Privacy Policy

ThinkingRoot stores memory on behalf of the people who build on it. This explains exactly what we hold, where it lives, and what you can demand of us.

Effective 21 July 2026Version v2026-07-21

1. Our two roles

ThinkingRoot plays two different roles, and the distinction decides which rights apply to whom. Reading this section first will make the rest of the document make sense.

RoleDataWho to ask
ControllerYour account with us: email, handle, organisation, billing records, and how you use the Console.Us, directly. This policy governs it.
ProcessorCustomer Content — the memories, documents and facts you or your end-users store in a project.The customer who operates the application. We act only on their instructions.

If you are an end-user of an application built on ThinkingRoot and you want your memories corrected or deleted, the operator of that application is your first point of contact. We will help them act on your request, and our Data Processing Addendum obliges us to.

2. What we collect

The complete list. If something is not here, we do not collect it.

DataWhyNotes
Email addressAccount creation, verification, service notices, billing receipts.Stored once per account, plus a copy per linked SSO provider.
Handle and display nameIdentifying you in the Console and within your organisation.Chosen by you.
PasswordAuthenticating you.Stored only as an Argon2id hash with a per-password random salt. We cannot read it. Accounts created through Google or GitHub have no password at all.
Session and API tokensKeeping you signed in; authenticating SDK and API calls.Stored only as BLAKE3 hashes. The plaintext is shown to you once and never persisted.
Organisation and roleTeam membership and access control.
Billing recordsSubscriptions, invoices, credit top-ups, tax.Amounts, status and Stripe identifiers only.
Audit logSecurity, abuse investigation, and answering your own 'who did what' questions.Actor, action, target, result, timestamp.
Site analyticsUnderstanding which pages are read.A salted hash of your IP address, approximate country/region/city, referring page, and path. No cookie, no persistent client-side identifier, no user-agent.

Two things we deliberately do not do. We do not record your IP address or browser user-agent against your login sessions — the database columns exist but we pass nothing into them. And we never see, transmit or store payment card numbers: checkout is hosted entirely by Stripe, and no card field of any kind exists anywhere in our systems.

On analytics we would rather be precise than flattering. We never store your raw IP address; we hash it with a salt that rotates every day, so the identifier cannot follow you from one day to the next. That makes re-identification impractical, but not impossible in principle — so we treat the result as personal data and list it above with everything else rather than calling it anonymous.

3. Your content

Customer Content is whatever you or your end-users put into a project: documents you compile, memories you remember, facts extracted from them, entities, relationships and the queries used to retrieve them. Its contents are determined entirely by you. ThinkingRoot does not classify or filter it, so it can contain any category of personal data — including sensitive data — if you choose to put that there.

Each project runs in its own isolated container with its own database. Within a project, each end-user you scope gets their own separate memory store. This is a boundary in the architecture, not a filter applied to a shared pool.

We do not use Customer Content for any purpose other than operating the service for you. Content is never shared, pooled or made reachable across tenants.

4. AI processing and training

Producing memory from your content requires sending parts of it to a large language model for extraction and synthesis. We use Microsoft Azure OpenAI Service for this. Query text and the content being processed are sent; the results come back into your project.

We do not train or fine-tune any model on Customer Content, and our AI sub-processors are contractually prohibited from training on data we send them.

One consequence worth stating plainly, because most vendors leave it vague: embedding and reranking — the operations that run over every memory you store — are performed by models that ship inside our own engine and execute on our own infrastructure. No third party receives your memory text in order to embed or rank it.

ThinkingRoot does not make automated decisions that produce legal or similarly significant effects about anyone. If you build such a decision on top of our output, you are responsible for the disclosures and safeguards that attach to it, and our Data Processing Addendum commits us to giving you the information you need.

5. Legal bases (EEA and UK)

PurposeBasis
Creating and operating your accountPerformance of a contract (Art 6(1)(b))
Processing Customer ContentOn the instructions of our customer, who determines the basis
Billing, invoicing and tax recordsContract, and legal obligation (Art 6(1)(c))
Security, abuse prevention, audit loggingLegitimate interests — keeping the service and its users safe (Art 6(1)(f))
Service and security emailsContract
Marketing emailsConsent (Art 6(1)(a)), withdrawable at any time
Analytics cookies and measurementConsent

6. Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it only to the sub-processors that run the service, each under a written contract that holds them to the obligations in this policy.

The complete, current list — with the purpose and processing location of each — is published at thinkingroot.com/subprocessors. You can subscribe there to be notified before we add a new one.

We may also disclose data where we are legally compelled to, or to establish or defend legal claims. Where we are permitted to tell you, we will.

7. International transfers

ThinkingRoot is operated from India and its infrastructure runs in the United States. If you are in the EEA, the UK, or another region with transfer restrictions, your data will be processed outside it.

