Last updated: 2026-08-27T00:00:00.000Z
Privacy Policy
Draft pending legal review. Prepared in-house against the Singapore Personal Data Protection Act (PDPA) and reviewed by AI on 2026-08-26. That is not a substitute for a Singapore-qualified lawyer, and checkout does not open until this review is complete. Not legal advice.
This policy explains how JOYFULAI TECHNOLOGY PTE. LTD. (UEN 202347972H) handles personal data. It is written to meet the obligations of the Singapore Personal Data Protection Act 2012.
The short version
Thorp runs on your machine. We never receive your passwords, cookies, session tokens, browsing history or the contents of any browser profile. They are written to %APPDATA%\Thorp and to the browser data directories on your own disk, and they stay there.
For a paid licence, Thorp attempts a background licence heartbeat on startup and roughly every 24 hours until one attempt succeeds in that ISO week; after a success it stops until the next week. A stored record contains an opaque licence ID, the ISO week, the total number of local browser environments, and the time our server received it. It does not contain your name, email, order number, browsing activity or profile contents. A free installation without a paid licence file sends no heartbeat at all.
If you want to verify any of this, capture the application’s network traffic and look.
What we do collect
| What | Why | Kept for |
|---|---|---|
| Website and API operational logs processed by Cloudflare, which may include IP address, request URL, timestamp, headers, response information and security metadata | Hosting, security, abuse prevention and fault diagnosis | Up to 7 days |
| Cloudflare Web Analytics, a cookie-free measurement script Cloudflare injects into our website pages. It reports the page URL, referrer, browser and device type, country and page-load timings to Cloudflare. It does not use cookies and does not follow you across other sites | To see which pages people read, so we know what to write next | Held by Cloudflare under its own retention policy; we see only aggregate reports |
| Your email address and message, if you write to support | To answer you | 24 months after the last message |
| Buyer records available from Paddle: name, address, email address, purchase history and transaction analytics. We access only what fulfilment, licence administration, support, refund and fraud handling and our records reasonably need | To issue and validate a licence, answer support, handle refunds, and meet tax record obligations | As required by law |
| Paid-licence heartbeat: an opaque licence ID, the ISO week, the total environment count, and our server’s receipt time. Attempted on startup and roughly every 24 hours until one attempt succeeds in that ISO week | To administer paid licences and to measure active paid installations | One stored row per licence per week, deleted automatically 12 months after collection by a scheduled job that runs daily |
| A diagnostic bundle, only when you choose to upload one | To diagnose the problem you reported | 90 days |
We do not describe our website logs as anonymous. Hosting and security metadata may sometimes allow requests or visits to be correlated, so an absolute claim would not be supportable.
We do not receive or store your full card number, CVV or payment credentials. Depending on Paddle’s dashboard and API, we may be able to access limited payment-method metadata such as card brand, the last four digits, expiry and cardholder name. We do not use that information to charge you.
What we never collect
Passwords. Cookies. Session tokens. The contents of a browser profile. The URLs you open inside your browser environments — the pages your own automation and browsing visit. The content of pages your automation reads. Screenshots, unless you attach one yourself.
This list is about the browser environments the Software runs. It is not a claim about our own website: the row above says plainly that our website pages are measured.
Purpose and consent
We collect, use and disclose personal data only for the notified purposes, and only where we have consent, deemed consent, another basis authorised by the PDPA, or an obligation under other written law. Processing that is reasonably necessary to complete and fulfil a purchase you request is not consent to unrelated analytics or marketing.
Sending a support message or a diagnostic bundle is voluntary, and it authorises us to use its contents to investigate and answer that request. We will not use it for an unrelated purpose without a separate legal basis and notification.
You may withdraw consent on reasonable notice. We will explain the likely consequences and cease the affected processing, including by relevant processors, unless continued processing is authorised or required by law.
We use the email associated with a licence for fulfilment, product, security, legal and support messages. We do not use personal data received from Paddle for direct marketing unless you have separately opted in, and every marketing email carries an effective unsubscribe method.
We do not conduct outbound telemarketing. We will not send marketing calls, SMS or messages to a Singapore telephone number unless the communication is permitted both by the PDPA’s Do Not Call provisions and by our agreement with Paddle.
Disclosure
Paddle is the independent seller, Merchant of Record and data controller for the transaction. Paddle collects and processes checkout, billing, tax, fraud, payment and refund data under Paddle’s own Privacy Notice, and makes buyer records available to us. Requests concerning Paddle’s independent processing should be directed to Paddle.
Brevo sends our transactional email — the licence delivery message and support replies — and therefore receives the recipient’s email address and the content of that message. It acts as our processor under its agreement with us. Cloudflare hosts our website and API, routes our inbound mail, and provides the website measurement described above.
We do not sell personal data, and we do not share it for advertising.
We may disclose personal data where required by law or a valid order of a Singapore court or authority.
Transfers outside Singapore
Some of the providers above operate outside Singapore. Our website hosting, API, email routing and website measurement are provided by Cloudflare under its data processing terms; our outbound transactional email is sent by Brevo under its data processing terms; Paddle acts as an independent controller under its own terms.
Before transferring personal data outside Singapore we rely on those contractual terms as legally enforceable obligations providing a standard of protection comparable to the PDPA, as the transfer limitation obligation requires.
Protection and retention
We keep the data listed above in access-controlled systems. Transaction and accounting records needed for tax or accounting obligations are retained for at least five years from the relevant Year of Assessment. Other licence and support records are retained for the specific periods in the table above. When the stated purpose and every lawful legal or business need have ended, we delete the record or irreversibly de-identify it. Paddle applies its own retention policy as an independent controller.
Heartbeat rows are deleted by a scheduled job that runs once a day. We say this only because the job exists — publishing a retention period we do not enforce would be worse than publishing none.
We notify the Personal Data Protection Commission when a data breach is either likely to cause significant harm or of significant scale, within the period the PDPA requires after determining that it is notifiable. We notify affected individuals where the significant-harm test and the statutory notification requirements apply.
Your rights
Subject to the exceptions the PDPA allows, you may:
- ask for a copy of the personal data about you that is under our control, together with information about how it was used or disclosed during the preceding year;
- ask us to correct it. Where required, we will send the correction on to organisations we disclosed the data to during the preceding year;
- ask us to delete it, subject to retention that law or a legitimate business need requires.
Write to the address below. We respond as soon as reasonably possible; if we cannot respond within 30 days, we will tell you when we expect to.
Complaints
If you are unhappy with how we handled your personal data, write to support@thorp.run with the subject “Privacy complaint”. The Data Protection Officer acknowledges it, investigates, and normally responds within 30 days, or explains why more time is needed. You may also complain to the Personal Data Protection Commission.
Data Protection Officer
As required by section 11(3) of the PDPA, we have designated an individual to be responsible for data protection. Public enquiries and requests reach that individual through the business contact information below; the PDPA does not require us to publish their name.
Data Protection Officer, JOYFULAI TECHNOLOGY PTE. LTD., 60 Paya Lebar Road #13-04, Paya Lebar Square, Singapore 409051 Email: support@thorp.run
Changes
If this policy changes, the date at the top of this page changes, and material changes are sent to the email associated with any active licence.