Privacy Policy
Effective: 13 August 2026 · Last updated: 13 August 2026
InThink ("we", "us", "our") is a daily learning app that helps you sit with one thoughtful concept a day, keep private notes, and think through ideas with an AI helper called "Think". This policy explains what data we collect, how we use it, and the choices you have.
If you have any questions, email chaudharyhardik1106@gmail.com.
1. What we collect
We only collect what we need to run the service.
- Account — your email, name (if you provide one), a bcrypt-hashed password (never the plain text), the sign-in providers you use (email/password and/or Google), account creation date, and last sign-in date.
- App content you create — personal notes, daily cards shown to you, your review status on cards, and messages you send to the "Think" AI helper. This content is yours.
- Preferences — subject categories, timezone, and display settings.
- Usage data (limited) — server logs and short-lived rate-limit counters (e.g. how many Think messages you sent today) so we can prevent abuse.
We do not collect: location, contacts, phone number, camera, microphone, or advertising identifiers.
2. How we use your data
- To sign you in and keep you signed in.
- To show you the daily card and preserve your notes across devices.
- To send messages you write in "Think" to a large-language-model provider so the AI can respond, and to save the conversation so it stays in context for you.
- To prevent brute-force sign-in attempts and other abuse (rate limiting).
- To send transactional emails related to your account (password reset, security alerts). We do not send marketing emails without your opt-in.
- To compute your personal statistics (streak, cards reviewed) that only you can see.
We do not sell your data. We do not use your notes or Think conversations to train third-party AI models.
3. Who we share data with
We share data only with service providers we need to run InThink.
- MongoDB Atlas (or equivalent) — encrypted database storage of your account, notes, cards, and chat history.
- Google Sign-In — only if you choose to sign in with Google; receives your Google email and public profile to authenticate you.
- OpenAI / Anthropic / Google (via the Emergent LLM proxy) — the individual messages you send to Think and the current card or note they relate to, so the AI can respond.
- Cloud hosting — currently Emergent — encrypted server logs and application traffic.
We do not share your data with advertisers, data brokers, or analytics networks.
4. Where your data is stored
Your data may be transferred to and processed in the United States or other countries where our providers operate. We rely on standard contractual clauses and provider certifications as the legal basis for these transfers.
5. How long we keep your data
- Active accounts: as long as your account exists.
- After deletion: we remove your personal data within 30 days, except records we must keep by law for up to 90 days.
- Server logs: rotated within 30 days.
- Rate-limit counters: rotated within 24 hours.
6. Your rights and choices
- Access your data — Preferences inside the app.
- Correct your data — Preferences inside the app.
- Export your data — email us; you'll receive a machine-readable file within 30 days.
- Delete your data — email us; we'll delete your account and content within 30 days.
- Withdraw consent — stop using InThink at any time.
- Complain to a data-protection authority in your country.
If you sign in with Google, you can revoke InThink's access at myaccount.google.com/permissions.
7. Children
InThink is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect data from children in those age groups. If you believe a child has provided us data, email chaudharyhardik1106@gmail.com and we will delete it promptly.
8. Security
- Passwords are hashed with bcrypt — we never store plain text passwords.
- Sessions use JSON Web Tokens with a server-side secret.
- All traffic is served over HTTPS.
- We enforce rate limits on sign-in, register, and AI endpoints.
- Access to production systems is limited to authorised administrators.
9. Push notifications
If you enable push notifications, we store the device subscription token needed to deliver them. Turning notifications off in your device settings stops us from sending them; the token is removed within 30 days of your last use.
10. Cookies
InThink uses a small number of cookies and browser-storage entries strictly required to keep you signed in. We do not use advertising or analytics cookies.
11. Third-party links
The app may contain links to external websites. This policy does not apply to those sites; please read their own policies.
12. Changes to this policy
If we materially change how we handle your data, we will update this page and change the "Last updated" date at the top. For significant changes we will also notify you inside the app or by email.
13. Contact
Hardik Chaudhary — InThink
Email: chaudharyhardik1106@gmail.com
App: https://inthink.world