In plain language,
Your archive belongs to you.
Thus Far may hold prayers and memories you would never put in an ordinary cloud journal. It starts with local storage and encrypted data, before you create an account or turn on backup. This page describes how the current private beta handles your archive.
Local first, by default
You do not need a Thus Far account or network connection to save your first memories. Thus Far stores text, attachments, story connections, and the rest of your archive on your iPhone. The local database is encrypted. Its key stays in the device-bound Keychain instead of beside the archive.
Backup only when you choose it
Backup is off until you turn it on. If you enable it, Thus Far encrypts the archive on your iPhone before sending anything to the backup service. The service receives encrypted content and the limited operational metadata it needs to move and restore that content. It does not receive a readable copy of your memories.
Controls you can understand
- App Lock: add an intentional lock at the entrance to your archive.
- Selective sharing: choose one memorial to share without exposing the archive around it.
- Export: create a portable copy of your archive for safekeeping outside Thus Far.
- Deletion: remove local data and, when applicable, encrypted remote backup data.
On-device meaning search
Thus Far can find related memories by meaning when you cannot remember the exact words. In the private beta, this is an optional feature that runs on your device. Your private reflections do not become material for a remote recommendation feed.
Share one memorial at a time
Thus Far has no follower count, public profile, engagement streak, or advertising feed. When you share, you choose one story. You decide whether to keep a testimony to yourself or send it to someone you trust.
Data the service receives
Without backup or private-link sharing, your journal content stays on your iPhone. When you use an online feature, the service receives the information required to provide it: random account and device identifiers, encrypted records or media, ciphertext sizes and checksums, object versions, request timing, and link expiry or revocation status. The decryption key for a private keepsake stays in the URL fragment and is not sent to the service.
Optional, content-blind diagnostics
Product diagnostics are off by default. If you turn them on, Thus Far sends allowlisted events such as feature success or failure, broad duration and archive-size buckets, app version, and a keyed installation pseudonym. Diagnostics do not include prayer text, titles, names, photos, recordings, search terms, recovery keys, or precise location. Product events are retained for up to three months.
Retention and deletion
Local content remains until you delete it or remove the app. You may delete an active remote archive from the app. Cloudflare provider-recovery history may retain encrypted database state for 7 days on a Free plan or 30 days on a Paid plan; the production plan in use determines the applicable window. Incomplete multipart uploads expire automatically after seven days. Private keepsakes expire when you choose and can be revoked sooner.
Service providers and sale of data
Cloudflare provides hosting, encrypted object storage, database infrastructure, and optional analytics. Thus Far does not sell your personal information and does not use journal content for advertising or model training.
Questions and requests
For privacy questions, deletion requests, or support, visit the Thus Far support page or email support@thusfar.app. Please do not include private journal content or a recovery key in a support message.