Privacy policy
Version 2026-09-07.1, last updated 2026-09-07. thinkapenny.ai — admin@thinkapenny.org
The short version: we keep as little as possible, we keep it only if you ask us to, and we keep it only where you tell us to. We do not sell anything about you to anybody, and we never share the mobile number you give us.
Who this is about
This policy covers the websites and applications at thinkapenny.ai, including the chat application, the document extractor, and the API that serves them.
What we collect
- Your sign-in identity. If you sign in with Google we receive your email address and name. We use them to know which account is yours and to show you your own work. We do not receive your Google password.
- What you send to a model. The text of your messages, and any document you upload to the extractor, are sent to the model that answers them.
- A mobile number, only if you give us one. Used to send you one-time passcodes and account notices, and for nothing else. See Text messages below.
- Operational records. Enough to run and bill the service: the time of a request, which model it used, how many tokens it consumed, and whether it succeeded.
Where your content is kept — and that is your choice
This is the part most policies are vague about, so here it is exactly.
- Chat conversations. The chat offers three options and honours them: this browser only, which keeps conversations in your own browser's storage and nowhere else; this browser and Google Drive, which additionally writes them to your Drive, in your account, under your control; or don't save chats, which keeps nothing at all once the page is closed. We do not keep a copy of your conversations on our servers under any of the three.
- Uploaded documents. A document you send to the extractor is held only while it is being worked on and is deleted automatically within twenty-four hours. You can delete it sooner from the application.
- Your provider keys. If you bring your own API key for a model provider, it is stored encrypted, used only to make the requests you ask for, and never shown back to you or to anyone else — only its first few characters, so you can tell your keys apart. You can remove it at any time, and removing it deletes it.
Text messages and mobile information
If you give us a mobile number, we use it to send one-time passcodes and notices about your own account. We do not send marketing texts, and we do not text people who have not asked us to.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as the messaging provider that delivers the message, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
You can stop the messages at any time by replying STOP, and get help by replying HELP or writing to admin@thinkapenny.org.
Message frequency varies and depends on your own activity. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
What we never do
- We do not sell your personal information, and we never have.
- We do not share your mobile number, or the fact that you opted in, with anyone for marketing — see the clause above, which we mean literally.
- We do not use your conversations or documents to train models.
- We do not read your content except where you ask us to help with a specific problem, or where we are compelled by law.
Operational records, stated honestly
Running an API means keeping some record of what it did. We keep a request log — time, model, token counts, outcome — because it is how the service is billed and how faults are found. A short rolling window of request and response bodies is also kept for diagnosis: the most recent few hundred, each truncated, oldest discarded first. They are readable only by the service account and are not used for anything else.
If you would rather your requests were not in that window, say so and we will tell you what we can turn off for your account.
Other people we rely on
- Model providers. Your prompt goes to whichever model answers it. Where that is a model we host ourselves, it does not leave our machines. Where it is a third-party model, your prompt goes to that provider under their terms — and if you brought your own key, the request is made with your key and billed to your account with them.
- Google. For sign-in, and for Drive if you choose to save chats there. Drive access is limited to the files the application creates.
- A messaging provider, to deliver text messages. They receive the number and the message so they can deliver it, and nothing more.
Your choices
- Change where chats are kept, at any time, in the chat's settings.
- Delete a conversation, an uploaded document, or a stored provider key from the application.
- Stop text messages by replying STOP.
- Ask us to delete your account and what is associated with it, by writing to admin@thinkapenny.org. We will confirm when it is done.
Security, children, and changes
Traffic is encrypted in transit. Credentials are stored encrypted and are never returned to a browser. Access to the servers is limited to the people who operate them.
The service is not intended for children under 13, and we do not knowingly collect their information.
If this policy changes, the date at the top changes with it. Material changes will be announced in the application rather than made quietly.
Questions: admin@thinkapenny.org.