For transfers out of the EEA and UK we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where applicable, and we carry out a transfer impact assessment. Where a sub-processor is additionally certified under the EU–US Data Privacy Framework we treat that as a secondary safeguard rather than the primary one, so that a change in its status does not interrupt our lawful basis. Write to us for a copy of the clauses relevant to your data.

8. How long we keep things

Customer Content is retained for as long as your project exists. You can delete individual memories or whole sources at any time, and doing so removes the underlying records and rebuilds the search indexes so that deleted material stops being retrievable.

We back projects up roughly every five minutes to encrypted off-host storage, keeping the most recent snapshot. Deleted content therefore stops appearing in backups within approximately one backup cycle.

What happens when you close your account, stated exactly. You must first delete your projects, which removes the Customer Content in them. We then deactivate your account and pseudonymise its record: your email address and handle are overwritten with non-identifying placeholders and your password hash is erased. Active sessions and tokens are revoked and team memberships are removed. We retain the pseudonymised account row, billing records, and audit-log entries — billing records because tax law requires it, audit entries because they are our security record and a customer's own evidence of what happened in their organisation.

Consent records outlive the data they relate to: we keep proof of what you agreed to, and when, so that we can demonstrate we had the right to process it. Site analytics rows are kept in aggregate.

9. Your rights

Wherever you live, you may ask us to:

  • Access — get a copy of the personal data we hold about you.
  • Correct — fix anything inaccurate.
  • Delete — erase your data, subject to the retention rules above.
  • Port — receive your data in a machine-readable format.
  • Object or restrict — challenge processing we base on legitimate interests.
  • Withdraw consent — at any time, without affecting what was lawful beforehand.
  • Complain — to us, and to your supervisory authority.

Email [email protected]. We respond within 30 days, and we will not charge you or treat you differently for asking. If your request concerns memories held inside an application built on ThinkingRoot, we will route it to the operator of that application, who controls that data.

10. Regional notices

EEA and UK.You may lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office. We ask that you raise it with us first — we would rather fix it than litigate it.

India. Under the Digital Personal Data Protection Act 2023 you may access, correct, complete, update and erase your data, nominate another person to exercise your rights, and complain to the Data Protection Board of India. Our grievance channel is [email protected]; we respond well inside the 90-day statutory ceiling. This notice is available in English and in other Eighth Schedule languages on request.

United States.Residents of California and the twenty-plus other states with comprehensive privacy laws have rights to know, delete, correct, and appeal a refusal. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no “Do Not Sell or Share” mechanism to offer — we would rather say that plainly than post a link that does nothing. We honour Global Privacy Control signals. Where we handle personal information on a business customer's behalf we act as a service provider and are contractually barred from using it for our own purposes.

Other regions. Singapore, Japan, Australia, Canada and Brazil residents have equivalent rights under their local law; the same contact address reaches us.

11. Security

  • All traffic is encrypted in transit with TLS. Our origin servers accept connections only from our edge network, and are not reachable directly from the public internet.
  • Passwords are hashed with Argon2id at OWASP-recommended parameters. Session and API tokens are stored only as BLAKE3 hashes with 192 bits of entropy.
  • Connector access tokens are encrypted at rest with XSalsa20-Poly1305 authenticated encryption. Plaintext never reaches the database.
  • Project secrets use sealed-box asymmetric encryption: the component that stores them holds only the public key and is cryptographically incapable of reading them back.
  • Each project is isolated at the container boundary with its own database volume, and each scoped end-user gets a separate store within it.
  • Our infrastructure providers encrypt data at rest on the underlying storage.

No system is perfectly secure. If you find a vulnerability, please report it to [email protected] — we will respond quickly and we will not pursue good-faith researchers. If a breach affects your personal data we will notify you and the relevant authorities within the time limits the law sets.

12. Cookies and measurement

We use one strictly necessary cookie to keep you signed in. That is the only cookie set without your consent, because the service cannot work without it.

Analytics measurement runs only if you accept it. Our banner offers accept and reject as equally prominent single clicks, nothing is pre-selected, and rejecting means no measurement request is made at all. You can change your mind at any time from the same control, and your choice is remembered for twelve months.

We do not use advertising cookies or third-party trackers.

13. Children

ThinkingRoot is for developers and is not directed at children. You must be at least 16, or the age of digital consent where you live if that is higher, to hold an account. We do not knowingly collect data from children; if you believe a child has given us data, contact us and we will delete it.

14. Changes to this policy

Every version of this document is numbered and dated, and we keep the previous ones. If we make a material change we will email account holders before it takes effect. This policy was last updated on 21 July 2026 and is next scheduled for review by 21 July 2027.

15. Contact

Naveen Kumar, sole proprietor, trading as ThinkingRoot is the controller of the personal data described in this policy.

ReasonAddress
Privacy, data rights[email protected]
Grievances (India)[email protected]
Security reports[email protected]
Postal[POSTAL ADDRESS — SEE README BEFORE PUBLISHING]

We keep every previous version of this document. If you need the text that was in force on a particular date, write to [email protected] and we will send it.