ThalenixAI Privacy Policy
Effective: October 8, 2026
1. About this policy
This policy explains how personal information is handled when you visit thalenixai.com (the "Website"), join Early Access, contact us, or use Unified AI Workspace (the "Service"). The Product Privacy Notice gives more detail about how the Service works, and the Cookie Notice covers cookies and similar technologies.
2. Who is responsible and how to reach us
The Website and the Service are operated by Mithra Devi A, which uses the name ThalenixAI ("ThalenixAI", "we", "us"), of 58, Sampath Street, Cross 2, Rathinapuri, Coimbatore - 641027, Tamil Nadu, India.
Email contact@thalenixai.com for privacy requests, legal requests, grievances, security reports and general questions. Please put the type of request in the subject line, for example "PRIVACY: Deletion Request", "LEGAL: Legal Request", "GRIEVANCE: Complaint" or "SECURITY: Report". The subject line helps us route your message; we handle requests whatever it says.
Grievance Officer: Mithra Devi A, through contact@thalenixai.com (subject "GRIEVANCE: Complaint").
3. Information we collect
Website and Early Access. On the Early Access form: name, email address, role, AI tools you use, how you intend to use the Service, how often you move context between AI tools, and whether you want to join early testing. If you email us: your address, your message and anything you include. Our hosting systems process technical information needed to deliver and secure the Website, such as IP address, browser and device type, pages requested, and date and time.
Account and workspace. Name, email address, a hashed password, account identifiers, workspaces and settings. If you sign in with Google, the profile details Google shares with us for sign-in.
Content you create, import or upload. Messages, prompts and AI responses; conversations you import and the branches between conversations; and files, images and other assets, with their metadata and with text we extract from them and divide into parts to support search and context.
Provider keys. If you add your own AI-provider key, we store it in encrypted form and our backend uses it to send requests to that provider for you. It is not kept only in your browser.
Derived context. To continue your work, the Service selects and condenses parts of your earlier content into context that is sent with later requests.
Logs. Application, infrastructure and security logs, which can include account identifiers, IP addresses, timestamps and error details. We do not intentionally log the content of your prompts, responses or files, or your provider keys.
From others. Responses from the AI providers you use through the Service, and content you import from other products.
Please do not send what you do not need to. The Service accepts free-form content, so sensitive or confidential information may be present in what you submit. We do not ask for it. Include other people's personal information only if you have the right to.
4. How we use information
- To provide, secure and troubleshoot the Website and the Service.
- To review Early Access requests and contact you about the program and early testing.
- To send optional product updates, only if you separately opt in.
- To understand needs and workflows for product research.
- To comply with law, respond to lawful requests, and establish, exercise or defend legal claims.
- To investigate security incidents and misuse.
5. How we act for your information
For your account details, Early Access information, support and security, ThalenixAI decides how and why the information is used. For the content you submit to the Service, we process it to provide the features you ask for and to keep the Service secure, and we do not use it for our own unrelated purposes. If your content includes other people's personal information, you decide whether to include it. We process it only to provide the Service you ask us to provide and to keep it secure. If we offer team or enterprise plans, those plans will have their own terms describing our role.
6. AI providers
When you ask the Service to process content with an AI provider, we send the provider the content needed for that request. That can include earlier conversation content (including content you imported from another product), uploaded files and images, and settings. Content that began with one provider can therefore be sent to another.
Our current providers are listed at thalenixai.com/providers, which includes only providers approved for production use. We activate a provider only after reviewing its terms, data use, retention, security, international processing and agreements, and we send real user content only through provider services whose terms do not permit the provider to use that content to improve its own models. If you use your own key, the terms of your account with that provider apply, including how it uses and keeps your content. Providers may also apply their own safety and abuse monitoring to what they receive.
We do not control how long an AI provider keeps what we send it. Deleting data from our systems does not delete copies a provider holds. Whether, and how soon, a provider deletes them depends on that provider's terms and on the service and settings we use. The provider list says what we know about each provider's retention.
7. AI model training
ThalenixAI does not use your content to train or fine-tune AI models. Operating, securing and debugging the Service are not training. If we ever offered a program that uses customer content to improve models, it would need its own notice and your separate consent. This is ThalenixAI's own policy; how an AI provider handles content it receives is governed by that provider's terms (section 6).
8. Cookies and analytics
The Website does not use analytics at launch. If we add analytics, we will load it only after you opt in, and we will update the Cookie Notice first. See the Cookie Notice for the technologies we do use.
9. Sharing and service providers
We do not sell personal information. We share information only as needed with:
- our hosting and infrastructure providers;
- our email service for Early Access and product communications;
- the AI providers described in section 6;
- Google, if you sign in with Google or choose to load an embedded YouTube video;
- professional advisers; and
- authorities, as described in section 18, and a party to a merger, acquisition or sale, as described in section 19.
The list of vendors that handle personal information is at thalenixai.com/providers.
