Privacy Policy
Effective October 11, 2026
This policy explains what personal information Thegram (“we”) handles when you use thegram.one, the Thegram web viewer at viewer.thegram.one, the Thegram web app at vault.thegram.one, and the Thegram apps for Mac, iPhone, and iPad (the “Services”), and what you can ask us to do with it. We follow the Personal Information Protection Act of the Republic of Korea.
- No ads, no tracking across sites, and no account needed to read a file.
- We count visits to thegram.one and downloads of the Mac app as daily totals, without cookies and without keeping your IP address.
- The web viewer, and the web app while you are signed out, read the file you open in memory, send back the result, and keep nothing.
- If you sign in, we keep your account and the documents you save to a Vault, and use the Google Drive accounts you connect.
- The Mac app sends nothing to us while you use only files on your Mac. If you sign in to use Vaults, it sends your sign-in and the Vault documents you open or save.
- The iPhone and iPad app sends nothing to us while you read only files on your device. If you sign in, it sends your sign-in and downloads your Vault documents and connected Google Drive documents to read on the device.
- If you email us, we use your address to reply.
1. What we handle
| Where | What | How |
|---|---|---|
| thegram.one | Technical logs: IP address, browser type, the page requested, and the time | Recorded automatically by our web server |
| thegram.one visit and download counts | Daily totals only: visitors and views for each page, and Mac app downloads. To recognize a returning visitor within the same day, the server combines your IP address and browser type with a random value that changes every day, and keeps the result only in memory | When a page is shown, your browser sends that page’s address to thegram.one/api/visit. Downloads are counted as the file is sent. Nothing is stored in your browser |
| Web viewer, and web app signed out | The .gram file you choose to open, and the same technical logs | You send the file; logs are recorded automatically |
| Web app, signed in | Your account (email, name, profile picture when supplied, sign-in method, display name and display preferences), your sessions and desktop devices (hashed credentials, browser type, IP address), the versions of our terms you agreed to and when, the documents you save to a Vault, and the Google Drive accounts you connect | You sign in with Google, Apple, or an email code, and choose what to save or connect |
| Mac app | Using only files on your Mac: nothing. Signed in: the same account, session, and device information as the web app, and the Vault documents you open or save | The app works on your Mac without our servers until you sign in to use Vaults |
| iPhone and iPad app | Reading only files on your device: nothing. Signed in: the same account and session information as the web app, the date of birth check at sign-up (not stored), and the Vault and Google Drive documents it downloads to read. Search runs on your device and its index never leaves it | The app works without our servers until you sign in in its settings with Google, Apple, or an email code |
| Your email address, any name you include, and your message | When you write to support@thegram.one |
The moving mark on our home page remembers its own path inside your browser tab to draw the animation. That record never leaves your browser and disappears when you close the tab.
The web viewer, and the web app while you are signed out, do not save your file on our servers, write it to logs, or create a link to it. The web viewer stores nothing in your browser. Whether or not you sign in, the web app keeps some things only in your browser and never sends them to us: display settings and language, panel layout, the titles of the last 8 documents you opened, and, if you choose a folder on your device, the browser’s permission to open it again. Clearing the site’s data in your browser removes them.
Signed-in use, including Google Drive and the Google API Services User Data Policy, is described in detail in the web app privacy policy.
2. Why we use it
- To run the Services, show you the files you open, and keep your Vaults and Drive connections working.
- To keep the Services secure and investigate abuse.
- To count how many people visit thegram.one and download the Mac app. The counts are daily totals and cannot identify you.
- To answer your questions and requests, and to send sign-in codes and security notices from noreply@thegram.one. We do not send marketing email unless you ask for it.
We do not use personal information for advertising or profiling, and we do not use your files to train AI models.
3. How long we keep it
- Files opened while signed out: not kept. They are discarded once the response is sent.
- Account information and the record of which terms you agreed to: until you delete your account.
- Sessions and desktop devices: until the session ends or is revoked, at most 30 days.
- Vault documents and their history: while the Vault exists. A deleted Vault stays in the trash for 30 days and is then purged. Encrypted backups are kept for up to 14 days.
- Technical logs: up to 90 days, unless we need them longer to investigate a security incident or the law requires it.
- Visit and download counts: the daily totals are kept indefinitely and contain no personal information. The in-memory value used to recognize returning visitors is discarded at the end of each day (Korea time) or when the server restarts.
- Support emails: until your request is resolved, then up to 1 year, unless you ask us to delete them sooner or the law requires us to keep them longer.
4. How we delete it
When the retention period ends or the purpose is met, we delete the information without delay, using methods that prevent recovery.
5. Sharing
We do not sell personal information. We do not give it to third parties unless the law requires it, for example when a court or an investigative authority makes a lawful request.
We entrust the following processing to other companies:
- Resend, Inc. (United States) delivers sign-in code emails. It receives your email address and the message only to send it, and does not use them for anything else.
- Encrypted backups of Vault data are kept in the operator’s Google Drive for up to 14 days. The encryption key is held only by us.
Transfer abroad: each time we send you a sign-in code, your email address and the message are sent over an encrypted connection to Resend, Inc. in the United States, only to deliver the email, and are deleted under Resend’s retention rules once that purpose is met. If we add or change a processor, we will name it and its task here before the change takes effect.
When you sign in with Google or Apple, or connect Google Drive, that company processes your information under its own privacy policy.
Our pages link to X, Telegram, and LinkedIn. Their privacy policies apply when you visit them.
6. Your rights
You can ask us to show, correct, delete, or stop processing your personal information. Email support@thegram.one and we will respond within 10 days. If you have no account, please tell us the email address you used or roughly when you contacted us, so we can find the information. If you have an account, you can also change your profile, sign out other sessions and devices, disconnect Google Drive, or delete the account in the web app’s settings. In the iPhone and iPad app, Settings › Account › Delete Account deletes the account and the Vaults it owns.
7. Security
- We collect as little as we can.
- Connections to our sites use HTTPS.
- Files opened in the web app while signed out stay in memory and are never stored.
- Sessions, device tokens, and email sign-in codes are stored only as hashes.
- Only the people who run Thegram can access logs and support email.
8. Cookies
thegram.one does not use cookies, and neither does the web app while you are signed out. When you sign in, the web app sets a cookie that keeps you signed in and a short-lived cookie used only during sign-in. We do not use advertising or analytics cookies. Visit counts use no cookies or other storage in your browser; if your browser or a content blocker blocks thegram.one/api/visit, your visit is not counted.
9. Children
You must be at least 14 years old to create an account. At sign-up we ask for your date of birth only to confirm this. We do not store it; we keep only the fact that the check passed and when. If you are under 14, the account and everything entered for it are deleted at once and we collect nothing further. If you believe a child under 14 has sent us personal information, contact us and we will delete it.
10. Contact and help
| Privacy contact | Thegram team |
|---|---|
| support@thegram.one |
For help with a privacy complaint in Korea, you can also contact:
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office: 1301, www.spo.go.kr
- Korean National Police Agency: 182, ecrm.police.go.kr
11. Changes to this policy
We will post changes on this page at least 7 days before they take effect, or at least 30 days before for changes that significantly affect your rights. If you have an account, the web app asks you to agree again when you next sign in.