Privacy Policy
Last updated: 12 July 2026
ThoughtPartner is a personal AI assistant operated by Lintel. This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It covers the ThoughtPartner web app and the optional services you can connect to it, including Google Calendar.
Information we collect
We collect only what we need to run your assistant:
- Account information — the email address and identifier from the identity provider you sign in with, used to authenticate you and secure your account.
- Your conversations and files — the messages you send and any files you upload, which form your assistant's memory. These are stored in the storage you choose during setup (your own self-hosted repository, or storage we host for you), under your control.
- Data from services you connect — if you connect Google Calendar or Telegram, we access data from those services as described below. You choose whether to connect them, and you can disconnect at any time.
- Operational logs — limited technical logs (e.g. request timing, error diagnostics, and audit events such as sign-in and connect/disconnect) used to operate, secure, and debug the service.
Google user data (Google Calendar)
If you choose to connect Google Calendar, ThoughtPartner requests read-only access to your calendar events (the https://www.googleapis.com/auth/calendar.readonly scope), along with your basic Google account email to show you which account is connected.
- How we access it — your calendar events are read only during a conversation, at the moment your assistant needs them to answer you (for example, "what's on my calendar tomorrow?").
- How we use it — solely to provide the assistant feature you asked for. We do not use Google Calendar data for advertising, and we do not sell it.
- How we store it — we do not copy your calendar events into your assistant's memory or any long-term store; they are used in-memory to answer and then discarded. The only Google data we retain is the authorization token needed to reconnect, which is stored encrypted, and the connected account email.
- How we protect it — your Google authorization (refresh) token is encrypted at rest using envelope encryption, with the key-encryption key held in a managed key vault. The short-lived access token used for each request is kept only in memory for that request and is never written to disk or shown to the AI model.
- Your control — you can disconnect Google Calendar at any time from your account, which revokes our access at Google and deletes the stored token. You can also review or revoke access at your Google Account permissions.
ThoughtPartner's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Telegram (optional)
If you connect Telegram, messages you send to and receive from your assistant on Telegram pass through Telegram's servers, which are outside our control. Because Telegram is a lower-trust channel, your assistant operates in a reduced-exposure mode there: it withholds designated sensitive information and redirects sensitive or account-level actions to the web app. You can disconnect Telegram at any time.
AI processing
ThoughtPartner uses Anthropic's Claude models to generate responses. To answer you, the relevant parts of your conversation and memory (and, within a turn, any connected data you asked about) are sent to Anthropic for processing. We do not use your content to train models.
How we share information
We do not sell your personal information. We share it only with service providers that help us operate ThoughtPartner (such as our cloud hosting, database, and the AI provider above), under agreements that limit their use of it, and when required by law.
Retention and deletion
Your conversations and files persist in your chosen storage until you delete them or delete your account. Connected-service tokens are retained until you disconnect that service. Deleting your account removes your account data and revokes connected integrations. Limited operational logs are kept for a short period for security and debugging.
Security
We use encryption in transit, encryption at rest for sensitive credentials, per-user access controls, and least-privilege access to your data. No system is perfectly secure, but we work to protect your information and to limit what any part of the system can access.
Contact
Questions about this policy or your data? Contact us at privacy@thoughtpartner.online. We may update this policy from time to time; we'll revise the "last updated" date above when we do.