about this page
Reproduced verbatim from the file shipped with the build. If this page and the file in the distribution ever differ, the file in the distribution prevails.
Available without registration, without payment and without a cookie gate — required by LGPLv3 §4(a)–(b) and GPLv3 §6(d).
PRIVACY POLICY
FOR "The" SOFTWARE
Document version: 1.0
Effective date: 2026-05-01
Last updated: 2026-07-11
This Privacy Policy explains what personal data may be processed when using
The (the “Application”) and when voluntarily registering a version
of the Application, why the data is processed, and what rights the user has.
The data controller is:
Individual Entrepreneur Vitalii Talykh, trading as “Talyh Studio”
Registration or tax number: 304663237
Address: 0162, Georgia, Tbilisi, Krtsanisi district, Ponichala-3 settlement, Building 5
Privacy e-mail: privacy@talyh.com
Website: https://talyh.com
Product website: https://the.talyh.com
This Policy is published at: https://the.talyh.com/legal/privacy
0. CURRENT STATUS OF THE REGISTRATION PROGRAMME
As at the effective date of this Policy, the Application is distributed free of
charge and the voluntary registration programme described in sections 4 to 11
HAS NOT BEEN LAUNCHED. The Application performs no registration, no licence-key
activation, and no network communication with the Controller.
Sections 4 to 11 therefore describe processing that does not currently take
place. They are published in advance so that the applicable rules are known
before any such processing begins, and they take effect only once the
registration programme is launched and this Policy is updated with the
corresponding provider, retention and configuration details.
Sections 1 to 3 describe the position that applies today.
1. SUMMARY
1.0. SCOPE. This Policy covers the Application — the software installed on the
user's device. It does NOT cover the websites operated by the Controller.
Visiting the product website at the.talyh.com, or talyh.com, is governed by the
website privacy policy published at https://talyh.com/privacy/, which applies
to talyh.com and its subdomains and describes matters such as hosting and
server logs. Neither policy replaces the other.
1.1. The Application is a local text editor. Its core document-processing
functions operate on the user's device.
1.2. The Application does not provide cloud storage and does not send the
Controller the contents of documents opened, created, or edited by the user.
1.3. Core functions are available without registration. Voluntary registration
is used to associate a user with an issued registration or license key,
including where a key is provided in connection with a support contribution.
1.4. Following creation of a pseudonymous identifier, the Controller should not
retain the e-mail address in plain text unless the user separately requests
correspondence, contacts support, or retention is required by law.
2. DATA THE APPLICATION DOES NOT COLLECT
When the core local functions are used, the Application does not collect or
transmit to the Controller:
(a) document contents or text entered by the user;
(b) names, paths, or contents of local files;
(c) editing history, clipboard contents, or search queries within documents;
(d) usage telemetry or behavioral analytics;
(e) advertising identifiers;
(f) precise location data;
(g) contacts, photos, audio, or other device data; or
(h) automatic crash reports, unless such a feature is later added and described
in an updated Privacy Policy.
The Application does not use embedded advertising networks and the Controller
does not sell personal data.
3. LOCAL DOCUMENTS
3.1. Documents, settings, and other local data are stored on the user's device
or in a storage location selected by the user.
3.2. The Controller does not gain access to the user's local documents merely
because the user installs or uses the Application.
3.3. The user is responsible for document backups, access controls on the
device, and the security of the selected storage location.
3.4. Third-party synchronization, backup, or cloud-storage services that the
user independently applies to Application folders are governed by the policies
of those providers and are not controlled by the Controller.
4. VOLUNTARY REGISTRATION
4.1. Registration is voluntary and is not required to use the core version of
the Application.
4.2. To register, the user provides an e-mail address through [WEBSITE,
REGISTRATION FORM, OR OTHER CHANNEL]. The address is used only to:
(a) create a stable pseudonymous identifier;
(b) associate that identifier with an issued key;
(c) reissue, check the status of, or restore a key at the user's request;
(d) prevent erroneous duplicate issuance and abuse; and
(e) respond to a user inquiry where the user separately submits one.
4.3. Recommended technical implementation: the e-mail address is converted to
a deterministic normalized form, after which the server computes an HMAC using
a cryptographic hash function no weaker than SHA-256 and a separate secret key
controlled by the Controller. The database stores the HMAC result rather than
the plain-text e-mail address.
