Privacy policy
Last updated: 2 September 2026
Operator details are being finalised; the policy itself is in force.
This policy explains what ThoughtBridge collects about you, why, who else touches it, and what you can ask us to do with it. It is written to follow the Australian Privacy Principles in the Privacy Act 1988 (Cth).
The short version
- We collect your account details, the audio you record, the transcript and AI analysis derived from it, your projects and notes, and basic operational data.
- Audio is temporary. Recordings are deleted from our storage within 7 days of upload. The transcript and the structured note are what remain.
- Transcription and analysis happen overseas. Audio and transcripts are sent to Groq in the United States for speech-to-text and language-model processing.
- Everything else stays in Sydney. Accounts, thoughts, and files are stored on Google Cloud in the australia-southeast1 region.
- Destinations are yours. Notes written to your GitHub repository or Google Drive live in accounts you own and control.
- No ads, no sale of data, no trackers. We do not sell your data, we do not use your thoughts to train models, and this site runs no analytics.
- You are in control. Export or delete everything from Settings, or email us. Complaints go to us first, then the Office of the Australian Information Commissioner.
Who we are
ThoughtBridge is operated by [OPERATOR_NAME] (ABN [ABN]), a sole operator based in [STATE], Australia. In this policy, "we", "us", and "ThoughtBridge" mean that operator. "The service" means the ThoughtBridge apps for iPhone, iPad, Apple Watch, and Mac, the web app at app.thoughtbridge.io, the API, and this website.
You can reach us about anything in this policy at hello@thoughtbridge.io.
What we collect
We collect only what the service needs to work. Specifically:
- Account details. Your email address, your display name, and an optional avatar image.
- Sign-in identifiers. A Firebase Authentication user id and the sign-in method you use: email and password, Google, Apple, or GitHub. If you use email and password, the password is handled by Firebase Authentication and is never visible to us.
- Captures. The audio (and, where supported, video) you record, the transcript produced from it, and the AI-generated summary, title, task list, questions, and decisions derived from the transcript.
- Project data. Project names, notes, and any images you attach to a thought or project.
- Device type. Which kind of device a capture came from (for example watch, phone, Mac, web, or API), so the app can show where a thought was recorded.
- API keys. Keys you create in Settings are stored as a hash. We cannot recover a key after it is shown to you once.
- Destination credentials. When you connect a GitHub destination we store the GitHub App installation id. When you connect Google Drive or YouTube (private beta) we store an OAuth refresh token so we can write to the folder or channel you chose.
- Usage counters. How many captures you have made this month, used to apply the fair-use limit.
- Request logs. Server logs that record your user id and request ids for each API call, kept for 30 days. Logs do not contain transcripts or audio.
If you join the waitlist on this site, we collect the email address you enter and use it only to send you an invitation and related updates.
Why we collect it
We use your information for these purposes and no others:
- To create and secure your account and let you sign in.
- To transcribe and analyse your captures and write the result into the destinations you connect.
- To show your thoughts, projects, and history in the apps and web app.
- To apply the fair-use limit and keep the service stable.
- To diagnose problems when something goes wrong, using request logs.
- To send you transactional email, such as a waitlist confirmation.
- To respond when you contact us.
- To comply with the law.
We do not use your content to train AI models, to build a profile of you, or to advertise to you. We do not sell personal information.
AI processing and overseas disclosure
Two steps of every capture run on an AI model: speech-to-text transcription of the audio, and analysis of the transcript into a title, summary, tasks, questions, decisions, and a suggested project. Both steps are performed by Groq Inc., a service provider in the United States. Groq receives the audio file for transcription and the transcript for analysis. It does not receive your account details.
This is a disclosure of personal information to an overseas recipient under Australian Privacy Principle 8. We take reasonable steps to make sure Groq handles your information in a way consistent with the Australian Privacy Principles, and we send only what the job needs. Transcription and analysis cannot currently be done without this step, so if you are not comfortable with your recordings being processed in the United States, please do not use the service.
AI output can be wrong. Transcripts and summaries are suggestions, and your exact words are kept alongside them so you can check.
Where your data is stored
Your account, thoughts, projects, and uploaded files are stored on Google Cloud in the australia-southeast1 (Sydney) region: Firebase Authentication for sign-in, Firestore for structured data, Cloud Storage for audio, video, and images, and Cloud Run for the API. Apart from the AI processing described above, your data does not leave Australia unless you connect a destination that lives elsewhere.
Who we share it with
We share personal information only with the providers below, and only so far as each one needs to do its part. We do not share it with anyone else unless the law requires it.
- Google Cloud (Firebase Authentication, Firestore, Cloud Storage, Cloud Run): hosting and storage, Sydney region.
- Groq Inc. (United States): transcription and analysis, as described above.
- GitHub: when you connect a GitHub destination, we write Markdown files into your repository through a GitHub App installation you authorise.
- Google (Drive and YouTube, private beta): when connected, we write files to the folder or channel you chose using the access you granted.
- Apple: Sign in with Apple, and App Store and TestFlight distribution of the apps.
- Resend: transactional email, such as waitlist confirmations.
Files written to a destination are governed by that provider's terms and your account with them, not by this policy. Removing a destination stops future writes; what is already there stays under your control.
How long we keep it
- Audio and video. Deleted from ThoughtBridge storage within 7 days of upload. One exception: a video that no destination hosts is kept so the app can play it, until you delete the thought or your account.
- Transcripts, summaries, and project data. Kept until you delete the thought or your account.
- Request logs. 30 days.
- Firestore backups. 14 days.
- Account details and destination credentials. Kept while your account exists; removed when you delete it.
Your rights
You can do all of the following yourself, or ask us to do it by email.
- Access and export. Settings, then "Download my data", gives you a copy of everything we hold. You can also email us for a copy.
- Correction. Edit your name, projects, transcripts, and notes directly in the app. If something cannot be edited in the app, email us and we will fix it.
- Deletion. Delete a single thought from the thought itself. Settings, then "Delete account", removes your account and everything in it from our systems; copies in backups are gone within the 14-day backup window. Files already written to your own GitHub repository or Google Drive are yours and stay where they are.
- Disconnecting. Remove a destination or revoke an API key at any time in Settings. You can also revoke the GitHub App or Google access from those providers' own settings pages.
- Complaints. If you think we have mishandled your information, email hello@thoughtbridge.io and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Security and data breaches
All traffic between your devices, our servers, and our providers is encrypted with TLS. Service credentials live in Google Secret Manager, never in code. API keys are stored as hashes. Server components run under least-privilege service accounts that can reach only what they need.
No system is perfectly secure. If a breach is likely to cause serious harm to you, we will notify you and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.
Cookies and local storage
This website sets no cookies and runs no analytics or tracking. It stores one value in your browser's local storage: your light or dark theme preference. The web app stores your sign-in state in local browser storage so you stay signed in between visits. Neither is shared with anyone.
Children
The service is not directed at people under 16, and we do not knowingly collect personal information from them. If you believe a person under 16 has created an account, email us and we will delete it.
Changes to this policy
We will update this policy when the service changes in a way that affects your information. The date at the top tells you when it last changed. For material changes we will email account holders before the change takes effect.
Contact
Questions, requests, and complaints about privacy: hello@thoughtbridge.io.