Privacy
The privacy promise
Last updated: October 2026
Thinkori is built privacy-first, and for a student audience that is a design constraint, not a policy afterthought: data minimization first, deletion that actually works, and no training on student content. The commitments below are enforced in the app's code, not just its copy.
What is stored
- Sessions and chat messages — the math content you type or photograph.
- Photos of your work — stored as media; grades are saved as topic-level scores, never raw test photos.
- A learner model — mastery numbers and misconception tags, no problem content.
- Usage counters — content-free counts (like hints used) that power limits and rollups.
- Push subscriptions — device endpoints, only if you enable reminders.
- Share links and group memberships — invited emails and password hashes, never passwords.
What is deliberately not done
- No training on student content — your work is never model-training data.
- Logs carry no personal information — request lines hold route, status and timing, not messages or names.
- The tutor never reads your raw history beyond the current conversation — only capped, high-level personalization.
- Shared sessions are minimized when served — your name is scrubbed, and analysis cards are opt-in.
Your memory, your call
The tutor's knowledge graph stores derived beliefs about your understanding — concepts, misconceptions, strengths. It is built to be inspected, not trusted blindly.
- Every item is visible to you, with its evidence — nothing behind a curtain.
- Forget anything, any time — forgotten items can never reappear.
- Session summaries are readable, editable and forgettable — and they die with the session.
Parents: observe and manage, never read
A linked parent sees per-child study rollups and manages billing from the family console. The console cannot open the chat — that boundary is the product's design, not a setting.
Retention & deletion
Data lives until you delete it. Deleting your account walks the full inventory — sessions, grades, media, memory, boards, group content, billing rows — in one cascade.
- Export first: a one-shot archive of your data, downloadable once.
- Metrics are ring buffers — old counters are pruned automatically.
- Expired share links are swept hourly and enforced dead at read time.
- A deleted account's group content renders as a generic “Student” — no ghost profiles.
Where the app runs
Hosting on Netlify; database and authentication on Neon (Postgres); payments by Stripe — card details never touch Thinkori's servers. AI providers are configured so student content is not used for training.
Privacy questions & requests
Export, deletion or correction requests — or plain questions — start at the contact form. Ask for your data archive or account deletion there and it gets handled. Contact