Effective 31 July 2026
Privacy Policy
This Policy explains what information Thido handles, why we use it, which service providers help us operate the product, and the choices available to you.
1. Who is responsible for your data
Thido is responsible for the personal data described in this Policy. For privacy questions, rights requests, or account-deletion requests, contact privacy@thido.ai.
2. Information we collect
Account and authentication data
We process your name, email address, profile image, email-verification status, and account identifiers. If you use a password, we store a salted cryptographic hash, not the password itself. If you use Google sign-in, we receive basic profile information and store the provider identifiers and tokens needed to maintain the connection.
Documents and prompts
We store the documents you create, titles, prompt questions and answers, comments, suggestions, document status, AI preferences, and associated timestamps. Thido currently stores this editable content in its PostgreSQL database; it does not currently store documents as uploaded files in object storage.
You may begin an outline before signing in. During that guest flow, the answers are kept temporarily in your browser and are not sent to Thido's servers until you authenticate and ask us to create the document.
If someone shares a document directly, we store the recipient's normalised email address, the permission selected by the sharer, who sent the invitation, and invitation timestamps. We use the address to deliver the invitation and to grant access when the recipient signs in with that address. Depending on the selected permission, the recipient may view, comment on, edit, delete, or manage sharing for the document.
If you enable link sharing, we store a random share-link token and the permission you select. Anyone who receives the link can view the document title, body, and your profile name without an account until you revoke the link. When a protected link action is selected, we check the person's account and store the account and access time so the document owner or a full-access manager can review link access. Depending on the link permission, a signed-in holder may comment, edit, delete, or manage sharing. The shared view does not expose your email address or other account details. Recipients may still copy or retain content they can view.
Communications
We process your email address and the content needed to send account verification, password-reset, and document-invitation messages. If you contact us, we may retain your message and related support correspondence.
Signed-in users may send private messages to the Thido founding team. We store the message, its category, replies, response timestamps, and the page path the user chose to include. We do not automatically add document text, comments, prompts, editor selections, or public share-link tokens to founder conversations.
Beta access and billing
We store your beta-place number and the date access was granted. If you choose a paid plan, we store Stripe customer, subscription, price, status, renewal, and cancellation identifiers needed to provide and manage that plan. Payment details are collected by Stripe through its hosted checkout and billing portal; Thido does not store your full payment-card number.
Usage and technical data
We receive technical information such as IP-derived location, browser, operating system, device type, referring page, requested route, and timestamps. We also process security and operational information needed to authenticate requests, enforce rate limits, diagnose failures, and protect Thido.
3. How and why we use information
- to create and secure your account and keep you signed in;
- to save, display, edit, organise, and share your documents;
- to generate drafts, follow-up questions, comments, and revisions;
- to send verification, password-reset, invitation, and service messages;
- to receive, answer, and monitor response times for founder messages;
- to provide beta access and administer optional paid plans;
- to understand aggregate product usage and improve reliability;
- to prevent fraud, misuse, and security incidents; and
- to meet legal obligations and enforce our Terms.
Where European data-protection law applies, our legal bases are performance of our contract with you, our legitimate interests in operating and securing Thido, consent where we specifically request it, and compliance with legal obligations. You may object to processing based on legitimate interests as described below.
4. AI processing
When you request an AI feature, Thido sends the text and instructions needed to fulfil that request to one or more third-party AI model providers. Depending on the feature, this may include document text, prompt answers, selected text, comments, and nearby context. The provider may vary based on feature availability, performance, safety, or product configuration. Do not include personal or confidential information that is unnecessary for your request.
We select provider accounts and commercial services intended for API use and apply available data controls appropriate to Thido. Provider retention periods and permitted processing may differ. We require each provider to process submitted material under its applicable commercial terms, our configuration, and relevant data-protection obligations. We will update this Policy if a provider change materially affects how your information is handled.
Thido's AI features assist with writing; they do not make decisions that produce legal or similarly significant effects about you.