4.4. A simple unsalted hash of an e-mail address should not be treated as
sufficient protection because the space of likely addresses can be searched.
The HMAC secret must be stored separately from registration records and made
available only to authorized systems.
4.5. Ed25519 is used to digitally sign the license or registration token and to
verify its authenticity. Ed25519 is not used as the e-mail hashing algorithm.
4.6. The registration system may store:
(a) the pseudonymous identifier derived from the e-mail address;
(b) an identifier and/or public part of the issued key;
(c) the signed license or registration token;
(d) the Application version or edition to which the key applies;
(e) issuance date, status-change dates, and date of the most recent key
operation;
(f) key status, such as active, replaced, revoked, or deleted;
(g) minimal service information required to prevent abuse; and
(h) a relationship to a payment transaction where the key is provided as part
of a paid offer and the relationship is required for accounting or
performance of obligations.
4.7. The registration database must not contain user document contents.
5. TECHNICAL DATA OF NETWORK REQUESTS
5.1. When the registration server is contacted, network infrastructure
technically processes the IP address, request date and time, protocol version,
operation result, and information required to protect the service.
5.2. Such information is not used for advertising, profiling, or analysis of
document contents.
5.3. Persistent logging must be limited to the minimum necessary scope.
Security logs are retained for no longer than [FOR EXAMPLE: 30 DAYS], unless a
longer period is required to investigate a specific incident or comply with
law.
5.4. If the registration infrastructure is configured not to retain IP
addresses persistently, the Controller should describe the actual configuration
here: [DESCRIPTION OF ACTUAL CONFIGURATION].
6. PAYMENTS AND SUPPORT CONTRIBUTIONS
6.1. Payment data such as a full payment-card number is processed by the
selected payment provider and must not be received by the Application or stored
by the Controller.
6.2. The Controller may receive limited information from the payment provider,
such as a transaction identifier, amount, currency, date, payment status, and
other information required to perform the offer and meet accounting or tax
obligations.
6.3. The payment provider's processing is governed by its own privacy policy.
Provider used: [NAME AND LINK].
6.4. Where the user receives a key, feature, or other specific benefit in
exchange for a payment, the transaction may be treated as a paid transaction
regardless of whether it is described as a “support contribution”.
7. PURPOSES AND LEGAL BASES
Depending on applicable law, data is processed for:
(a) completing the voluntarily requested registration and issuing a key — to
perform an agreement with the user or take steps at the user's request
before entering into an agreement;
(b) verifying, restoring, and managing a key — to perform the agreement and on
the basis of the legitimate interest in maintaining a functioning licensing
system;
(c) protecting the registration service and preventing abuse — on the basis of
the Controller's legitimate interest in service security;
(d) processing payments and meeting accounting and tax requirements — to
perform an agreement and comply with legal obligations;
(e) responding to inquiries — to handle the user's request; and
(f) other purposes — on the basis of separate consent where consent is required
by law.
The Controller does not use registration data for advertising messages without
separate, freely given consent.
8. PSEUDONYMIZATION AND DATA STATUS
8.1. A pseudonymous identifier reduces the risk of disclosure of an e-mail
address but does not necessarily make the data anonymous.
8.2. As long as the Controller can associate the identifier with a user by
recomputing a value from a submitted address or by using additional
information, the registration record is treated as personal data to the extent
required by applicable law.
8.3. The Controller applies personal-data security and processing requirements
to such data and does not treat it as public or irreversibly anonymized.
9. RETENTION
9.1. The pseudonymous identifier and key information are retained for as long
as necessary to operate the registration program, verify status, or restore or
reissue a key, but not longer than [STATE PERIOD OR CRITERION].
Suggested wording for a perpetual key:
“until the registration program is discontinued or the record is deleted at
the user's request, unless further retention is required by law.”
9.2. Following a valid deletion request, the registration record is deleted or
irreversibly disconnected from the user within [FOR EXAMPLE: 30 DAYS], unless
there is a lawful basis for continued retention.
9.3. Deletion may make later verification, restoration, reissuance, or
revocation of a key impossible. An already issued offline key may continue to
function if verification does not require contacting the server.
9.4. Deleted records are removed from backups through the ordinary backup
rotation cycle, no later than [FOR EXAMPLE: 90 DAYS], and before removal are
used only for disaster recovery or security purposes.
9.5. Payment records are retained for the period required by applicable
accounting, tax, and other mandatory rules.
