Privacy Policy
Last updated: January 10, 2026
1. Introduction
ThoughtMap Technologies Inc. ("we", "us", "our", or "ThoughtMap") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered learning platform and related services (collectively, the "Service").
This Privacy Policy applies to all users of our Service and should be read in conjunction with our Terms of Service. By using our Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, username, password, and profile information
- Payment Information: Billing address, payment method details (processed securely by third-party payment processors)
- Learning Content: Topics you explore, questions you ask, learning expeditions you create, notes, and journal entries
- Communications: Messages you send to us, feedback, support requests, and survey responses
- API Keys: If you use our "Bring Your Own Key" (BYOK) plan, we securely store your encrypted API keys for third-party AI services
2.2 Information Collected Automatically
- Usage Data: How you interact with our Service, features used, time spent, click patterns, and navigation paths
- Device Information: Device type, operating system, browser type and version, screen resolution, and device identifiers
- Technical Data: IP address, location data (general geographic area), connection information, and performance metrics
- Cookies and Tracking: Session cookies, preference cookies, analytics cookies, and similar tracking technologies
- Log Data: Server logs, error reports, and security-related information
2.3 Information from Third Parties
- Authentication Providers: Information from social login services (if used)
- Payment Processors: Transaction status and payment verification data
- Analytics Services: Aggregated usage statistics and performance data
- AI Model Providers: Usage metrics and API response data (anonymized)
3. How We Use Your Information
3.1 Service Provision
- Provide, operate, and maintain our AI learning platform
- Process your learning queries and generate AI responses
- Create and manage your learning expeditions and knowledge maps
- Generate personalized learning recommendations and insights
- Enable PDF exports and content sharing features
- Provide customer support and respond to your inquiries
3.2 Account and Subscription Management
- Create and manage your user account
- Process payments and manage subscriptions
- Send transactional emails and service notifications
- Enforce usage limits and subscription terms
3.3 Service Improvement and Analytics
- Analyze usage patterns to improve our Service
- Develop new features and enhance existing functionality
- Monitor service performance and troubleshoot issues
- Conduct research and analytics (using aggregated, anonymized data)
3.4 Security and Legal Compliance
- Protect against fraud, abuse, and security threats
- Enforce our Terms of Service and policies
- Comply with legal obligations and regulatory requirements
- Respond to legal requests and prevent illegal activities
3.5 Marketing and Communications (With Consent)
- Send promotional emails and product updates (opt-in only)
- Provide educational content and learning tips
- Conduct surveys and gather feedback
4. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following circumstances:
4.1 Service Providers
We share information with trusted third-party service providers who assist us in operating our Service:
- AI Model Providers: OpenRouter and other AI services (query data only, not personal information)
- Cloud Infrastructure: Supabase, Vercel, and other hosting providers
- Payment Processors: Stripe and other payment services
- Analytics Services: Vercel Analytics and similar services (anonymized data only)
- Email Services: For transactional and marketing emails (with consent)
4.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety, or that of our users or the public.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections.
4.4 Aggregated Data
We may share aggregated, anonymized data that cannot identify individual users for research, analytics, or business purposes.
5. Data Security
We implement industry-standard security measures to protect your personal information:
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest
- Access Controls: Strict access controls and authentication requirements
- Regular Audits: Security assessments and vulnerability testing
- Secure Infrastructure: Use of reputable cloud providers with security certifications
- Data Minimization: We collect and retain only necessary information
- Employee Training: Regular security training for all team members
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Data Retention
6.1 Account Data
We retain your account information and learning data as long as your account is active or as needed to provide our Service.
6.2 Deleted Accounts
When you delete your account, we will delete your personal information within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention).
6.3 Backup and Recovery
Some information may persist in backup systems for up to 90 days after deletion for disaster recovery purposes.
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
7.1 Access and Portability
- Request access to your personal information
- Receive a copy of your data in a portable format
- Export your learning expeditions and journals
7.2 Correction and Updates
- Correct inaccurate personal information
- Update your account information and preferences
7.3 Deletion
- Delete your account and associated data
- Request deletion of specific information (subject to legal requirements)
7.4 Marketing Communications
- Opt out of marketing emails at any time
- Manage your communication preferences
7.5 Exercising Your Rights
To exercise these rights, contact us at privacy@thoughtmap.space or use the privacy controls in your account settings. We will respond to your request within 30 days.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience and analyze usage:
8.1 Types of Cookies
- Essential Cookies: Required for basic functionality and security
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how you use our Service
- Marketing Cookies: Used for targeted advertising (with consent)
8.2 Cookie Management
You can control cookies through your browser settings or our cookie preference center. Note that disabling certain cookies may affect Service functionality.
9. International Data Transfers
Our Service is operated from the United States, and your information may be transferred to, stored, and processed in the United States and other countries. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses and adequacy decisions where applicable.
10. Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
AI Data Processing Disclosure
Important Information About AI Processing:
- Your learning queries are processed by third-party AI models through services like OpenRouter
- We do not use your personal data to train our own AI models
- Third-party AI providers may have their own data handling policies
- We recommend avoiding sensitive personal information in your learning queries
- AI-generated content may be inaccurate and should be independently verified
- Your learning conversations are stored to provide continuity and improve your experience
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect and how it's used
- Right to delete personal information (subject to exceptions)
- Right to opt out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at privacy@thoughtmap.space with "California Privacy Request" in the subject line.
12. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
You also have the right to lodge a complaint with your local data protection authority.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or through our Service at least 30 days before the changes take effect. Your continued use of our Service after the effective date constitutes acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: privacy@thoughtmap.space
Subject Line: Privacy Policy Inquiry
Response Time: We will respond within 30 days
For general support inquiries, please use our regular support channels available through your account dashboard.