Privacy Policy
On this page
- 01Who We Are
- 02How You Interact With Thinker
- 03Information We Collect
- 04Cookies and Local Storage
- 05Legal Bases and Purposes
- 06Email and Accounts
- 07Newsletter
- 08AI and the Librarian
- 09Vault and Notes
- 10Reading and Bookmarks
- 11Payments (if enabled)
- 12Third Parties and Processors
- 13International Transfers
- 14Security and Retention
- 15Your Rights
- 16Contact and Changes
- 17Librarian Memory Retention
- No passwords stored — sign in with an email magic link or Google.
- Librarian chat is not stored server-side; only small metadata is kept per question.
- Vault notes are encrypted at rest; you can clear them at any time.
01Who We Are
Thinker is a reading and thinking platform: long-form writing, a podcast, and a private Room where you can keep notes, progress, and conversations with the Librarian.
This Privacy Policy explains what information we collect when you use Thinker, why we collect it, and the choices you have.
- Controller: Mr. Ngô Lê Bảo Duy (individual, owner of the Thinker project)
- Registered address: 268 Lý Thường Kiệt Street, Diên Hồng Ward, Ho Chi Minh City, Vietnam
- Contact: nowhere0199@gmail.com
We process personal data using Cloudflare infrastructure (Workers, Pages, D1, KV) and a small set of clearly identified service providers. There is no advertising, no audience tracking, and no sale of personal data.
02How You Interact With Thinker
You can use Thinker in three ways, and each one collects a different amount of information:
- As a guest, you read articles and listen to episodes. Almost nothing is stored about you.
- As a newsletter subscriber, you receive our welcome email and — only if you choose to — future issues.
- As a signed-in user, you get a Room: notes, reading progress, the Librarian, and optional backups.
When you do not sign in, we store as little as possible about your visit.
03Information We Collect
What you give us directly.
- Email address — required to sign in (via magic link) or to connect with Google. We use it for account creation, sign-in, and account communication.
- Google profile data — when you sign in with Google, we receive the email address and profile name that Google shares for that purpose.
- Notes, highlights, and questions — the content you create in your Room. This is stored in your Vault (see Section 09).
- Messages in the Librarian chat — see Section 08.
What we collect automatically.
- Account data — the email address, sign-in method, language preference, account tier, and last sign-in date.
- Reading progress — for signed-in users, which items you have read and how far you have read them. This powers progress bars and "continue reading".
- Librarian metadata — for each question asked, a few derived theme tags (keywords derived from the question — never the question text itself), the page you asked on, your language, and whether the answer was grounded. We do not store the full conversation.
- Technical data — IP address and basic request information handled by Cloudflare as our infrastructure provider. Used for security, abuse prevention, and rate limiting.
What we do not collect.
We do not collect precise location data, health data, financial account numbers, or government identifiers. We do not use advertising pixels or third-party tracking scripts.
04Cookies and Local Storage
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
th_sess | HttpOnly cookie (session) | Keeps you signed in. Secure, SameSite=Lax, not readable by page scripts. | 30 days |
thinker_lang | Cookie | Remembers your language choice. | 1 year |
th_provider | Cookie | Remembers that you signed in with Google. | Session–30 days |
| Local storage (browser) | Client-side | Room preferences such as Librarian consent toggles. Stays in your browser; you can clear it at any time. | Until cleared |
The session cookie is essential for the account feature. The language cookie is a convenience. There are no advertising or third-party cookies on Thinker.
05Legal Bases and Purposes
Depending on your location, we rely on different legal bases. In practical terms:
- Consent — newsletter subscription, and (where required) the use of cookies beyond what is essential.
- Contract — providing your Room, the Librarian, notes, and reading progress after you sign in.
- Legitimate interest — security, abuse prevention, rate limiting, and basic service reliability. We do not use this basis for anything that materially affects you, and you can object to specific processing (see Section 15).
- Legal obligation — records required to run a service lawfully (for example, basic billing records once payments are live).
