1. Who we are
Thincker (“we”, “us”, “our”) is a web application that helps users create AI-assisted slideshows. This policy explains what personal data we collect, why we collect it, and your rights under applicable data protection law including the EU General Data Protection Regulation (GDPR).
For privacy questions, contact us at privacy@example.com.
2. Data we collect
| Data | Why | Legal basis |
|---|---|---|
| Email address | Account creation and login | Contract |
| Presentation content you create | Core service — storing and generating your slides | Contract |
| Photos and audio recordings you capture | Core service — attaching photos or voice notes to your notes | Contract |
| AI usage metrics (token counts, model used) | Billing, abuse prevention, capacity planning | Legitimate interest |
| Page views and feature usage events | Product analytics (PostHog) — only with your consent | Consent |
| IP address (server logs) | Security, abuse prevention | Legitimate interest |
We do not sell your data, run advertising, or share it with third parties except the sub-processors listed below.
Photo and audio capture.If you use the app’s capture feature to attach a photo or voice recording to a note, that file is uploaded to our storage provider under the same terms as any other content you create. Voice recordings are automatically transcribed to text; the transcript is kept indefinitely alongside your note, but the original audio file is automatically deleted 90 days after upload. Photos are retained indefinitely, tied to your account, like other content you upload.
3. Sub-processors and third parties
- Neon — database hosting. Your account details and content are stored in their infrastructure (AWS, US East). Neon Privacy Policy
- Groq— AI inference for content generation. Your prompts and generated content are sent to Groq’s API for processing. Groq Privacy Policy
- PostHog — product analytics (only if you consent). No personal data is shared in analytics events. PostHog Privacy Policy
- Vercel — web hosting and edge functions. Processes request data as part of serving the application. Vercel Privacy Policy
4. Cookies and local storage
| Name | Purpose | Duration | Essential? |
|---|---|---|---|
| better-auth.* | Authentication session | Session / 1 week | Yes |
| gdpr_consent | Your cookie preference choices | 1 year | Yes |
| ph_* | PostHog analytics session & distinct ID | 1 year | No — analytics consent |
| app-store-* | Local UI state (presentation draft) | Session | Yes |
5. Data retention
- Account data is retained for as long as your account exists.
- Presentations are deleted immediately when you delete them.
- AI usage logs are retained for 12 months for billing and abuse review.
- Course and lesson engagement records are retained for 18 months.
- Server access logs are retained for 30 days.
6. Your rights
Under GDPR you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — delete your account and all associated data from your account settings
- Portability — export your presentations via the Export function
- Object — opt out of analytics at any time from the cookie preferences panel
- Withdraw consent — change your cookie preferences at any time in the footer
To exercise any right, email privacy@example.com. We respond within 30 days.
7. Security
All data is transmitted over HTTPS. Access to your content is enforced by the application on every request, checking your session against the owner and collaborator records for that item. We do not store payment card data. Authentication is handled by Better Auth; passwords are salted and hashed (scrypt) and are never stored in readable form.
8. Changes to this policy
We may update this policy occasionally. Significant changes will be notified via email or an in-app notice. The “Last updated” date at the top will always reflect the latest revision.