Unified AI Workspace — Product Privacy Notice
Effective: October 8, 2026
This notice adds detail to the ThalenixAI Privacy Policy, which also explains who operates the Service (Mithra Devi A), your rights and how to contact us.
1. What the Service does
The Service stores your AI conversations, imported conversation history, uploaded files and workspace settings so that you can continue work across AI tools. When you ask for an AI response, it sends the content needed for that request to an AI provider. The Service is for people who are 18 or older and is not currently offered in China.
2. Account and sign-in
We store your name, email address, a hashed password, account identifiers, workspaces and settings. You can sign in with email and password or with Google. Sessions use a cookie that is HTTP-only and expires after 14 days. The Service does not offer multi-factor authentication.
3. Conversations and messages
We store the messages, prompts and AI responses in your workspaces and the branches between conversations. Deleted conversations go to Trash first. Trash is not deletion. Trash empties automatically after 30 days, and you can restore items or delete them permanently sooner.
4. Importing from other products
You can import conversations by uploading the export file that another product provides (for example, a data export from an AI chat product). Supported formats are shown in the Service. Imported conversations are stored in your workspace like any other content. They can contain other people's personal information and other providers' output, so import only what you have the right to import. The Service does not use a browser extension and does not capture content from other products' web pages.
5. Uploaded files
We store the files and images you upload, with metadata, and text we extract from them and divide into parts to support search and context. When you delete a file or a workspace, or close your account, the stored files are removed from our active systems as part of the deletion process in section 12.
6. Context continuation
The Service selects and condenses parts of your earlier content and sends them with later requests so the conversation can continue. Condensed context is stored with your workspace and is deleted when you delete the source content. The Service does not currently use a vector database or embeddings-based memory and does not keep a hidden permanent AI memory. We will update this notice before that changes.
7. Cross-provider processing
Content that began with one provider can be sent to a different provider. For example, a conversation you imported from one AI product can be included in a request to another provider. Sending context to a provider means that provider receives it.
8. AI providers
Our current providers, the service and tier we use with each, and what we know about their retention, human review and processing locations are listed at thalenixai.com/providers, which includes only providers approved for production use. We activate a provider only after reviewing its terms, data use, retention, security, international processing and agreements, and we send real user content only through provider services whose terms do not permit the provider to use that content to improve its own models.
We do not control how long a provider keeps what we send it. Deleting data from our systems does not delete copies a provider holds. Whether, and how soon, a provider deletes them depends on that provider's terms and on the service and settings we use. Some providers keep content for a limited period for abuse monitoring.
9. Your own provider key
If you add your own provider key, we store it on our servers in encrypted form. Our backend decrypts it when it needs to send a request to that provider for you. It is not kept only in your browser. We do not intentionally show your key in responses or logs, and we delete it when you remove it or close your account. Requests made with your key are governed by the terms of your own provider account, including how that provider uses and keeps your content.
10. Logs
We keep application, infrastructure and security logs. They can include account identifiers, IP addresses, timestamps and error details, and file names can appear in import-error logs. We do not intentionally log the content of your prompts, responses or files, or your provider keys. Logs are kept for 12 months (our own standard, longer than the 180 days Indian rules currently require for certain logs), held in India, and then deleted.
11. Support, security and abuse handling
We do not routinely read your content, and we do not scan it. Staff may access your content only (a) to give support you ask for, (b) to look into a credible security or abuse report or alert, or (c) to meet a legal duty. Access is limited to what is needed, and every access is logged. AI providers may apply their own safety and abuse monitoring to what they receive, and our staff-access rules do not govern what providers do with content they receive.
If we find content that the law requires us to report to the authorities, we will report it. We may suspend the account and preserve limited information for that purpose, and we will not tell you where the law prohibits it. Legal requests are handled under section 18 of the Privacy Policy.
12. Retention and deletion
- While your account is active, we keep your workspace content.
- When you permanently delete an item, close your account, or we verify a deletion request, we aim to remove the data from our active systems within 15 calendar days and will do so within 30 calendar days. Deletion covers messages, files, extracted text, condensed context, search entries, generated file derivatives such as thumbnails, and stored provider keys.
- Not immediately removed: backups (kept 30 days, then they expire); logs (12 months); records we must keep by law; and copies held by AI providers (section 8).
- Inactive accounts: we do not automatically delete active workspaces because they are old. If that changes, we will give advance notice first. Stored provider keys on inactive accounts may be removed sooner.
13. AI model training
ThalenixAI does not use your content to train or fine-tune AI models. Operating, securing and debugging the Service are not training. A future program that used customer content to improve models would need its own notice and your separate consent.
14. Security
We use reasonable technical and organisational measures. They include encrypted connections, authenticated sessions, ownership checks on workspaces and data, hashed passwords, encrypted storage of provider keys, and role-based staff access with logging. We do not claim certifications or audits. No system is completely secure.
15. Where your information is processed
Our primary hosting region is India. AI providers process requests where they operate, so we cannot promise that your content stays in any country. Where the law requires a transfer mechanism, we use one that is available and appropriate for that transfer.
16. Our role
For your account details, support and security, ThalenixAI decides how and why information is used. For the content you submit, we process it to provide the features you ask for and to keep the Service secure, and we do not use it for our own unrelated purposes. If your content includes other people's personal information, you decide whether to include it. We process it only to provide the Service you ask us to provide and to keep it secure.
17. Your rights, export and requests
The baseline rights in the Privacy Policy (section 14) apply, and section 15 of that policy explains regional additions. There is no self-service export. If the law gives you a right to a copy of your information or to portability, we provide it on request through the privacy request process.
18. Changes and contact
We update this notice when the Service's data practices change, before the change takes effect where we can. Privacy and legal requests: contact@thalenixai.com (put the type of request in the subject line, for example "PRIVACY: Deletion Request" or "LEGAL: Legal Request").