10. International transfers
Our primary hosting region is India. Our AI providers, email service and other vendors may process information in other countries, and you may use the Service from outside India, so information can cross borders. Where the law requires a transfer mechanism, we use one that is available and appropriate for that transfer. We do not promise that your content stays in any country.
11. Retention
- Account and workspace content: while your account is active.
- Early Access records: until you ask us to delete the record, or 24 months after your last substantive interaction with us (submitting the form, contacting or replying to us, creating an account, or taking part in early testing), whichever is first. Opening or clicking links in update emails does not extend this period. Updates continue until you unsubscribe or the record is deleted. If you unsubscribe or we delete your record, we keep only your email address on a suppression list so that we do not contact you again.
- Logs: application, infrastructure and security logs are kept for 12 months and held in India, then deleted. This is ThalenixAI's own standard. Indian rules currently require certain logs to be kept for at least 180 days, and we apply the 12-month period to all logs.
- Backups: kept for 30 days, then they expire.
- Legal records: kept as long as the law requires.
12. Deletion
Items you move to Trash are not deleted. Trash empties automatically after 30 days, and you can delete items from Trash sooner. When you permanently delete an item, close your account, or we verify a deletion request, we aim to remove the data from our active systems within 15 calendar days and will do so within 30 calendar days. Deletion covers your messages, files, extracted text, condensed context, search entries, generated file derivatives such as thumbnails, and stored provider keys.
Deletion does not immediately remove:
- backups, which expire within 30 days after the data leaves our active systems;
- logs, which are kept for 12 months;
- records we must keep by law; or
- copies held by AI providers or other third parties (section 6).
13. Security
We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. No system is completely secure. If a security incident affects your information, we will tell you and the authorities as the law requires. To report a security concern, email contact@thalenixai.com with the subject "SECURITY: Report".
14. Your rights (global baseline)
For every user, we will:
- tell you what personal information we hold about you;
- correct inaccurate information;
- delete your information as described in section 12;
- let you withdraw optional marketing consent at any time;
- provide a privacy contact and a complaint route; and
- not charge you for making these requests.
Export. There is no self-service export. If the law gives you a right to a copy of your information or to portability, we will provide it on request through the process in section 16.
15. International users and regional information
We aim to give every user the baseline in section 14. Where the law of your region requires more, such as additional rights, a local representative, transfer safeguards, consent for cookies or marketing, or specific notices, we apply those requirements to the extent the law applies to our processing.
- India: existing Indian data-protection and IT rules apply, and the Digital Personal Data Protection Act and Rules apply as they come into force.
- California: we do not sell personal information. We collect the categories of information described in section 3 and share them with the categories of recipients in section 9. We tell you about changes as described in section 21. We do not track you across other websites and do not currently respond to "Do Not Track" signals, because there is no common standard.
- Other regions, including the EU/EEA, the UK, Canada and Australia: ThalenixAI is based in India, and the Service is not deliberately targeted to other regions at launch. We will complete jurisdiction-specific review before targeted marketing, localised offerings or other activities that may bring additional obligations. Where the law of your region applies to our processing, you have the additional rights and protections it provides, and we will identify any representative we are required to appoint.
- China: the Service is not currently offered in China.
16. Requests and grievances
Email contact@thalenixai.com with a subject beginning "PRIVACY:" (for example "PRIVACY: Access Request" or "PRIVACY: Deletion Request"). We may verify your identity first, using no more information than we need. We acknowledge requests automatically when they arrive and respond within 30 calendar days. If the law allows more time and we need it, we will tell you why. Complaints go to our Grievance Officer through the same address (subject "GRIEVANCE: Complaint"); we aim to resolve them within 15 calendar days and will do so within 30. You can also complain to the relevant data-protection regulator, where applicable.
17. Eligibility and age
ThalenixAI is for people who are 18 or older. You confirm this when you join Early Access or create an account. This is our eligibility rule; it is not consent to marketing or to any other use of your information. We do not verify age. If we learn that someone under 18 has an account or an Early Access record, we stop using their information and delete it, except where the law requires us to keep it.
18. Legal disclosures and law enforcement
We disclose information to authorities only (a) under valid legal process, after review; (b) in a genuine emergency involving a serious risk to life or safety, where the law permits and limited to what is necessary; or (c) to preserve information where the law requires it. We keep a record of each request and, where the law allows, tell the affected user. Authorities should send requests to contact@thalenixai.com with the subject "LEGAL: Legal Request".
19. Corporate transactions
If ThalenixAI is involved in a merger, acquisition, restructuring or sale of assets, information may be transferred, subject to applicable law and with notice where required.
20. Automated processing
The Service automatically selects and condenses context to continue your work. We do not make decisions about you with legal or similarly significant effects by automated means, and the Service is not intended for such decisions.
21. Changes
We update the effective date at the top. For material changes we give notice on the Website and, if we hold your email and the change materially affects you, by email. Where the law requires your consent to a change, we ask for it.