5. Service providers and disclosures
We disclose information only as needed to operate Thido, follow your instructions, protect the service, complete a business transaction, or comply with law. Our principal service providers are:
| Provider | Purpose | Information involved |
|---|---|---|
| Vercel | Application hosting and web analytics | Requests, technical data, and analytics events |
| Neon | Managed PostgreSQL database infrastructure | Account, document, prompt, comment, and settings data |
| AI model providers | AI generation and text processing | Prompts, relevant document content, and generated output |
| Resend | Transactional email delivery | Email address and verification, reset, or invitation email content |
| Rollbar | Application error tracking and incident diagnosis | Error messages, stack traces, route patterns, deployment identifiers, and technical data |
| Stripe | Hosted checkout, subscriptions, and billing management | Account and contact details, payment information, transaction details, and Thido billing identifiers |
| Optional Google account sign-in | Basic profile and OAuth authentication data |
We do not sell personal data. We do not share personal data for cross-context behavioural advertising. If ownership or control of Thido changes, information may be transferred as part of that transaction, subject to this Policy and applicable law. You may contact us for information about the AI model providers currently used by Thido.
6. Analytics, cookies, and browser storage
Thido uses essential cookies for authentication and security, plus a preference cookie that remembers your light or dark theme. Disabling essential cookies may prevent sign-in and other core features from working.
The guest drafting flow uses your browser's session storage to preserve unfinished outline answers during navigation, refreshes, and the sign-in redirect. Thido treats a stored guest outline as expired after 24 hours and removes it after the authenticated document is created. Session storage is local to the browser tab or session and may disappear sooner if you close the tab, clear site data, or use browser privacy controls.
We use Vercel Web Analytics to measure page visits and product usage. Vercel states that this service does not use third-party cookies. It derives an anonymous visitor identifier from request data, discards the identifier after 24 hours, and records information such as route, referrer, coarse location, browser, operating system, and device type. We do not intentionally send document text, prompts, email addresses, or authentication secrets as analytics events. See Vercel's Web Analytics privacy documentation.
We use Rollbar to group application errors and alert us when Thido fails. The integration is configured to exclude document text, prompts, comments, form input, email addresses, authentication secrets, request bodies, and public share-link tokens. Session replay and automatic browser activity recording are disabled. Rollbar may receive an error message, stack trace, sanitised route pattern, deployment identifier, provider request identifier, and other technical context needed to diagnose the failure.
7. Retention
We generally retain account information and documents while your account is active or as needed to provide Thido. Verification links expire after 24 hours and password-reset links expire after one hour. Billing and transaction records may be retained for the periods required for accounting, tax, dispute, and legal obligations. Founder-message threads may be retained with the account so the user and team can refer to the conversation; a specific support retention period will be published before broader production use. We may retain limited records longer where reasonably necessary for security, dispute resolution, backup integrity, or legal compliance.
You may request deletion by contacting privacy@thido.ai. Some data may remain temporarily in backups or where retention is legally required. Our providers apply their own documented deletion and backup cycles to data they process for us.
8. International transfers
Thido's providers may process information in countries other than the one where you live, including the United States. Where required, we rely on recognised transfer mechanisms and provider contractual safeguards for international transfers.
9. Security
We use technical and organisational measures designed to protect your information, including encrypted connections, access controls, hashed passwords and one-time authentication tokens, and server-side access to infrastructure credentials. No service can guarantee absolute security. Please use a unique password and notify us if you suspect unauthorised account access.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal data, object to certain processing, withdraw consent, or appeal our response. You may also have the right to complain to your local data-protection authority. We may need to verify your identity before completing a request.
Send requests to privacy@thido.ai. You can disconnect Thido from your Google Account through Google's account security settings, but doing so does not by itself delete your Thido account or stored documents.
11. Children
Thido is not directed to children under 18, and we do not knowingly collect their personal data. If you believe a child has provided data to Thido, contact us so we can investigate and take appropriate action.
12. Changes to this Policy
We may update this Policy as Thido or applicable law changes. We will update the effective date and provide reasonable notice when a change materially affects your privacy rights.
13. Contact
For privacy questions or requests, email privacy@thido.ai. For general account support, email support@thido.ai.