Privacy Policy
Last updated: September 25, 2026.
1. Who We Are
thinqOS is a product of AI4Outcomes, operated by DeMers IT Inc., a company incorporated in Ontario, Canada. This policy explains what we collect, how we use it, and your rights under applicable privacy law. For users in Canada this includes PIPEDA and provincial privacy laws (such as Quebec's Law 25 and the BC and Alberta PIPA); for users in the EU and UK it includes the GDPR and UK GDPR; for users in the United States it includes state privacy laws such as the CCPA and CPRA.
2. Information We Collect
We collect the following categories of information:
- Account data, through Clerk: your email, display name, and authentication tokens.
- Mind data: everything held in your mind graph, including beliefs, goals, skills, entities, preferences, relationships, and the evaluations attached to them. This is the core of the product.
- Conversation history: your threads, messages, and attachments.
- Uploaded content: documents you upload.
- Model usage data: token counts, the providers used, and costs.
- Payment and transfer data: the billing country and state or province recorded by our payment provider when you make a card purchase, the last known billing location on your account, and, where you send credits to another user, the counterparty, amount, any note, and any report that a transfer was not authorized by you.
- Technical data: IP address, browser, device, and timestamps.
3. How We Use It
- To run the platform: storing, retrieving, and attending to your cognitive state.
- To route AI requests to provider APIs on your behalf.
- To bill accurately, based on token usage.
- To record credit transfers between users, notify both parties, and support regulatory analysis of where transfers occur.
- To detect and prevent fraud and abuse, including automated review of transfer patterns such as circular transfers and transfers structured to avoid limits.
- To debug and improve the service.
We do not sell your data, we do not use your cognitive state to train third-party models, and we do not share your data with advertisers. For the purposes of the CCPA and CPRA, we do not "sell" or "share" personal information as those terms are defined.
3.1 Human Review of Your Content
thinqOS is operated by a small team and is in early-stage development. Authorized thinqOS personnel may read, review, or otherwise access your Mind data, conversation history, uploaded documents, and other content you store on the platform. We do this for the following purposes:
- Support: responding to help requests and investigating reported issues.
- Debugging: diagnosing and resolving technical failures, bugs, and errors.
- Security: investigating potential security incidents and protecting the platform.
- Service improvement: evaluating and improving service quality, functionality, and reliability.
Who can access your data. Access is restricted to named thinqOS personnel holding a platform administrator role, with a legitimate operational need. We maintain an internal list of authorized personnel and review it periodically.
Account impersonation. For debugging and support purposes, authorized personnel may use an impersonation mechanism that allows them to view and interact with your account environment as if they were logged in as you. This is used solely for diagnosing and resolving technical issues. Every impersonation session is recorded in an internal audit log capturing who accessed the account, when the session started and ended, and from where. You will not necessarily be notified before or during an impersonation session, as the practice is reactive to operational needs.
What we do not do. We do not use your Mind data, conversations, or uploaded content to train third-party AI models. We do not share your data with advertisers. We do not sell your data.
Your content stays inside AI4Outcomes. Apart from the sub-processors listed in Section 5, which process it on our instructions, and the services you connect yourself, which receive it only when you or your agents use that connection, we do not send your content to anyone outside our company, and we do not disclose it to third parties except where the law requires it.
What this means for you. In practice this access is occasional and purposeful: someone looks when something is broken, when you have asked for help, or when we are investigating a problem affecting the platform. It is not routine reading, and nobody here is browsing your Mind for interest. That said, thinqOS is early, and the honest guidance is this: treat what you put into thinqOS as something a small number of people at our company could potentially see. If a particular document, conversation, or belief would be a real problem for anyone here to read, it is better kept out of the platform for now. We are building the technical controls that will remove this access entirely, and until they exist we would rather tell you plainly where we stand than let you assume a level of privacy the product does not yet enforce.
Limits of our current controls. Impersonation sessions are audit-logged, but administrative access to platform data through internal tooling and direct database access is not yet comprehensively logged. We are working toward broader audit coverage and reduced-privilege debugging tools. These are not yet fully implemented. If you have questions about who can access your data, contact us at [email protected].
4. Where Your Data Lives
- Neon Postgres for application data, isolated by identity.
- Google Cloud Run for compute.
- Clerk for authentication and session management.
- AI provider APIs for inference: the providers listed in section 5. Which provider receives a given prompt depends on the model chosen for that agent or conversation. Each provider has its own data-handling policy.
- Ask thinqOS connects you to our Help agent without requiring an account. Your messages and replies are stored on our servers under a visitor identifier. A token stored by the embedded chat in your browser lets it recognize a return visit on that browser when storage is available. The agent can remember facts you share in the conversation. Ask also receives the public page's title, path and published text to help answer questions about it; our website does not send form inputs, URL query parameters or private commercial pages as page context. "Forget me" deletes this visitor conversation and its visitor-specific memory records, revokes its recognition token, and clears the browser token after the server confirms deletion. Conclusions extracted into the agent's Mind are withdrawn from use, but some inactive internal records can remain. This control does not erase every internal record. If deletion fails, the chat keeps the token so you can retry and does not report success. The backup and provider retention provisions below still apply.
