String Theory
Who it's for The views Boards Customize Templates & skins Extras Together Sharing Pricing

Privacy

Privacy Policy

Version 2026-08-24 · Effective 2026-08-24 · Terms of Service

String Theory is made by Grumpy Gopher, LLC, a Montana limited liability company. This policy says what information we handle, where it lives, and what you can do about it. The short version: we collect what the product needs to work, we don't sell it, we don't run ads, and you can export or delete everything yourself from inside the app.

What we collect, and why

Your account. Sign-in is handled by Clerk, our authentication provider. We get your email address and the name you gave Clerk, and we use them to run your account, deliver invitations you send, and contact you about the service. Sign-in codes are emailed by Clerk; we never see or store a password.

Your content. Your boards, entities, connections, notes, tags, and uploaded media are stored so we can show them back to you and the people you choose to share with. We don't mine your content, train AI on it, or use it for anything except running the service. The people who operate String Theory can technically access stored content and do so only to run the service—debugging a problem you've reported, or acting on an abuse report.

Uploaded images. Images you upload are re-encoded in your browser before upload, which removes embedded metadata such as camera model and GPS location.

Operational logs. The service keeps technical logs (requests, errors, timings) in Microsoft Azure to keep it running and debuggable. Logs are about the service's behavior, not a record of your content.

Feedback sent from inside the app

String Theory has a "Send feedback" form. Because it is the one place in the product where you can hand us a picture of your own case material, what happens to it is worth stating precisely:

  • What we keep. What you type, which account sent it, which screen you were on, and the app version.
  • Screenshots and technical details are optional, and asked for every time. There is no remembered preference and no "don't ask again". Nothing is captured in the background—a screenshot exists only because you attached one, and you see exactly what will be sent before you send it. Technical details are counts and view state (how many items are on the board, which screen you were on); never the names, notes, or tags of anything in your case.
  • A person reads every submission. Nothing is filed automatically.
  • Where it can end up. If we act on a report, we copy it into our issue tracker, Microsoft Azure DevOps, under a reference like FB-1234—without your name or email address. That copy is a deliberate human decision, made per submission.
  • How long attachments last. Screenshots and technical details are deleted 90 days after we close a report. The written report is kept.

What's stored on your device

The app stores two kinds of things in your browser, and no more:

  • Sign-in state, set by Clerk. Cookies (names beginning __client_uat, __clerk_db_jwt, and after sign-in __session and __client) plus one localStorage entry (__clerk_environment). These exist so you stay signed in; they are not used to track you across other sites.
  • Your own preferences, in localStorage keys beginning st_: which project and board you had open, view filters and tags you've set, and your project's appearance settings. These never leave your device as tracking data—they're conveniences the app reads back. They are removed when you sign out or when the app loads without an active session, so they don't linger on a shared machine.

There is no advertising, no cross-site tracking, and no third-party analytics inside the app. Because nothing stored is beyond sign-in state and your own preferences, the app doesn't show a cookie banner.

If you visit a shared page

Boards can be published as read-only pages at links like app.stringtheoryconnect.com/s/…. If you open one without an account: the page loads its content and short-lived links to its media from us, and our authentication provider (Clerk) sets its sign-in-state cookies—the page needs them to tell whether a restricted share's visitor is signed in. No analytics run on shared pages, and nothing about your visit is sold or profiled. Shared content is published by a String Theory user, not by us; every shared page carries a report link if you believe content on it shouldn't be there.

This website

The marketing site you're reading now uses Cloudflare Web Analytics, a cookie-free measurement tool: it stores nothing on your device and shows us only aggregate counts—how many visits, which pages, which countries, which sites linked here. It cannot identify you and we couldn't recognize you in it if we tried. Email addresses submitted through the early-access forms are delivered to us by Formspree, a form-handling service, and are used solely to contact you about early access.

Who else touches the data (subprocessors)

  • Clerk — authentication and the emails it requires (sign-in codes, invitations).
  • Microsoft Azure — hosting: the database, file storage, the servers, operational logs, and our issue tracker.
  • Neo4j Aura — the graph database storing entities and their connections.
  • Cloudflare — aggregate, cookie-free analytics on this marketing site only.
  • Formspree — delivers this site's early-access form submissions to us.

Each processes data only to provide its service to us, under its data-processing terms. We don't sell personal information to anyone, and we don't share it with anyone else except as required by law.

Retention and deletion

Your content stays until you delete it, and your account stays until you delete it. Both are yours to do from inside the app: Account → Export gives you a zip of everything you own, and Account → Delete removes your account and every workspace you own—content, media files, and graph data. Deleted content disappears from the live systems immediately; copies in our operational backups age out with those backups over a short period. If you own a workspace that other people still collaborate in, deletion asks you to resolve that first rather than destroying shared work.

Your rights

Wherever you are, we honor the substance of modern privacy law: you can access and export your data (in-app), correct it (it's your content—edit it), delete it (in-app), and ask us questions or make any other request at info@stringtheoryconnect.com. If you're in a jurisdiction with specific statutory rights (the EU/UK, California, and others), those requests go to the same address and we'll handle them within that law's timelines.

Age

String Theory is for people 13 and older; creating an account requires confirming that. We don't knowingly collect information from children under 13—if you believe a child under 13 has an account, contact us and we'll close it.

Changes

If we make a material change to this policy, we'll bump the version above and the app will tell you before the change applies to you. We won't quietly start collecting things this page says we don't.

Contact

Grumpy Gopher, LLC · info@stringtheoryconnect.com

← Back to the home page

info@stringtheoryconnect.com · Templates · Guides · Privacy · Terms · Refunds

© 2026 Grumpy Gopher, LLC. String Theory is a Grumpy Gopher production. We doubt if Grumpy would approve.