Privacy

The privacy promise

Last updated: October 2026

Thinkori is built privacy-first, and for a student audience that is a design constraint, not a policy afterthought: data minimization first, deletion that actually works, and no training on student content. The commitments below are enforced in the app's code, not just its copy.

What is stored
  • Sessions and chat messages — the math content you type or photograph.
  • Photos of your work — stored as media; grades are saved as topic-level scores, never raw test photos.
  • A learner model — mastery numbers and misconception tags, no problem content.
  • Usage counters — content-free counts (like hints used) that power limits and rollups.
  • Push subscriptions — device endpoints, only if you enable reminders.
  • Share links and group memberships — invited emails and password hashes, never passwords.
What is deliberately not done
  • No training on student content — your work is never model-training data.
  • Logs carry no personal information — request lines hold route, status and timing, not messages or names.
  • The tutor never reads your raw history beyond the current conversation — only capped, high-level personalization.
  • Shared sessions are minimized when served — your name is scrubbed, and analysis cards are opt-in.
Your memory, your call

The tutor's knowledge graph stores derived beliefs about your understanding — concepts, misconceptions, strengths. It is built to be inspected, not trusted blindly.

  • Every item is visible to you, with its evidence — nothing behind a curtain.
  • Forget anything, any time — forgotten items can never reappear.
  • Session summaries are readable, editable and forgettable — and they die with the session.
Parents: observe and manage, never read

A linked parent sees per-child study rollups and manages billing from the family console. The console cannot open the chat — that boundary is the product's design, not a setting.

Retention & deletion

Data lives until you delete it. Deleting your account walks the full inventory — sessions, grades, media, memory, boards, group content, billing rows — in one cascade.

  • Export first: a one-shot archive of your data, downloadable once.
  • Metrics are ring buffers — old counters are pruned automatically.
  • Expired share links are swept hourly and enforced dead at read time.
  • A deleted account's group content renders as a generic “Student” — no ghost profiles.
Where the app runs

Hosting on Netlify; database and authentication on Neon (Postgres); payments by Stripe — card details never touch Thinkori's servers. AI providers are configured so student content is not used for training.

Privacy questions & requests

Export, deletion or correction requests — or plain questions — start at the contact form. Ask for your data archive or account deletion there and it gets handled. Contact