Effective 15 September 2026
Privacy
Thoughts is designed around a simple boundary: what stays on your device is different from what you choose to sync.
Data that stays local
Unless you explicitly enable cloud sync for a project, its thoughts remain on your device. Locked thoughts, capture audio, drafts, learned vocabulary, and local model data are not exposed through an AI connector.
Data you sync
When you enable cloud sync, the project content and eligible photo and document attachments needed for sync and collaboration are stored with Supabase. Attachment records include file names, types, sizes, and ownership so the app can display your files and manage your storage allowance. Capture audio stays on your device. Access is restricted by account identity, project membership, and database row-level security.
Account information
Depending on how you sign in, Thoughts verifies your email directly or receives verified identity details from Google or Apple. Thoughts stores your account identifier, verified email, display name, and optional avatar so sync and collaboration work.
Blocked users
When you block an email address, Thoughts stores that address and any matching account identifiers to prevent project invitations from that person. Your block list is available to you in Settings. Blocking does not remove anyone from existing shared projects. You can remove a block in Settings, and your block list is removed when you delete your account.
AI connectors
A connector receives access only after you approve it. The Thoughts connector can read your profile, synced Unfiled thoughts, and synced projects you own or belong to, including unlocked content, collaborator names, authorship, recent changes, and your invitation and shared-thought notification summaries. When you ask, it can also create a cloud-synced project or a typed thought in a synced project. Thoughts saved in shared projects are visible to their members. The connector exposes no tools to edit or delete existing content or manage invitations. You can revoke it from the Connected apps page.
Resend processes transactional messages such as sign-in codes and project invitations. Sign-in messages contain a short-lived code; invitation emails contain the inviter and project names, but never thought content. Delivery state may be retained to prevent duplicate sends and diagnose failures.
Notifications and service operation
If you enable notifications, Thoughts stores an installation identifier and Expo push token so invitations and shared-project activity can reach this device. The service also processes request timing, delivery state, and limited operational logs needed for security and reliability. It does not use advertising or cross-app tracking SDKs.
Account deletion
Open Settings → Account → Delete Account in Thoughts to permanently delete your account. Deletion removes synced projects you own, your contributions to shared projects, eligible cloud attachments, invitations, your block list, notification tokens, connector authorizations, and the account identity. Local-only thoughts remain on your device because they were never uploaded. If you used Sign in with Apple, Thoughts revokes the stored Apple authorization during deletion. For older accounts without a stored authorization, the app explains how to remove Thoughts from your Apple Account.
Security and retention
Connections use short-lived access tokens and rotating refresh tokens. You can stop sync, revoke connected apps, or delete your account from the app. Transactional delivery state and operational logs are retained only as needed to operate, secure, and diagnose the service. Logs are configured not to record access tokens or thought content.
Questions
Email areeb7676@gmail.com or visit Thoughts AI Support for privacy or data requests.