Effective 22 August 2026
Privacy
Thoughts is designed around a simple boundary: what stays on your device is different from what you choose to sync.
Data that stays local
Unless you explicitly enable cloud sync for a project, its thoughts remain on your device. Locked thoughts, capture audio, drafts, learned vocabulary, and local model data are not exposed through the Claude connector.
Data you sync
When you enable cloud sync, the project content and eligible attachments needed for sync and collaboration are stored with Supabase. Access is restricted by account identity, project membership, and database row-level security.
Account information
Google or Apple provides the identity details needed to sign you in. Thoughts stores your account identifier, verified email, display name, and optional avatar so sync and collaboration work.
Claude and other connectors
A connector receives access only after you approve it. The initial Thoughts connector is read-only and can fetch your profile plus synced, unlocked project and thought data. You can revoke a connector from the Connected apps page.
Resend processes transactional messages such as project invitations. Invitation emails contain the inviter and project names, but never thought content. Delivery state may be retained to prevent duplicate sends and diagnose failures.
Security and deletion
Connections use short-lived access tokens and rotating refresh tokens. You can stop sync, revoke connected apps, or delete cloud content from the app. Operational logs are configured not to record access tokens or thought content.
Questions
Use the support option inside Thoughts for privacy or data requests.