ThynkThynk

Privacy Policy

Last updated: August 13, 2026

Controller

The controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Felix Schabana
Heusteigstraße 38
70180 Stuttgart
Deutschland
Email: thynk.writer@gmail.com

Your rights as a data subject

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw any consent given, at any time, with effect for the future (Art. 7(3) GDPR)

To exercise these rights, an informal email to thynk.writer@gmail.com is sufficient.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. The authority responsible for Baden-Württemberg is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI).

Data collected when visiting this website

This website is delivered via the hosting provider Netlify, Inc. (San Francisco, USA). When you access the website, Netlify automatically collects technically necessary information in so-called server log files, which your browser transmits automatically. This includes in particular:

  • IP address of the accessing device
  • Date and time of access
  • File requested, amount of data transferred, and access status
  • Browser and operating system used
  • Referrer URL (previously visited page)

This processing is based on our legitimate interest (Art. 6(1)(f) GDPR) in the technically error-free presentation and security of our website. This website does not use cookies or any analytics or tracking tools; your usage behavior is not evaluated for marketing or profiling purposes.

Joining the waitlist

If you sign up for the waitlist via one of the forms on this website, we collect the email address you enter, the form through which you signed up, and the language the website was set to at the time.

Purpose: We use this data exclusively to inform you when the beta phase of Thynk starts.

Legal basis: Processing is based on your consent (Art. 6(1)(a) GDPR), which you give by submitting the form.

Retention period: We store your email address until you withdraw this consent or the purpose (informing you about the beta launch) no longer applies. You can object to this storage at any time by sending an informal email to thynk.writer@gmail.com.

Taking part in the survey

If you take part in our voluntary survey, we collect the answers you select or enter (e.g. type of thesis, tools used, interest in the product, preferred payment model, price you consider fair, likelihood of purchase) as well as the language the website was set to. Providing an email address at the end of the survey is optional and is used exclusively to inform you about the beta launch, if you choose to.

Purpose: We use the answers to develop Thynk, and its product and pricing model, to fit actual needs.

Legal basis: Taking part in the survey is voluntary and based on your consent (Art. 6(1)(a) GDPR). If you provide an email address, its processing is additionally governed by the "Joining the waitlist" section of this policy.

Retention period: Survey answers are stored for as long as they are being evaluated for the product and pricing development of Thynk, and at most until Thynk's market launch or until you object.

User account

You can create a user account in order to use the Thynk application. Registration takes place exclusively on this website; the desktop application then signs in with the same account. We store the following for your account:

  • your email address and your password, the latter only as a cryptographic hash (or, if you sign in with Google, the identifier and email address provided by Google)
  • optionally a display name that you provide yourself
  • the interface language you use
  • your product access (plan, expiry date) and an internal permission level
  • your consents, including the time given and the version of the respective text
  • technical timestamps for creation, last change and last sign-in

Purpose: providing the account, authenticating you on the website and in the application, unlocking sync and paid features, and demonstrating the consents you have given.

Legal basis: the processing is necessary for the performance of the user agreement (Art. 6(1)(b) GDPR). Keeping a record of consent is based on our legal obligation under Art. 7(1) GDPR (Art. 6(1)(c) GDPR).

An account is optional: the Thynk application is fully usable without one. The account only unlocks sync and paid features.

Retention: we store account data for as long as the account exists. You can delete your account yourself at any time under "My account", or request deletion informally by email to thynk.writer@gmail.com. On deletion, your login, profile, plan, consents and usage data are irreversibly removed and any waitlist entry is deleted. Survey answers you have already submitted are retained but separated from your email address, and can no longer be attributed to you afterwards.

Under "My account" you can also download all data stored about your account as a machine-readable JSON file at any time (Art. 20 GDPR).

Usage data from the Thynk application

If you explicitly consent in your account, the Thynk application transmits metrics about your AI calls to us: the time of the call, the provider and model used, the type of action from a fixed list (e.g. outline, draft, translation), the number of tokens consumed, the resulting calculated cost, the duration and success of the call, and the application version.

Content is explicitly not transmitted: no input to the AI, no responses, no chapter or project text, no titles, file names or references. Only numbers and values from predefined lists are transmitted.

Purpose: we analyse what individual features cost to operate, in order to develop a viable pricing model and make the application more efficient. No billing takes place on the basis of this data.

Legal basis: your consent (Art. 6(1)(a) GDPR). No usage data is transmitted without your consent; the default setting is "off". You can withdraw your consent at any time with future effect under "My account" — this does not affect the lawfulness of processing carried out up to that point.

Retention: usage data is deleted when you delete your account, and no later than 24 months after it was collected.

Processors we use

To technically provide this website and process the data described above, we use the following service providers, each covered by a data processing agreement under Art. 28 GDPR or whose standard contractual terms provide equivalent guarantees:

  • Netlify, Inc. (San Francisco, USA) — hosting of the website and execution of the server-side functions (form and account processing).
  • Supabase, Inc. (San Francisco, USA) — database, user accounts and sign-in, as well as sending account-related emails (confirmation, password reset). The data is stored and processed exclusively in a data centre in Frankfurt am Main (AWS region eu-central-1) within the European Union.
  • Google Ireland Limited (Dublin, Ireland) — only if you use sign-in with Google. In that case we receive your email address, your name and a user identifier from Google; we do not receive your Google password.

Where personal data is transferred to countries outside the EU/EEA (in particular the USA) as a result, we rely on appropriate safeguards within the meaning of Art. 46 GDPR, in particular the European Commission's Standard Contractual Clauses.

No cookies, no tracking

This website does not use cookies, analytics tools (e.g. Google Analytics), or marketing pixels. No profiling and no cross-site tracking takes place.

When you sign in, your browser stores your session credentials (access and refresh tokens) in local storage. This storage is strictly necessary to operate the signed-in area (§ 25(2) no. 2 TDDDG), serves solely to maintain your session, and is removed again when you sign out. The desktop application stores the refresh token in your operating system's keychain instead.

Data security

For security reasons, this website uses TLS encryption (https) to transmit the data you enter. You can recognize an encrypted connection by the "https://" prefix and the lock icon in your browser's address bar.

Changes to this privacy policy

We reserve the right to amend this privacy policy to ensure it always complies with current legal requirements, or to reflect changes to our services. The version in effect at the time of your visit applies.