10. RECIPIENTS AND PROCESSORS
The Controller may use only providers necessary for the relevant function:
(a) registration-service hosting provider: [NAME, COUNTRY];
(b) payment provider: [NAME, COUNTRY];
(c) e-mail or support provider, where the user contacts support:
[NAME, COUNTRY]; and
(d) professional advisers and public authorities where required by law or
necessary to protect lawful rights.
The Controller does not sell or rent personal data. Providers receive only the
data required for their service and must protect its confidentiality and
security.
11. INTERNATIONAL TRANSFERS
11.1. If a provider is located outside the user's country, data may be
processed in another country.
11.2. Where required, the Controller uses legally recognized transfer
mechanisms, contractual safeguards, and assessments of the level of protection.
11.3. Actual storage countries and safeguards:
[COMPLETE AFTER SELECTING HOSTING, PAYMENT, AND E-MAIL PROVIDERS].
12. SECURITY
The Controller applies reasonable technical and organizational measures,
including:
(a) data minimization;
(b) storing a pseudonymous identifier instead of a plain-text e-mail address;
(c) using HMAC with a secret key for the identifier;
(d) storing the HMAC key separately from the registration database;
(e) digitally signing registration tokens with Ed25519;
(f) keeping the Ed25519 private key only on a trusted system and excluding it
from the client Application;
(g) transmitting registration requests over a TLS-protected connection;
(h) limiting access according to the principle of least privilege;
(i) maintaining software components and reviewing security logs; and
(j) backing up and testing recovery to the extent necessary.
No method of storage or transmission can guarantee absolute security, but the
Controller seeks to keep risk at a reasonably low level.
13. USER RIGHTS
Depending on applicable law, a user may have the right to:
(a) receive information about processing;
(b) request access to the registration record;
(c) correct inaccurate data;
(d) request deletion;
(e) restrict processing or object to it;
(f) receive a portable copy of provided data where applicable;
(g) withdraw consent without affecting the lawfulness of processing before
withdrawal; and
(h) lodge a complaint with a competent data-protection authority.
Requests may be sent to privacy@talyh.com. To prevent disclosure of a record to another
person, the Controller may request reasonable proof of control over the e-mail
address or key. The Controller must not request more data than is necessary to
verify the request.
Where Georgian data-protection law applies, the user may contact the competent
Georgian state authority responsible for personal-data protection. Where the
GDPR applies, the user may also lodge a complaint with a supervisory authority
in the European Economic Area state of habitual residence, place of work, or
place of the alleged infringement.
14. CHILDREN
The Application and voluntary registration program are not specifically
directed to children below the age at which they may independently consent to
the relevant processing or enter into the relevant agreement under applicable
law. Where parental or guardian consent is required, registration must occur
only after that consent has been obtained.
15. PLUGINS AND THIRD-PARTY COMPONENTS
15.1. Third-Party Plugins may have their own network functions and data-
processing practices. This Policy does not describe the activities of
independent Third-Party Plugin developers.
15.2. Before installing a Plugin, the user should review its source,
permissions, license, and privacy policy.
15.3. An Official Plugin that begins collecting new categories of data must be
accompanied by an updated Policy or a separate notice before the processing
begins.
16. CHANGES TO THIS POLICY
16.1. The Controller may update this Policy when the Application, registration
system, providers, or applicable law changes.
16.2. A new version will be published at https://the.talyh.com/legal/privacy
with the update date. If a
change materially affects voluntary registration, the user will receive a
prominent notice before the change takes effect where required by law.
16.3. Adding telemetry, cloud storage, document synchronization, advertising,
or processing of document contents requires a prior update to this Policy and,
where necessary, separate consent.
17. LANGUAGE VERSIONS
17.1. This Policy is available in English and Russian. Both versions are
intended to convey the same meaning.
17.2. In the event of inconsistency, the English version shall prevail to the
maximum extent permitted by applicable law. This rule does not limit mandatory
user rights or statutory requirements concerning the language of a privacy
notice.
18. CONTACT
Questions and requests concerning personal data may be sent to:
Individual Entrepreneur Vitalii Talykh, trading as “Talyh Studio”
Address: 0162, Georgia, Tbilisi, Krtsanisi district, Ponichala-3 settlement, Building 5
E-mail: privacy@talyh.com
Website: https://talyh.com
END OF DOCUMENT
Previous editions stay available at permanent addresses. This is edition 1.0