GDPR users: the data you see above is processed under Article 6(1) on those bases. CCPA/CPRA users: we do not "sell" or "share" your personal information in those laws' sense. Vietnamese users: this policy is structured to the Personal Data Protection Decree (Decree 13/2023/ND-CP), in force from 01/01/2026, and in particular to its provisions on cross-border transfer and on user rights.
06Email and Accounts
Sign-in without a password. When you request a magic link, we generate a one-time token valid for 15 minutes and email it to you. The token is single-use. The email is sent through Resend. We rate-limit requests (a small number per email and per IP per day) to prevent abuse.
Google sign-in. You complete the OAuth flow with Google; we receive only your email address and profile name for that account.
Account data. We store your email, sign-in method, language, tier, and last sign-in date. No password is ever stored.
Deleting your account. You can delete your account from your Room settings ("Leave silently"). This removes everything linked to you — Vault notes, reading progress, Librarian metadata, and billing records — and ends all of your active sessions. The deletion is immediate and not reversible from your side.
07Newsletter
When you subscribe, we store your email address in our newsletter list and send you a welcome email via Resend. Subscribing is consent; no other marketing use happens by default.
You can unsubscribe at any time through the link in every email we send. Unsubscribing stops the emails; we keep the unsubscribe fact (not to send to you again) but process your address only for that suppression purpose.
08AI and the Librarian
The Librarian answers questions about the content you are reading. This section describes exactly what happens:
- When you ask a question, your question text is sent to our language-model service (an internal LLM portal on Cloudflare Workers, server-side key — you never see or handle keys). When you ask on an article page, the text of the article you are reading (up to the first ~6,000 characters) is included as context so the answer is grounded in the page.
- Chat content is not stored server-side. The conversation in the Librarian UI lives in your browser. We store only small metadata per question: theme tags (keywords derived from the question — never the question text), the page URL, your language, and an answer status.
- Notes and highlights. If you ask the Librarian to save something to your Vault, that content is stored encrypted (Section 09) — but only when you explicitly permit it through the in-UI consent toggle, which is off by default.
- AI output is not legal, medical, or professional advice. The Librarian can make mistakes. Verify anything important.
We do not train models on your questions. We do not send your conversation to advertising or analytics systems.
09Vault and Notes
Your Vault holds your notes, highlights, and saved items.
- Encryption at rest. Entries are encrypted with AES-GCM using a server-held key before being written to our database. The database stores ciphertext; the plaintext exists only in memory while the operation runs.
- Not end-to-end encrypted. Be clear about this: because the key is held on our side (on Cloudflare), we are technically able to read your notes. We do not. No support or moderation workflow reads note content; deletion is the user's tool, not ours.
- Retention is yours. You can clear your Vault at any time from your Room; this wipes your encrypted history. We do not purge entries on a schedule — an entry stays until you remove it or delete your account.
- Backups. When enabled, we can send you an encrypted backup reminder email. No note content is sent in the reminder itself.
10Reading and Bookmarks
For signed-in users we store which items you have read, how far you have read them, and what you have bookmarked. This data exists to resume you where you stopped and to power your Room's journey view. It is tied to your account and is deleted with your account.
Guests have no reading history: progress in an unsigned session is kept only in your browser.
11Payments (if enabled)
Payments are not live at the time of this writing. When we enable them:
- The merchant of record will be Paddle or Lemon Squeezy, acting as the payment processor and Merchant of Record / authorized reseller for applicable Thinker transactions, as specified by the provider's applicable terms., a regulated payment processor. They handle card data, 3-D Secure, and chargebacks; we never see full card numbers.
- We store a subscription reference, plan, and invoice metadata tied to your account.
- The terms for purchases are set out in the Terms of Service (Sections 12–14).
Until payments go live, no financial data is collected on Thinker at all.
