Privacy Policy
Thought Seed holds your private journal. This page says plainly what is stored, what leaves the app, who else can see it, and how to get rid of it. Where the honest answer is uncomfortable, it is written down anyway.
1. Who is responsible
Thought Seed is built and run by Raghav Gandhi, an individual, not a company. He is the data controller for everything described here and can be reached at thoughtseed.app@gmail.com.
2. What is stored
Your account
An email address, and the sign-in method you chose — either a password, which is stored only by the authentication provider and never in a form Thought Seed can read, or a linked account from an external sign-in provider. If you typed a name when signing up it is kept alongside your account. A small profile row records when your account was created and whether you have accepted the AI notice.
That profile row also holds your answers to the two questions asked once when you sign up — what you are working on, and what you are trying to get better at. Both are optional: you can skip them, and skipping is recorded so you are not asked again. They are stored as you typed them, up to 300 characters each. They are used for one thing, described in section 5.
Your writing
Every journal entry you save: its text, the date you filed it under, an optional category, and any title — both one you typed and one the AI wrote, which are kept separately. Each entry’s text is stored twice, once with formatting and once as plain text, because the app needs both — and three times once you have written the entry up, because the write-up is kept as its own separate copy on the entry. Tweet drafts generated from an entry are stored on the entry, and any draft you save is stored again in a separate list.
The write-up is the prose version of an entry you built by answering questions, made when you press Write it up (section 5). It is stored on the entry, you can edit it afterwards, and your edits are saved the same way the rest of your writing is. It is not folded back into the other two copies of your text, and it is never sent as a writing sample when you draft tweets.
Entries are text only. There is no way to attach an image or a file, and no file storage exists.
Technical records
The hosting and database providers keep ordinary server logs — IP address, browser, page requested, time. The app’s own server functions additionally record that a particular account used a particular AI feature at a particular time. Those records do not contain your journal text, with one narrow exception noted in section 5.
3. Where it is stored
In a Postgres database run by Supabase, hosted on Amazon Web Services in the ap-south-1 region (Mumbai, India). The website itself is served by Vercel from its global network.
If you are reading this from outside India, your writing is stored outside your country.
4. Nothing is sold, and nothing is used to train anything
Your writing is not sold, rented, or shared with advertisers. It is not used to train any AI model by Thought Seed, and it is not used to improve the app for anyone else. It is not read for marketing, and there is no advertising here at all.
5. The AI features, and what they send
Seven features use AI: drafting tweets from an entry, rewriting a draft, adjusting a draft to an instruction, naming an untitled entry, asking a follow-up question about what you have just written, sorting an entry into a category, and writing up an answered entry as prose. All seven are handled by a third-party AI provider outside Thought Seed.
Each of these runs only when you press a button. Nothing is sent while you type, and nothing is sent in the background.
What is sent when you use them:
- Drafting tweets sends the entry you are on. It also sends up to six of your own earlier entries, up to 1,200 characters of each, so the AI model can understand the way how you write. Those older entries are supplied as a writing sample; the drafts are meant to come from the entry you are on. If you answered the two questions at signup, those answers are sent too — up to 300 characters each, as background on what you work on rather than as a writing sample, so that the drafts are less generic before you have written enough for the model to have anything to go on.
- Naming an entry sends up to 4,000 characters of that entry.
- Sorting an entry into a category sends up to 4,000 characters of that entry. Only the five categories already built into the app can come back; anything else is discarded and the entry stays uncategorised. You can change the category with one tap whether or not the AI suggested it.
- A follow-up question sends the conversation in the entry you are on — the questions already asked and the answers you have written, up to 6,000 characters. Nothing from your other entries is sent. The AI may answer that there is nothing left worth asking; then no question is added and nothing is stored, and you can write more and ask again. As a hard limit, an entry can be asked at most nine follow-up questions, after which the button goes away.
- Writing up an entry sends the conversation in the entry you are on — the questions asked and the answers you wrote, up to 12,000 characters. Nothing from your other entries is sent. One request comes back with both the prose and a title for that entry, and both are stored on the entry. An entry that has been written up is not asked any further questions, and its write-up is never sent as a writing sample when you draft tweets.
- Rewriting or adjusting a draft sends that draft’s text, and your instruction if you gave one.
These requests are made by Thought Seed’s own servers, not by your browser. The provider therefore receives the text, but not your IP address, your device, or anything that identifies you personally. Its handling of that text is governed by its own terms rather than by this policy.