5. Third Parties and Sub-processors
We use the following sub-processors to operate the platform. This is the complete current list. The code that talks to each of them is checked against this page in our automated tests, so a new provider cannot ship without appearing here.
- Clerk, for authentication and session management.
- AI model providers, for inference: Anthropic, OpenAI, Google, Fireworks AI, OpenRouter, and xAI. Your prompts and conversation context are transmitted to the provider behind the model in use for that agent or conversation, under that provider's terms, so review each provider's privacy policy. Where an agent is set up to choose between models, a small routing model reads the message first to make that choice, and its provider can differ from the one that answers. OpenRouter routes requests to further model hosts under its own policy. If you bring your own provider key, that relationship is yours directly.
- Cohere, for reranking search results over your own knowledge, where that feature is enabled.
- ElevenLabs, for voice synthesis and transcription, where you use voice features.
- Tavily, for web search an agent performs on your behalf; the search query is transmitted.
- skills.sh, for searching the public skill catalog when you search for skills; the search text is transmitted.
- Google Cloud Platform, for hosting.
- Neon, for managed Postgres.
- Cloudflare, for the public website, DNS, and the sign-up bot check (Turnstile).
- Sentry, for error reporting; an error report can include your account identifier and the request that failed.
- Resend, for transactional email.
- Stripe, for payments when you buy a plan or credits; we never store card numbers.
Services you connect yourself are not on this list, because you choose them. When you or your agents connect Gmail, Google Workspace, HubSpot, Xero, Slack, GitHub, an MCP server you register, a Daytona sandbox under your own account, an AI tool such as HeyGen or ElevenLabs, or an AI provider key you bring, thinqOS sends data to that service only when the connection is used, under that service's own terms. Those are your relationships with those companies. You can see every connection in your account and disconnect any of them at any time.
We will give notice to registered users before adding a new sub-processor that materially changes how your data is handled. Enterprise customers may request a data-processing agreement (DPA) at [email protected].
6. International Users, Legal Bases, and Transfers
thinqOS is operated from Canada, and your data is processed in Canada and the United States, including by the sub-processors listed above. Where the GDPR or UK GDPR applies to you, our legal bases for processing are the performance of our contract with you (to provide the platform), your consent where we request it, and our legitimate interests in operating, securing, and improving the service. Cross-border transfers out of the EU or UK rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. If you are in Quebec, additional rights and French-language obligations under Law 25 apply, and you may contact us to exercise them.
7. Your Rights
Under applicable privacy law, including PIPEDA and provincial Canadian laws, and, where they apply to you, the GDPR, UK GDPR, and US state privacy laws, you have the right to:
- access your data, by exporting your mind graph as JSON;
- correct your data, by editing any node in your mind graph;
- delete your data; on account deletion we begin purging your Mind within 30 days. Residual copies may briefly persist in encrypted backups, which are cleared on the backup cycle, and in third-party AI provider systems under their own retention policies;
- withdraw consent, by deleting your account;
- where the GDPR applies, additionally restrict or object to processing, request portability, and lodge a complaint with your supervisory authority.
Where the GDPR applies, you have the right to object to processing based on our legitimate interests, including the human review of your content described in Section 3.1, on grounds relating to your particular situation. To exercise this right, contact us at [email protected].
To exercise any of these rights, contact us at [email protected].
8. Data Retention
We keep each category of data only as long as needed:
- Account data: for the life of your account, then deleted within 30 days of account closure.
- Mind data, conversation history, and uploaded content: until you delete them or close your account.
- Model usage data, such as token counts, providers, and costs: up to 24 months, for billing and accounting.
- Payment and transfer data: up to 7 years, for fraud prevention, dispute resolution, accounting, and regulatory purposes.
- Technical and security logs: up to 12 months.
- Access-request data: raw access-request PII is retained for up to 12 months after the final decision, may be deleted earlier on verified request, and is reduced to non-PII audit identifiers after purge.
- Backups: on a rolling basis, purged within 30 days.
Anonymized, aggregated data may be kept longer for service improvement and abuse prevention.
9. Cookies and Local Storage
We use a Clerk session cookie for authentication and a session-storage key that tracks an active admin impersonation session. We use no analytics, tracking, or advertising cookies.
10. Security
- Clerk handles password hashing and authentication-token security.
- All traffic is encrypted in transit with TLS.
- Neon provides encryption at rest and in transit.
- We do not yet encrypt individual cognitive nodes at rest. End-to-end encryption of the Mind is on the roadmap, with no committed timeline, and we mark it as planned rather than claiming it today.
11. Data Breach Notification
If a breach of our security safeguards creates a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada as required under PIPEDA, without undue delay. Where the GDPR or UK GDPR applies, we will also notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach, and affected individuals where required.
12. Children's Privacy
thinqOS is intended for adults. You must be at least 18 years old to use it, and it is not directed to children. If you believe someone under 18 has created an account, contact us at [email protected].
13. Changes to This Policy
We may update this policy from time to time. "Material changes" means changes to the data we collect, how we use or share it, retention, or your rights. We will give at least 30 days' notice of material changes by email to registered users and in-product. Continued use after the notice period constitutes acceptance.
14. Contact
Questions about this policy? Contact us at [email protected].