12Third Parties and Processors
We use a short list of processors. None of them use your data for their own marketing:
| Processor | What they handle | Basis |
|---|---|---|
| Cloudflare, Inc. | Hosting, Workers, D1 database, KV storage, CDN; IP logs handled under Cloudflare's DPA | Contract |
| Resend | Transactional email (magic links, welcome, billing, backup reminders) | Contract |
| LLM portal (internal, on Cloudflare Workers) | Librarian question processing | Contract / contract with the upstream model provider as applicable |
| Paddle or Lemon Squeezy, acting as the payment processor and Merchant of Record / authorized reseller for applicable Thinker transactions, as specified by the provider's applicable terms. | Payment processing (only once enabled) | Contract |
We do not embed third-party analytics scripts on Thinker. Cloudflare's default request logs (IP, timestamp, request path) are retained per Cloudflare's policy and are covered by its data processing agreement with us.
13International Transfers
Our infrastructure is operated by Cloudflare, which processes data across its global network. When personal data leaves the territory where you are located (for example, the EEA/UK, Vietnam, Japan, Korea, or India), we rely on the applicable transfer mechanism for that territory — standard contractual clauses where required, and we honor requests for safeguards specific to your jurisdiction.
If your jurisdiction requires a specific safeguard document for a transfer you make with us, tell us via the contact below; we will supply or adjust the arrangement. We do not make transfers to unverified third parties for marketing.
14Security and Retention
- In transit. All traffic is HTTPS. Session cookies are HttpOnly, Secure, and SameSite=Lax.
- At rest. Vault data is encrypted (AES-GCM) before storage. Databases are access-controlled.
- Abuse controls. Sign-in and email endpoints are rate-limited; API routes verify the origin; magic links are single-use with a 15-minute lifetime.
- Retention. Account data: while your account exists, then deleted on account deletion. Reading data: tied to the account. Librarian metadata: tied to the account. Newsletter address: while subscribed, then suppressed on unsubscribe. Sessions: 30 days or until logout.
- Breach handling. If a breach affects your data, we will notify affected users and the relevant authority where the law requires it.
15Your Rights
Depending on where you live (GDPR, CCPA/CPRA, Decree 13/2023/ND-CP, APPI, PIPA, DPDP, and similar laws), you may have some or all of these rights:
- Access — what we store about you.
- Correction — fix inaccurate data (for example, a changed email address).
- Deletion — delete your account and all linked data, from Room settings or by writing to us.
- Portability — receive your Vault content in a usable form.
- Objection / restriction — object to legitimate-interest processing; we will honor a documented objection.
- Withdraw consent — unsubscribe, or switch off the Librarian note-consent toggle.
To exercise any right, write to nowhere0199@gmail.com from the email associated with your account. We verify your identity before acting and aim to respond within 30 days.
16Contact and Changes
- Questions, rights requests, or corrections: nowhere0199@gmail.com
- Registered office: 268 Lý Thường Kiệt Street, Diên Hồng Ward, Ho Chi Minh City, Vietnam
We update this policy when the service or our processing changes. The updated date at the top of this page is the source of truth; material changes will be noted on this page rather than pushed to you silently.
If you have questions about this policy, write to us — a human reads the legal inbox.
17Librarian Memory Retention
If you use Thinker+ and enable persistent Librarian memory, Thinker may retain the Librarian memory associated with your account so that your experience can continue if you return to Thinker+ after your subscription ends.
When your Thinker+ entitlement expires, your persistent Librarian memory is placed into a dormant state. While dormant, it is not used to personalize Reader experiences or otherwise provide persistent Librarian functionality.
Dormant Librarian memory is retained for a maximum of 24 months from the date your Thinker+ entitlement ends, unless you delete it earlier, request deletion where applicable, or a different retention period is required by law.
If you reactivate Thinker+ during this period, eligible dormant Librarian memory may be restored to active use in accordance with your settings.
After the applicable 24-month retention period, dormant Librarian memory will be deleted or irreversibly anonymized, subject to any information that we are legally required or permitted to retain for a separate purpose.
You may manage, disable, or delete your persistent Librarian memory through the controls provided by Thinker.