Trust Center · Privacy
Privacy at ThinkToAction
Professional practice belongs under the learner’s control. This page explains current data flows without replacing the formal Privacy Policy.
What information is collected
Depending on use, information may include account, learning, AI, security, and commerce information. A first-party, metadata-only product analytics architecture exists but collection is disabled. It cannot accept learner or workplace content. No third-party analytics provider is configured.
Why it is used
To deliver learning you request, remember supported progress, protect an account, generate feedback you explicitly request, and support future rights or support requests. Unrelated secondary use is not authorized.
What is optional
Optional profile details, external AI requests, Mentor persistence consent, many learning entries, and account use are choices. Core reading, Framework study, and practice can operate without external AI.
Evidence Log
Evidence entries are learner-written summaries of observable work. You choose what to enter and its privacy classification. Avoid identifying, confidential, or sensitive workplace details.
Reflective Signal
Reflective Signal uses AI to review an active practice response and bounded learning context after an explicit feedback request. Authenticated account-wide local-only enforcement is implemented, subject to configured-environment acceptance.
Mentor
Mentor reviews plain text you choose to paste. It asks separately before saving material, supports a per-request local-only mode, and honors the authenticated account-wide local-only preference. It does not automatically import workplace files or learning history.
AI requests
The only external provider implemented is the OpenAI API. No external request occurs unless configured and explicitly requested. Live provider retention, region, and project data controls remain to be verified.
Accounts
Account persistence is designed to synchronize supported records across devices using learner-owned database rows. Production identity, isolation, export, and deletion behavior has not completed live acceptance.
Cookies and browser storage
Required authentication cookies support sessions when accounts are configured. Browser storage may hold themes, progress, drafts, learning history, and privacy acknowledgements. No advertising or analytics cookies are implemented.
Retention
A production retention schedule has not been approved. Browser data remains until cleared by the learner or application. Durable records are designed to remain until deletion or another approved rule applies.
Employer and learner visibility
The product does not implement an employer dashboard or learner-to-learner sharing. Learner-owned database rows use row-level access policies. Authorized service operations and processors may handle data to provide, secure, support, or legally operate the service.
Sale and advertising
The product does not implement sale of personal data, cross-context behavioral advertising, advertising trackers, or marketing cookies. This statement must be reassessed before adding analytics, advertising, or marketing technology.
Deletion, export, and user control
Implemented account controls cover JSON export, evidence deletion, session revocation, privacy preferences, and cascaded account deletion. Reflective Signal and Mentor browser repositories also support deleting their saved records. Remote deletion cannot clear browser-local copies on every device or override provider and backup schedules.
Live acceptance remains pending. Legal rights, verification, deadlines, operating entity, and jurisdiction still require formal policy approval.
Review customer rights and controls · Read the Privacy Policy