How your data moves

This is the boundary between your browser, thinkpool cloud, the computer running the bridge and repository, and your AI provider.

The four stops

  1. Your browser renders the room, sends room content, and seals custom Claude provider keys.
  2. thinkpool cloud stores account, room, readable transcript, and private room-attachment data. It relays sealed credential envelopes and operates the narrow managed features listed below.
  3. Local bridge and repository run on the host computer. The agent reads and changes the repository there.
  4. Your AI provider is contacted by the local agent. Prompts may include code context chosen by that agent.

What thinkpool stores

thinkpool stores account and plan data, room membership and metadata, room chat, cleaned terminal output, terminal and room events, attachments, notification subscriptions, and operational request metadata. thinkpool does not upload the repository as a file tree.

Narrow managed features

Notifications, measurement, and edge metadata

Attachment retention

Controls

Room owners can delete a room, keep it until manual deletion, or set it to expire after 24 hours, 7 days, or 30 days. Account deletion is available in Settings.

Public technical records

The security architecture, bridge protocol and outbound domains, subprocessor inventory, vulnerability-disclosure contact, and security.txt are public technical records. They document current boundaries; they are not independent assurance.