Privacy Policy
Last updated: June 2026.
1. Who We Are
thinqOS is a product of AI4Outcomes, operated by DeMers IT Inc., a company incorporated in Ontario, Canada. This policy explains what we collect, how we use it, and your rights under Canadian privacy law, including PIPEDA.
2. Information We Collect
We collect the following categories of information:
- Account data, through Clerk: your email, display name, and authentication tokens.
- Mind data: everything held in your mind graph, including beliefs, goals, skills, entities, preferences, relationships, and the evaluations attached to them. This is the core of the product.
- Conversation history: your threads, messages, and attachments.
- Uploaded content: documents you upload.
- Model usage data: token counts, the providers used, and costs.
- Technical data: IP address, browser, device, and timestamps.
3. How We Use It
- To run the platform: storing, retrieving, attending to, and consolidating your cognitive state.
- To route AI requests to provider APIs on your behalf.
- To bill accurately, based on token usage.
- To debug and improve the service.
We do not sell your data, we do not use your cognitive state to train third-party models without your explicit consent, and we do not share your data with advertisers.
4. Where Your Data Lives
- Neon Postgres for application data, isolated by identity.
- Google Cloud Run for compute.
- Clerk for authentication and session management.
- AI provider APIs (Anthropic, OpenAI, Google) for inference. Each provider has its own data-handling policy.
5. Third Parties
- Clerk, for authentication and session management.
- Anthropic, OpenAI, and Google, for inference. Your prompts and conversation context are transmitted to the providers you select, so review each provider's privacy policy.
- Google Cloud Platform, for hosting.
- Neon, for managed Postgres.
6. Your Rights
Under PIPEDA and other applicable Canadian privacy law, you have the right to:
- access your data, by exporting your mind graph as JSON;
- correct your data, by editing any node in your mind graph;
- delete your data; full account deletion purges your Mind within 30 days;
- withdraw consent, by deleting your account.
7. Cookies and Local Storage
We use a Clerk session cookie for authentication and a session-storage key that tracks an active admin impersonation session. We use no analytics, tracking, or advertising cookies.
8. Security
- Clerk handles password hashing and authentication-token security.
- All traffic is encrypted in transit with TLS.
- Neon provides encryption at rest and in transit.
- We do not yet encrypt individual cognitive nodes at rest. End-to-end encryption of the Mind is on the roadmap, and we mark it as planned rather than claiming it today.
9. Children's Privacy
thinqOS is not intended for anyone under 16. If you believe a child has created an account, contact us at legal@thinqos.com.
10. Changes to This Policy
We will announce material changes by email to registered users. Continued use after the notice period constitutes acceptance.
11. Contact
Questions about this policy? Contact us at legal@thinqos.com.