about this page
Reproduced verbatim from the file shipped with the build. If this page and the file in the distribution ever differ, the file in the distribution prevails.
Available without registration, without payment and without a cookie gate — required by LGPLv3 §4(a)–(b) and GPLv3 §6(d).
PRIVACY POLICY FOR "The" SOFTWARE Document version: 1.0 Effective date: 2026-05-01 Last updated: 2026-07-11 This Privacy Policy explains what personal data may be processed when using The (the “Application”) and when voluntarily registering a version of the Application, why the data is processed, and what rights the user has. The data controller is: Individual Entrepreneur Vitalii Talykh, trading as “Talyh Studio” Registration or tax number: 304663237 Address: 0162, Georgia, Tbilisi, Krtsanisi district, Ponichala-3 settlement, Building 5 Privacy e-mail: [email protected] Website: https://talyh.com Product website: https://the.talyh.com This Policy is published at: https://the.talyh.com/legal/privacy 0. CURRENT STATUS OF THE REGISTRATION PROGRAMME As at the effective date of this Policy, the Application is distributed free of charge and the voluntary registration programme described in sections 4 to 11 HAS NOT BEEN LAUNCHED. The Application performs no registration, no licence-key activation, and no network communication with the Controller. Sections 4 to 11 therefore describe processing that does not currently take place. They are published in advance so that the applicable rules are known before any such processing begins, and they take effect only once the registration programme is launched and this Policy is updated with the corresponding provider, retention and configuration details. Sections 1 to 3 describe the position that applies today. 1. SUMMARY 1.0. SCOPE. This Policy covers the Application — the software installed on the user's device. It does NOT cover the websites operated by the Controller. Visiting the product website at the.talyh.com, or talyh.com, is governed by the website privacy policy published at https://talyh.com/privacy/, which applies to talyh.com and its subdomains and describes matters such as hosting and server logs. Neither policy replaces the other. 1.1. The Application is a local text editor. Its core document-processing functions operate on the user's device. 1.2. The Application does not provide cloud storage and does not send the Controller the contents of documents opened, created, or edited by the user. 1.3. Core functions are available without registration. Voluntary registration is used to associate a user with an issued registration or license key, including where a key is provided in connection with a support contribution. 1.4. Following creation of a pseudonymous identifier, the Controller should not retain the e-mail address in plain text unless the user separately requests correspondence, contacts support, or retention is required by law. 2. DATA THE APPLICATION DOES NOT COLLECT When the core local functions are used, the Application does not collect or transmit to the Controller: (a) document contents or text entered by the user; (b) names, paths, or contents of local files; (c) editing history, clipboard contents, or search queries within documents; (d) usage telemetry or behavioral analytics; (e) advertising identifiers; (f) precise location data; (g) contacts, photos, audio, or other device data; or (h) automatic crash reports, unless such a feature is later added and described in an updated Privacy Policy. The Application does not use embedded advertising networks and the Controller does not sell personal data. 3. LOCAL DOCUMENTS 3.1. Documents, settings, and other local data are stored on the user's device or in a storage location selected by the user. 3.2. The Controller does not gain access to the user's local documents merely because the user installs or uses the Application. 3.3. The user is responsible for document backups, access controls on the device, and the security of the selected storage location. 3.4. Third-party synchronization, backup, or cloud-storage services that the user independently applies to Application folders are governed by the policies of those providers and are not controlled by the Controller. 4. VOLUNTARY REGISTRATION 4.1. Registration is voluntary and is not required to use the core version of the Application. 4.2. To register, the user provides an e-mail address through [WEBSITE, REGISTRATION FORM, OR OTHER CHANNEL]. The address is used only to: (a) create a stable pseudonymous identifier; (b) associate that identifier with an issued key; (c) reissue, check the status of, or restore a key at the user's request; (d) prevent erroneous duplicate issuance and abuse; and (e) respond to a user inquiry where the user separately submits one. 4.3. Recommended technical implementation: the e-mail address is converted to a deterministic normalized form, after which the server computes an HMAC using a cryptographic hash function no weaker than SHA-256 and a separate secret key controlled by the Controller. The database stores the HMAC result rather than the plain-text e-mail address. 