Legal

Privacy Notice

Your plans contain the most sensitive thing an early venture owns: its thinking. This notice states exactly what we hold, why, for how long, and what you can make us do about it — with export and deletion available to you directly, not on request.

Effective 31 August 2026 · Version 1.0

1.Scope and approach

This notice explains what personal data Thinking Plans collects, why we collect it, how long we keep it, who else touches it, and what you can make us do about it. It covers the website, the planning engine, share links and exports.

We apply one standard everywhere rather than the minimum each country allows. That means data minimisation by default, purpose limitation, no sale or sharing of personal data, no advertising profiling, and the same export and deletion rights for every user regardless of where they live.

Where a specific law gives you stronger rights than this notice describes, that law wins and we will honour it.

2.What we collect

CategoryExamplesWhy we hold it
Account dataEmail address, authentication identifier, sign-in provider, account creation and last sign-in timesTo create your account, sign you in, and sync your library across devices
Planning contentBusiness profiles, briefs, uploaded material, generated sections, edits, financial figures, critiquesTo produce and store the documents you asked for
Evidence dataSearch queries derived from your profile, kept market signals, source links, scan historyTo research your market and show when the evidence behind a section has moved
Sharing dataShare identifier, whether sharing is on, timestampsTo serve a read-only link you enabled and to let you revoke it
Technical dataIP address, browser and device type, timestamps, error diagnosticsSecurity, abuse prevention, fault diagnosis
Consent recordYour cookie choice, its version and when you made itTo prove and honour your choice

We do not ask for special-category data (health, biometrics, beliefs, sexual orientation) or government identifiers, and we ask you not to upload them. If your planning material contains personal data about other people — staff, customers, investors — you are the controller of that material and must have a lawful basis for including it.

We do not run advertising trackers, we do not build behavioural profiles, and we do not make automated decisions that produce legal or similarly significant effects about you.

4.AI processing and model providers

To generate a document we send the relevant parts of your profile, brief, uploads and scan results to a large-language-model provider acting as our processor. To research your market we send derived search queries — not your raw profile — to a public web search service.

  • Model providers are contractually barred from using your content to train their models.
  • Prompts and completions are retained by providers only for the short abuse-monitoring period their terms require, then deleted.
  • We send the minimum context a section needs, not your whole library.
  • Search queries are derived from business attributes (industry, region, market) rather than personal identifiers.

5.How long we keep it

DataRetention
Profiles and plansUntil you delete them, or until you delete your account
Share copiesUntil you revoke sharing or delete the plan
Account recordUntil deletion, which is immediate and irreversible
Backups containing deleted dataOverwritten on the normal backup cycle, within 35 days
Security and error logsUp to 90 days, then deleted or aggregated beyond identification
Consent recordKept while the choice stands, plus a short period as proof of consent
Browser-only library (signed out)Stored on your device only; cleared when you clear site data

6.Your rights, and how to use them

Two of these are self-service and immediate, from your account page: download everything we hold in one machine-readable file, and permanently delete your account and its contents. We think rights you have to request are weaker than rights you can simply exercise.

  • Access — obtain a copy of your data. Self-service export.
  • Portability — receive it in a structured, commonly used, machine-readable format. The export is JSON.
  • Erasure — delete your account and content. Self-service, immediate, irreversible.
  • Rectification — correct inaccurate data by editing your profile, or ask us.
  • Restriction and objection — ask us to pause or stop processing based on legitimate interests.
  • Withdraw consent — change your cookie choice at any time from the footer, without affecting prior lawful processing.
  • Non-discrimination — exercising any right never degrades the Service you receive.
  • Complain — to your local data-protection or privacy authority, at any time, without contacting us first.

Where you ask us to act rather than doing it yourself, we respond within 30 days and never charge for a first request. We may ask you to confirm control of your account email before acting on a request.

7.International transfers

Our infrastructure, model providers and search providers operate across multiple countries, so your data may be processed outside the country where you live. Where data leaves a jurisdiction that restricts transfers, we rely on recognised safeguards — adequacy decisions where they exist, otherwise standard contractual clauses with the receiving processor, together with encryption in transit and at rest.

8.Who else touches your data

Type of processorWhat they do
Cloud application and database platformHosts the application, stores accounts, profiles and plans
Authentication providerVerifies your email or Google sign-in
Large-language-model providerGenerates and critiques document text on our instruction
Web search providerReturns public results for derived market queries

Each is bound by a written processing agreement, may act only on our documented instructions, and may not use your data for their own purposes. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we have never received payment for access to it.

If our business is ever sold or reorganised, your data may transfer to the successor — bound by this notice, with advance notice to you and the chance to delete your account first.

9.Security

  • Traffic is encrypted in transit; stored data is encrypted at rest by our platform provider.
  • Row-level access rules mean one account cannot read another account's profiles or plans, enforced in the database rather than only in the interface.
  • Share links are unguessable identifiers, served read-only, revocable instantly by the owner.
  • Access to production data by our people is limited to what is needed to fix a reported fault.

No system is perfectly secure. If a breach is likely to result in a risk to your rights, we will notify you and the relevant authority without undue delay, and tell you what happened and what to do.

10.Children

The Service is not directed at children under 16. We do not knowingly collect their data; if we learn we have, we delete it. Educational users below that age should access the Service through an institution that has obtained the necessary consents.

11.Changes to this notice

We version this notice and show its effective date. Material changes are announced in the product at least 14 days before they take effect, so you can export or delete first if you disagree.

12.Contact and complaints

Privacy questions and rights requests can be raised through the contact route published in the product; we answer within 30 days. You may also complain directly to the privacy regulator where you live, whether or not you have contacted us.