Privacy Policy

Effective July 18, 2026

This Privacy Policy explains how Think Agents (“Think Agents,” “we,” or “us”) handles information when you use ThinkOS, including the ThinkOS mobile and desktop applications, ThinkOS Cloud, and our websites (together, the “Services”).

1. Information we collect

Account information. We collect information you provide when creating or managing an account, such as your name, email address, tester details, and support communications.

Device and service information. We process device identifiers and public encryption/signing keys, app and platform versions, authorization status, IP address, timestamps, security events, and operational diagnostics needed to authenticate devices, synchronize data, prevent abuse, and operate the Services.

Encrypted Sphere data. Cloud-enabled Sphere content is encrypted before it is uploaded. ThinkOS Cloud stores encrypted objects and key envelopes but is designed not to possess the private device or recovery material required to decrypt those stored objects. Recovery Keys are intended to remain under your control and must not be uploaded to us.

Hosted model requests. When you deliberately send a hosted chat request, the ThinkOS app decrypts and selects the thread and bounded Sphere context on your device and sends that plaintext request to ThinkOS Cloud. We transmit it to the model provider and model you selected so the provider can generate a response. ThinkOS Cloud is designed not to persist the plaintext prompt, Sphere excerpts, or assistant response as conversation storage; it may retain bounded operational metadata such as provider, model, run status, token usage, timestamps, and sanitized errors.

Provider credentials. If you add an API credential, you enter it on a protected web form. We store the secret using application-level encryption and use it only to provide the model service you configured. Raw secret values are not returned through the mobile API.

2. How we use information

We use information to provide and secure accounts, authorize devices, synchronize encrypted Spheres, fulfill hosted model requests, deliver support, maintain service reliability, enforce our Terms of Service, and comply with applicable law. We do not sell personal information or use decrypted Sphere content to train a ThinkOS model.

3. When information is shared

We share information only as needed with infrastructure and service providers that help operate the Services; with the AI model provider you select when you submit a hosted request; when you direct us to share or collaborate; to protect users, the Services, or legal rights; or when required by law. We require service providers acting on our behalf to provide the same or an equivalent level of protection described in this policy and applicable law, and to process personal information only for authorized purposes. Model providers process submitted requests under their own terms and privacy policies.

4. Storage, retention, and security

We use administrative, technical, and organizational safeguards appropriate to the information we process. No system can guarantee absolute security. Encrypted cloud objects remain until you or an authorized workspace member delete them, subject to limited backup and security retention. Account, credential, and operational records are retained while needed to provide the Services, meet legal obligations, resolve disputes, or prevent abuse, and are then deleted or de-identified.

Your Recovery Key can unlock encrypted Sphere keys. Keep it private and secure. Losing all authorized devices and the Recovery Key may make encrypted content permanently unrecoverable.

5. Your choices and controls

You can manage account details, revoke collaboration devices and provider credentials, delete supported Sphere data, and sign out from the Services. You can permanently delete your ThinkOS Cloud account and associated cloud data directly in the mobile app under Settings > Account. You may also request access, correction, export, or deletion of personal information by emailing hello@thinkagents.ai or using ThinkOS support. We may need to verify your identity before completing a request. Some information may be retained when legally required or necessary for security.

6. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

7. International processing

We and our service providers may process information in countries other than where you live. Where required, we use appropriate safeguards for cross-border transfers.

8. Changes to this policy

We may update this policy as ThinkOS changes. We will publish the revised policy here and update its effective date. We will provide additional notice when required by law.

9. Contact

Questions or privacy requests can be sent to hello@thinkagents.ai or through ThinkOS support. You can also review and manage your account after signing in to the ThinkOS website.