4.4. A simple unsalted hash of an e-mail address should not be treated as sufficient protection because the space of likely addresses can be searched. The HMAC secret must be stored separately from registration records and made available only to authorized systems. 4.5. Ed25519 is used to digitally sign the license or registration token and to verify its authenticity. Ed25519 is not used as the e-mail hashing algorithm. 4.6. The registration system may store: (a) the pseudonymous identifier derived from the e-mail address; (b) an identifier and/or public part of the issued key; (c) the signed license or registration token; (d) the Application version or edition to which the key applies; (e) issuance date, status-change dates, and date of the most recent key operation; (f) key status, such as active, replaced, revoked, or deleted; (g) minimal service information required to prevent abuse; and (h) a relationship to a payment transaction where the key is provided as part of a paid offer and the relationship is required for accounting or performance of obligations. 4.7. The registration database must not contain user document contents. 5. TECHNICAL DATA OF NETWORK REQUESTS 5.1. When the registration server is contacted, network infrastructure technically processes the IP address, request date and time, protocol version, operation result, and information required to protect the service. 5.2. Such information is not used for advertising, profiling, or analysis of document contents. 5.3. Persistent logging must be limited to the minimum necessary scope. Security logs are retained for no longer than [FOR EXAMPLE: 30 DAYS], unless a longer period is required to investigate a specific incident or comply with law. 5.4. If the registration infrastructure is configured not to retain IP addresses persistently, the Controller should describe the actual configuration here: [DESCRIPTION OF ACTUAL CONFIGURATION]. 6. PAYMENTS AND SUPPORT CONTRIBUTIONS 6.1. Payment data such as a full payment-card number is processed by the selected payment provider and must not be received by the Application or stored by the Controller. 6.2. The Controller may receive limited information from the payment provider, such as a transaction identifier, amount, currency, date, payment status, and other information required to perform the offer and meet accounting or tax obligations. 6.3. The payment provider's processing is governed by its own privacy policy. Provider used: [NAME AND LINK]. 6.4. Where the user receives a key, feature, or other specific benefit in exchange for a payment, the transaction may be treated as a paid transaction regardless of whether it is described as a “support contribution”. 7. PURPOSES AND LEGAL BASES Depending on applicable law, data is processed for: (a) completing the voluntarily requested registration and issuing a key — to perform an agreement with the user or take steps at the user's request before entering into an agreement; (b) verifying, restoring, and managing a key — to perform the agreement and on the basis of the legitimate interest in maintaining a functioning licensing system; (c) protecting the registration service and preventing abuse — on the basis of the Controller's legitimate interest in service security; (d) processing payments and meeting accounting and tax requirements — to perform an agreement and comply with legal obligations; (e) responding to inquiries — to handle the user's request; and (f) other purposes — on the basis of separate consent where consent is required by law. The Controller does not use registration data for advertising messages without separate, freely given consent. 8. PSEUDONYMIZATION AND DATA STATUS 8.1. A pseudonymous identifier reduces the risk of disclosure of an e-mail address but does not necessarily make the data anonymous. 8.2. As long as the Controller can associate the identifier with a user by recomputing a value from a submitted address or by using additional information, the registration record is treated as personal data to the extent required by applicable law. 8.3. The Controller applies personal-data security and processing requirements to such data and does not treat it as public or irreversibly anonymized. 9. RETENTION 9.1. The pseudonymous identifier and key information are retained for as long as necessary to operate the registration program, verify status, or restore or reissue a key, but not longer than [STATE PERIOD OR CRITERION]. Suggested wording for a perpetual key: “until the registration program is discontinued or the record is deleted at the user's request, unless further retention is required by law.” 9.2. Following a valid deletion request, the registration record is deleted or irreversibly disconnected from the user within [FOR EXAMPLE: 30 DAYS], unless there is a lawful basis for continued retention. 9.3. Deletion may make later verification, restoration, reissuance, or revocation of a key impossible. An already issued offline key may continue to function if verification does not require contacting the server. 9.4. Deleted records are removed from backups through the ordinary backup rotation cycle, no later than [FOR EXAMPLE: 90 DAYS], and before removal are used only for disaster recovery or security purposes. 