Privacy & Security

What we collect, why we collect it, who we share it with, your rights, and how we keep it all secure. This policy covers your rights under the EU General Data Protection Regulation (GDPR). Questions: email privacy@thinkpool.io.

Who we are

thinkpool is built and operated by Thinkpool, UAB, a private limited company registered in the Republic of Lithuania. Thinkpool, UAB is the Data Controller for personal data processed through this service. Contact: privacy@thinkpool.io.

What we collect

Rooms are shared with the partner you invite. When you share a room link, your partner can read and steer every terminal in that room for as long as it exists. You can close a room, remove a partner, or delete the room at any time.

What we do NOT collect

Important: the record of what an agent terminal does, including file edits, commands, and messages, is stored so the room can be reopened and reviewed. Don’t put sensitive personal data, passwords, or confidential business information somewhere a room partner shouldn’t see it.

Who we share your data with

We route data through a small set of sub-processors:

Your runtime’s AI provider is not a sub-processor of ours: the local coding agent calls that provider directly. Claude Code uses the host’s Anthropic login or a registered Anthropic-compatible provider. Codex uses the host’s Codex/OpenAI login. Hermes Agent uses an isolated thinkpool ACP profile. A custom Claude provider key is encrypted in your browser to your bridge’s public key before it is transmitted; we never receive it in readable form and cannot decrypt it. Two narrow managed features use Groq on thinkpool’s key: voice dictation that you actively record, and terminal auto-naming when that server feature is explicitly enabled. Managed naming is off by default. When enabled, it sends the minimized first-task excerpt described above, not the full transcript, repository, room code, terminal ID, account email, or partner identity. Filtering reduces exposure but cannot guarantee that an excerpt contains no sensitive information.

We announce material sub-processor changes before they take effect, except when an emergency security replacement makes advance notice impractical.

Your rights under GDPR

If you are in the EU or EEA, you have the rights of access, correction, erasure (right to be forgotten), portability, objection, and withdrawal of consent. To exercise any right, email privacy@thinkpool.io: we respond within 30 days. You can also delete your account directly from Settings → Danger zone. You may lodge a complaint with your national data protection authority; thinkpool’s lead supervisory authority is Lithuania’s State Data Protection Inspectorate (VDAI).

Data retention

Security at thinkpool

These are the specific controls currently configured to protect your data and your machine. They are not a claim that the system is finished.

Security is not a certificate. It is a set of controls that must stay specific and reviewable. Found something? Email security@thinkpool.io.

thinkpool does not provide a routine employee feature for reading room transcripts. The two operators retain technical production access for support, security, and incident response. thinkpool is not a zero-knowledge system today because room transcripts are stored in readable form.

Cookies and children

thinkpool does not use third-party tracking or advertising cookies; Supabase Auth uses browser localStorage (not cookies) to keep you signed in. thinkpool is not intended for anyone under 16: if you believe a child has created an account, email privacy@thinkpool.io and we will delete it promptly.

Changes to this policy

For material changes that affect what we collect, who we share it with, or what you can do about it, we will notify you by email at least 30 days before the change takes effect.