The one exception to “logs contain no journal text”: if the provider returns a malformed response, the resulting error message can include a short fragment — on the order of ten characters — of the AI’s reply, which is derived from your entry. That fragment would land in the server logs.
6. Who else can see your writing
No third-party analytics, advertising, or tracking product is used here. No traffic measurement, no session recording, no crash reporting, no advertising pixel. Fonts are served from this site rather than from an external font service, so opening a page does not announce your visit to anyone.
But three companies necessarily see something, because they run the infrastructure:
- Supabase stores the database and runs sign-in. Your browser talks to it directly whenever you are signed in.
- Vercel serves the site and keeps standard request logs. Because pages are addressed by path, those logs include the web address of each page you open — which contains the identifier of the entry you were reading, though not its contents.
- The AI provider receives entry text when you use an AI feature, and — when you draft tweets — your answers to the two signup questions, which are profile data rather than entry text. Both are set out in section 5.
If you sign in with an external account rather than a password, your browser contacts that provider to complete the sign-in. Your browser contacts X or WhatsApp only if you click one of those share buttons, and only for an entry you have already made public.
And Raghav can read your entries. They are stored unencrypted, and running the service means holding database access. He does not read them, and there is no feature or process that surfaces them — but the honest statement is that he is able to, and any claim otherwise would be false.
7. Entries are private until you publish them
Every entry is private the moment it is created. New entries are saved with sharing switched off, and the database enforces that rather than the app merely respecting it: an entry can be read only by the account that wrote it, and a signed-out visitor cannot read entries at all.
An entry becomes readable by anyone else only when you switch on the Public toggle on that specific entry. After that:
- Anyone holding the link can read it. There is no password and the link does not expire. The link is not guessable, but it is not a secret either — anyone you send it to can send it on.
- Only what the page displays is exposed. Unposted AI drafts, your usage counts, and your account identifier are never served to a public reader.
- Public entries are marked so that search engines do not index them.
- Switching the toggle off makes it private again, but a link preview generated while it was public can stay cached for up to an hour.
8. What is kept in your browser
Two things: your sign-in session, so you are not asked to log in on every page, and your light or dark theme preference. That is all. There are no advertising or tracking cookies. Clearing your browser storage signs you out.
Signing out ends your session, but does not by itself wipe entries already loaded into that browser tab’s memory. Closing the tab does.
9. How it is protected, and the limits of that
Traffic is encrypted in transit. The database enforces per-account access rules, so one user cannot read another’s entries, and every query the app makes is additionally scoped to the signed-in account as a second line of defence. Passwords are handled by the authentication provider and are never visible to the app.
What this is not: your entries are not end-to-end encrypted, and Thought Seed does not encrypt them itself before storing them. Anyone with administrative access to the database — which means Raghav, and Supabase as the provider — can read them. If you need writing that nobody but you can ever read, this is not the right place to put it.
10. Deleting things
- An entry can be deleted from the entry itself. It is removed immediately and permanently; there is no trash and no undo.
- A draft can be deleted from the drafts page, the same way.
- Your whole account can be deleted from Settings. It asks you to type a confirmation and then to enter a code emailed to you, and then removes your entries, your drafts, your profile and your login. It is immediate and permanent.
One thing does not follow the entry it came from. If you save a tweet draft and later delete the entry it was generated from, the draft remains — it is stored separately and is not linked to the entry. Delete those drafts yourself, or delete your account, if you want that text gone.
Deletion removes your data from the live database. It cannot reach into the infrastructure providers’ backups or server logs, which age out on their own schedules and are outside this project’s control.
11. Your rights
You can ask what is held about you, ask for a copy, ask for corrections, or ask for everything to be erased. Most of that you can do yourself in the app — entries and drafts can be edited or deleted at any time, and the delete button in Settings removes the account outright. The one exception is the two answers given at signup: there is no screen for changing them yet, so correcting those means asking. For that, and for anything else, write to thoughtseed.app@gmail.com and it will be handled by hand. Requests sent by email are, of course, then sitting in an email account — if you would rather not do that, the delete button in Settings needs no message to anyone.
Thought Seed is not intended for children under 13, and accounts are not knowingly created for them.
12. Changes to this policy
If what the app does changes, this page changes with it, and the date at the top moves.
Anything here unclear, or something you think is wrong? Write to thoughtseed.app@gmail.com.