9.5. Payment records are retained for the period required by applicable accounting, tax, and other mandatory rules. 10. RECIPIENTS AND PROCESSORS The Controller may use only providers necessary for the relevant function: (a) registration-service hosting provider: [NAME, COUNTRY]; (b) payment provider: [NAME, COUNTRY]; (c) e-mail or support provider, where the user contacts support: [NAME, COUNTRY]; and (d) professional advisers and public authorities where required by law or necessary to protect lawful rights. The Controller does not sell or rent personal data. Providers receive only the data required for their service and must protect its confidentiality and security. 11. INTERNATIONAL TRANSFERS 11.1. If a provider is located outside the user's country, data may be processed in another country. 11.2. Where required, the Controller uses legally recognized transfer mechanisms, contractual safeguards, and assessments of the level of protection. 11.3. Actual storage countries and safeguards: [COMPLETE AFTER SELECTING HOSTING, PAYMENT, AND E-MAIL PROVIDERS]. 12. SECURITY The Controller applies reasonable technical and organizational measures, including: (a) data minimization; (b) storing a pseudonymous identifier instead of a plain-text e-mail address; (c) using HMAC with a secret key for the identifier; (d) storing the HMAC key separately from the registration database; (e) digitally signing registration tokens with Ed25519; (f) keeping the Ed25519 private key only on a trusted system and excluding it from the client Application; (g) transmitting registration requests over a TLS-protected connection; (h) limiting access according to the principle of least privilege; (i) maintaining software components and reviewing security logs; and (j) backing up and testing recovery to the extent necessary. No method of storage or transmission can guarantee absolute security, but the Controller seeks to keep risk at a reasonably low level. 13. USER RIGHTS Depending on applicable law, a user may have the right to: (a) receive information about processing; (b) request access to the registration record; (c) correct inaccurate data; (d) request deletion; (e) restrict processing or object to it; (f) receive a portable copy of provided data where applicable; (g) withdraw consent without affecting the lawfulness of processing before withdrawal; and (h) lodge a complaint with a competent data-protection authority. Requests may be sent to [email protected]. To prevent disclosure of a record to another person, the Controller may request reasonable proof of control over the e-mail address or key. The Controller must not request more data than is necessary to verify the request. Where Georgian data-protection law applies, the user may contact the competent Georgian state authority responsible for personal-data protection. Where the GDPR applies, the user may also lodge a complaint with a supervisory authority in the European Economic Area state of habitual residence, place of work, or place of the alleged infringement. 14. CHILDREN The Application and voluntary registration program are not specifically directed to children below the age at which they may independently consent to the relevant processing or enter into the relevant agreement under applicable law. Where parental or guardian consent is required, registration must occur only after that consent has been obtained. 15. PLUGINS AND THIRD-PARTY COMPONENTS 15.1. Third-Party Plugins may have their own network functions and data- processing practices. This Policy does not describe the activities of independent Third-Party Plugin developers. 15.2. Before installing a Plugin, the user should review its source, permissions, license, and privacy policy. 15.3. An Official Plugin that begins collecting new categories of data must be accompanied by an updated Policy or a separate notice before the processing begins. 16. CHANGES TO THIS POLICY 16.1. The Controller may update this Policy when the Application, registration system, providers, or applicable law changes. 16.2. A new version will be published at https://the.talyh.com/legal/privacy with the update date. If a change materially affects voluntary registration, the user will receive a prominent notice before the change takes effect where required by law. 16.3. Adding telemetry, cloud storage, document synchronization, advertising, or processing of document contents requires a prior update to this Policy and, where necessary, separate consent. 17. LANGUAGE VERSIONS 17.1. This Policy is available in English and Russian. Both versions are intended to convey the same meaning. 17.2. In the event of inconsistency, the English version shall prevail to the maximum extent permitted by applicable law. This rule does not limit mandatory user rights or statutory requirements concerning the language of a privacy notice. 18. CONTACT Questions and requests concerning personal data may be sent to: Individual Entrepreneur Vitalii Talykh, trading as “Talyh Studio” Address: 0162, Georgia, Tbilisi, Krtsanisi district, Ponichala-3 settlement, Building 5 E-mail: [email protected] Website: https://talyh.com END OF DOCUMENT
Previous editions stay available at permanent addresses. This is edition 1.0