Privacy
Updated 27 September 2026
When you share a project from Thraft, the Thraft app on your Mac sends it to the Thraft server at thraft.app, which older versions of the app reach as plano.sh. Once a day, the app also sends the server a few anonymous usage counts, which you can turn off. This page says what that server keeps, where, for how long, who can read it, and how you delete it. Apart from those counts, everything you don't share stays on your Mac.
What the server stores
Three things, and nothing else:
- Your account. Your GitHub user ID, login, display name, and avatar address, as GitHub reports them when you sign in. For each Mac you sign in from, the server keeps the Mac's name and a one-way hash of the token it gave that Mac. The token itself is never stored, and neither is your GitHub token.
- The projects you share. The plans, their blocks and revisions, the board, and the records, as the app sends them. Each project is its own file.
- Daily usage counts. One row a day for each install of Thraft. A row holds a random ID the app made for that install, the Thraft and macOS versions, how many days ago the app was installed, which first-run steps it has reached, and how many times it did each of a few things, such as running an agent turn or creating a plan. A row never holds your name, your login, a project, a plan's title or number, a folder path, your IP address, or anything you wrote, and it is never joined to your account. To stop sending the counts, turn off Send anonymous usage counts on the Settings page in Thraft.
The server's logs record what kind of request came in, which project and account it was for, its size, how long it took, and how it ended. They never record a token, a login, a display name, or anything you wrote. Logs are kept for two weeks.
Where it is stored
On one server in Hetzner's data center in Falkenstein, Germany, on an encrypted disk. Backups go to one encrypted storage bucket in the same location.
How long it is kept
A project stays on the server until its owner deletes it. After that, copies remain in the backups for up to thirty days and are then removed for good.
A usage row is kept for one year and then deleted. Copies remain in the backups for up to thirty days after that.
Who can read it
The members of a project, and the two people who look after the server: Miguel Carvalho, who runs it, and Pedro Gonçalves, who can open it when Miguel can't. Nobody else. The server doesn't sell or share your data. The usage counts are read only as weekly totals, such as how many installs ran a turn that week.
How deletion works
When the owner deletes a project in Thraft, the server removes it at once. The backups age out within thirty days, after which no copy remains.