information and security metadataHosting, security, abuse prevention and fault diagnosisUp to 7 days
Cloudflare Web Analytics, a cookie-free measurement script Cloudflare injects into our website pages. It reports the page URL, referrer, browser and device type, country and page-load timings to Cloudflare. It does not use cookies and does not follow you across other sitesTo see which pages people read, so we know what to write nextHeld by Cloudflare under its own retention policy; we see only aggregate reports
Your email address and message, if you write to supportTo answer you24 months after the last message
Buyer records available from Paddle: name, address, email address, purchase history and transaction analytics. We access only what fulfilment, licence administration, support, refund and fraud handling and our records reasonably needTo issue and validate a licence, answer support, handle refunds, and meet tax record obligationsAs required by law
Paid-licence heartbeat: an opaque licence ID, the ISO week, the total environment count, and our server’s receipt time. Attempted on startup and roughly every 24 hours until one attempt succeeds in that ISO weekTo administer paid licences and to measure active paid installationsOne stored row per licence per week, deleted automatically 12 months after collection by a scheduled job that runs daily
A diagnostic bundle, only when you choose to upload oneTo diagnose the problem you reported90 days

We do not describe our website logs as anonymous. Hosting and security metadata may sometimes allow requests or visits to be correlated, so an absolute claim would not be supportable.

We do not receive or store your full card number, CVV or payment credentials. Depending on Paddle’s dashboard and API, we may be able to access limited payment-method metadata such as card brand, the last four digits, expiry and cardholder name. We do not use that information to charge you.

What we never collect

Passwords. Cookies. Session tokens. The contents of a browser profile. The URLs you open inside your browser environments — the pages your own automation and browsing visit. The content of pages your automation reads. Screenshots, unless you attach one yourself.

This list is about the browser environments the Software runs. It is not a claim about our own website: the row above says plainly that our website pages are measured.

We collect, use and disclose personal data only for the notified purposes, and only where we have consent, deemed consent, another basis authorised by the PDPA, or an obligation under other written law. Processing that is reasonably necessary to complete and fulfil a purchase you request is not consent to unrelated analytics or marketing.

Sending a support message or a diagnostic bundle is voluntary, and it authorises us to use its contents to investigate and answer that request. We will not use it for an unrelated purpose without a separate legal basis and notification.

You may withdraw consent on reasonable notice. We will explain the likely consequences and cease the affected processing, including by relevant processors, unless continued processing is authorised or required by law.

We use the email associated with a licence for fulfilment, product, security, legal and support messages. We do not use personal data received from Paddle for direct marketing unless you have separately opted in, and every marketing email carries an effective unsubscribe method.

We do not conduct outbound telemarketing. We will not send marketing calls, SMS or messages to a Singapore telephone number unless the communication is permitted both by the PDPA’s Do Not Call provisions and by our agreement with Paddle.

Disclosure

Paddle is the independent seller, Merchant of Record and data controller for the transaction. Paddle collects and processes checkout, billing, tax, fraud, payment and refund data under Paddle’s own Privacy Notice, and makes buyer records available to us. Requests concerning Paddle’s independent processing should be directed to Paddle.

Brevo sends our transactional email — the licence delivery message and support replies — and therefore receives the recipient’s email address and the content of that message. It acts as our processor under its agreement with us. Cloudflare hosts our website and API, routes our inbound mail, and provides the website measurement described above.

We do not sell personal data, and we do not share it for advertising.

We may disclose personal data where required by law or a valid order of a Singapore court or authority.

Transfers outside Singapore

Some of the providers above operate outside Singapore. Our website hosting, API, email routing and website measurement are provided by Cloudflare under its data processing terms; our outbound transactional email is sent by Brevo under its data processing terms; Paddle acts as an independent controller under its own terms.

Before transferring personal data outside Singapore we rely on those contractual terms as legally enforceable obligations providing a standard of protection comparable to the PDPA, as the transfer limitation obligation requires.

Protection and retention

We keep the data listed above in access-controlled systems. Transaction and accounting records needed for tax or accounting obligations are retained for at least five years from the relevant Year of Assessment. Other licence and support records are retained for the specific periods in the table above. When the stated purpose and every lawful legal or business need have ended, we delete the record or irreversibly de-identify it. Paddle applies its own retention policy as an independent controller.

Heartbeat rows are deleted by a scheduled job that runs once a day. We say this only because the job exists — publishing a retention period we do not enforce would be worse than publishing none.

We notify the Personal Data Protection Commission when a data breach is either likely to cause significant harm or of significant scale, within the period the PDPA requires after determining that it is notifiable. We notify affected individuals where the significant-harm test and the statutory notification requirements apply.

Your rights

Subject to the exceptions the PDPA allows, you may:

Write to the address below. We respond as soon as reasonably possible; if we cannot respond within 30 days, we will tell you when we expect to.

Complaints

If you are unhappy with how we handled your personal data, write to support@thorp.run with the subject “Privacy complaint”. The Data Protection Officer acknowledges it, investigates, and normally responds within 30 days, or explains why more time is needed. You may also complain to the Personal Data Protection Commission.

Data Protection Officer

As required by section 11(3) of the PDPA, we have designated an individual to be responsible for data protection. Public enquiries and requests reach that individual through the business contact information below; the PDPA does not require us to publish their name.

Data Protection Officer, JOYFULAI TECHNOLOGY PTE. LTD., 60 Paya Lebar Road #13-04, Paya Lebar Square, Singapore 409051 Email: support@thorp.run

Changes

If this policy changes, the date at the top of this page changes, and material changes are sent to the email associated with any active licence.