Privacy Policy
Last updated 2026-08-08

How Tohm handles your data.

Tohm is a book-launch checklist tool. You sign in with an email, enter a release date, and unlock a dated task list tied to your launch. This page lists exactly which fields we collect, what each one does, who receives a copy, and how to ask for it back or ask for it deleted.

Read this if: you want to know what is stored against your magic-link email, how long it stays, and where it goes when a Stripe checkout, a digest email, or a hosting log handle a slice of it.

Scope

What this page covers.

This Privacy Policy explains how Tohm(“Tohm”) collects, uses, and shares information when you sign in via the magic-link form on /login, submit your release date and tier choice on /start, complete a Stripe-powered one-time checkout, or work through your tasks inside the dated checklist. It also covers the small set of third-party services that handle slices of that data on our behalf.

Tohm is operated by the same team that built and ships it. We do not sell your information, and we do not run a newsletter list.

Data we collect

What Tohm collects from you.

We collect the smallest set of fields needed to deliver a personalized, dated checklist tied to your release date. The fields below are the full list — no address book, no purchase history beyond the single checkout, no device fingerprinting.

  • Email address. Collected from the magic-link form on /login and from the start form on /start. Used as your account identity and the destination for transactional email.
  • Release date. A single calendar date entered on the start form, stored as UTC midnight. Used to compute the due date for every task in your checklist.
  • Plan tier. One of 4-week free, 8-week one-time ($39), or 12-week one-time ($59). Stored alongside the Stripe checkout-session id and a stripeVerified flag that records whether the payment was completed.
  • Checklist state. Which static tasks are completed or skipped, the titles and due dates of any custom tasks you add, and the daily-digest delivery log (which dates we sent a due-task digest to your inbox).
  • Server logs.Standard hosting logs — IP address, user-agent, timestamps — retained briefly by Render to operate the platform. We do not link these logs to your account.
Data we deliberately do not collect

What Tohm does not collect.

  • No passwords. Tohm uses magic-link sign-in through better-auth. There is no password field, no password hash, and no password-reset flow.
  • No card numbers.Payments run through Stripe’s hosted checkout against the company’s Stripe Connect account. Stripe handles card entry; Tohm never receives, stores, or sees your card number.
  • No third-party marketing trackers. There is no Google Analytics, no Meta Pixel, no Hotjar, no advertising SDK. The only page-view counter is Polsia’s built-in analytics, which counts anonymous page views by slug and is injected at deploy time.
Use of data

How Tohm uses the data it collects.

Every field above is necessary to deliver the core service and is used inside that loop only. We do not use your email for drip campaigns, retargeting, or a newsletter list. We do not resell or share your information with third parties for their own use.

  • Sign you in. Your email is the key the magic-link sends against.
  • Generate your checklist. Your release date and plan tier determine which static tasks belong in your list and the due date each task carries.
  • Send transactional email. Sign-in links, Stripe payment receipts, and a single daily digest email listing the tasks due today.
Third parties

Third-party services that receive a slice of your data.

Tohm runs on a tight set of vendors — one for payments, one for transactional email, one for hosting, and a slug-based analytics counter. The list below names each one and the slice of data it receives.

  • Stripe (Connect). Processes the 8-week and 12-week one-time checkouts against the Tohm Stripe Connect account. Receives whatever you enter into the Stripe-hosted checkout form (name, billing address, card details) under Stripe’s privacy policy. Tohm receives back only the checkout-session id and a verified/unverified flag.
  • Polsia email proxy.Relays the magic-link sign-in message, the Stripe payment receipt, and the daily due-task digest to your inbox. The proxy sees the same email contents we compose for you — no additional tracking.
  • Render (hosting).Hosts the application and the managed database. Holds the application data described in the “What Tohm collects” section and standard request logs (IP, user-agent, timestamp).
  • Polsia platform analytics. Records anonymous page-view counts keyed by URL slug, injected at deploy time. No per-user profile, no cookies, no cross-site identity.
Cookies

Cookies on Tohm.

Tohm sets exactly one cookie: a signed, httpOnly session cookie written by better-auth when you complete a magic-link sign-in. We do not set tracking cookies, advertising cookies, or any third-party cookies. The analytics counter described above does not use cookies.

Retention

How long Tohm holds your data.

Your account, plan tier, release date, and checklist rows are kept for as long as your account exists. Server logs on Render rotate on the host’s standard schedule and are not retained by Tohm beyond what Render keeps by default. Stripe retains payment records under their own retention rules.

Your rights

Your rights over the data we hold.

You can ask for a copy of the data Tohm stores against your account, ask us to delete it, or correct your release date by emailing booklaunchplan@polsia.app. Requests are usually answered within a few business days. The current build does not expose a self-serve delete button inside the app, so the email route is the honest path.

Children’s privacy

Children’s privacy.

Tohm is a book-launch planning tool aimed at adult indie and nonfiction authors. It is not intended for children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child’s email is stored against an account, mail us and we will delete the account.

Changes to this policy

How changes to this page are handled.

If we update this Privacy Policy in a way that changes what we collect, how we use it, or who receives it, the “Last updated” date at the top of this page changes to the revision date. Continued use of Tohm after a posted change means you have read the new version.

Questions about this page?

Mail us — we read every message.

The fastest way to ask about a field on this page, request a copy of your data, request deletion, or correct your release date is the address on the right. It goes to the same team that builds Tohm, and replies usually arrive within a business day.

Privacy & data contactbooklaunchplan@polsia.app
Last updated 2026-08-08 · built and operated by the Tohm team.