ThinkRoom
Data Protection & Privacy

Privacy Policy

At ThinkRoom, your privacy and data security are foundational. This Privacy Policy explains how we collect, use, store, and safeguard your personal information and thinking workspace data.

Last Updated: August 23, 2026
Effective Date: August 23, 2026

1. Information We Collect

We collect information to provide, maintain, and improve the ThinkRoom platform. The types of information we collect include:

  • Account Data: Name, email address, profile preferences, and authentication tokens when you register.
  • AI Workspace Data: Decision prompts, perspective notes, assumptions, trade-off comparisons, and session histories you generate during your thinking workflow.
  • Technical & Usage Data: IP address, browser type, operating system, device diagnostics, page views, and interactions.

2. Account Information

When you sign up for ThinkRoom, we store your basic account details to identify you, manage your access, personalize your experience, and send necessary transactional notifications (such as password reset links or security alerts).

3. AI Workspace Data

Your prompts, problem definitions, assumptions, and decision outputs are private to your account. We process your inputs through secure AI APIs strictly to produce perspective analyses, challenge assumptions, and generate structured decision models.

We do not sell your personal data or decision contents to third parties, and we do not use your private workspace sessions to train public AI models.

4. Usage Analytics

We use aggregated, anonymized usage telemetry to understand feature usage patterns, optimize performance, fix software bugs, and enhance user experience across the platform.

5. Cookies & Local Storage

ThinkRoom uses essential cookies and local browser storage to maintain session state, authenticate your user account, remember theme preferences (such as dark mode), and protect against automated security threats (e.g. Turnstile anti-bot verification).

6. How We Use Data

We use collected information solely for legitimate business purposes:

  • Providing, operating, and delivering the ThinkRoom application.
  • Executing multi-perspective AI agent analysis for your decision workflows.
  • Preventing fraud, abuse, and unauthorized access.
  • Fulfilling legal obligations and enforcing our Terms of Service.

7. Data Storage & Security

All data is encrypted in transit using industry-standard TLS protocols and encrypted at rest in managed cloud infrastructure. We implement strict access controls, security patching, and vulnerability monitoring to protect your information against unauthorized access.

8. Third-Party Services

We partner with trusted, privacy-compliant infrastructure providers to power ThinkRoom. These services process data only as necessary to provide their specific functionality:

  • Supabase: Encrypted database hosting and user authentication infrastructure.
  • Google Gemini API: Large language model processing for multi-perspective decision analysis.
  • Vercel: Application hosting, edge delivery, speed insights, and telemetry.
  • PostHog / Analytics: Privacy-conscious product analytics and performance monitoring.

9. User Rights & Data Control

Depending on your location (including rights under GDPR or CCPA/CPRA), you have the right to access, rectify, export, or request deletion of your personal data.

10. Permanent Account Deletion

Self-Service Deletion

You can permanently delete your ThinkRoom account and purge all associated decision history and workspace sessions at any time directly from the Settings page. Account deletion is permanent and cannot be undone.

11. Contact Information

If you have questions, data inquiries, or privacy concerns, please contact our privacy compliance team at:

ThinkRoom Privacy Team