Privacy Policy
Last updated: July 26, 2026
This Privacy Policy is provided by ThoughtDrops LLC, a New Jersey limited liability company ("ThoughtDrops," "we," "our," or "us"), which operates the ThoughtDrops mobile application (the "App") and is the controller of the personal information described below. This Privacy Policy explains in detail what information we collect, how we use it, who we share it with, and how we protect it.
By creating an account or using the App, you consent to the collection and use of information in accordance with this policy. Section 11 explains how to withdraw that consent at any time.
1. User Registration & Account Data
When you create an account, we collect:
| Data | Purpose | Storage |
|---|---|---|
| Full name | Display in your profile | Server database |
| Email address | Account identification & login | Server database |
| Password | Account authentication | Hashed with bcrypt (12 salt rounds) — we never store or see your plain-text password |
| Age confirmation | Verifying you meet our minimum age requirement (13+) | Server database |
Authentication method: Email and password only. We do not currently offer social login (Google, Apple, Facebook). Your session is managed via JSON Web Tokens (JWT) with a 7-day expiration. Tokens are stored on your device only and are never shared with third parties.
Password requirements: Minimum 8 characters.
2. Voice Recordings & Transcription
When you use the voice capture feature:
- Your audio is recorded on your device in M4A format.
- The recording is uploaded to our servers over an encrypted HTTPS connection.
- The audio file is sent to OpenAI's Whisper API for transcription.
- The audio file is permanently deleted from our servers immediately after transcription is complete. We do not retain, archive, or back up your audio recordings on our systems.
- Only the text transcription is saved to your project.
Third-party retention: OpenAI processes audio under its API terms and does not use API inputs to train its models. However, OpenAI may retain API inputs and outputs for a limited period (currently up to 30 days) for trust-and-safety and abuse monitoring under its own policies, after which they are deleted unless retention is legally required. See OpenAI's API data usage policies for details.
3. Project Content & AI Processing
As you use ThoughtDrops, the following content is generated and stored in your account:
- Transcriptions — text converted from your voice memos
- Talking points — key points extracted from your transcription
- Research — web research gathered to support your topic
- Scripts — full video scripts generated from your research and talking points
- Short scripts — 60-second condensed versions of your scripts
- Tweets — social media posts generated from your content
This content is stored in our database so you can access it across sessions. It is associated with your account and is not visible to other users.
AI Services Used for Content Generation
| Service | What We Send | Purpose | Data Training |
|---|---|---|---|
| OpenAI Whisper | Audio file | Voice-to-text transcription | Not used for training (per policy) |
| Anthropic Claude | Transcription text, talking points, research | Script generation, research synthesis, talking point extraction, tweet & short script creation | Not used for training (per policy) |
| Brave Search | Search queries derived from your topic | Web research to enrich your scripts | Standard search queries (per policy) |
All three services process data under their respective API terms, and none of them use API inputs to train their AI models. Like OpenAI, Anthropic may retain API inputs and outputs for a limited period for trust-and-safety and abuse monitoring under its own retention policies before deletion. These providers are contractually and by policy limited to processing your data to provide their services to us — they provide protections for your data consistent with this policy.
4. Video Recordings (Studio)
When you record video using the Studio teleprompter feature:
- Video is recorded directly on your device using your device's camera.
- Finished recordings are saved to your device's camera roll / photo library.
- We do not upload, access, transmit, or store your video recordings on our servers.
5. Device Permissions
ThoughtDrops requests the following device permissions. Each is only used when you actively initiate the related action — we never access these in the background.
iOS
| Permission | Why We Need It |
|---|---|
| Microphone | Record voice memos for transcription and audio during Studio video recording |
| Camera | Record video with the teleprompter overlay in Studio mode |
| Photo Library (Add Only) | Save your recorded videos to your camera roll |
Android
| Permission | Why We Need It |
|---|---|
| Record Audio | Record voice memos and audio during video recording |
| Camera | Record video with the teleprompter overlay in Studio mode |
| Read/Write Media | Save and access recorded videos on your device |
| Foreground Service | Keep audio recording active when the screen overlay appears |
6. Data Storage & Security
We take the security of your data seriously. Here is how your information is protected:
Infrastructure
- Database: PostgreSQL hosted on Railway with SSL/TLS encryption in transit
- Backend: Node.js (Express) hosted on Railway
- All data transmitted between your device and our servers is encrypted via HTTPS/TLS
- Your data is processed and stored in the United States
Authentication Security
- Passwords are hashed using bcrypt with 12 salt rounds — we never store plain-text passwords
- Sessions use JWT tokens (7-day expiration) stored only on your device
- All API keys (OpenAI, Anthropic, Brave) are stored as server-side environment variables and are never sent to or accessible from your device
On-Device Storage
- A single preference flag (onboarding completion) is stored locally via AsyncStorage
- Your JWT session token is stored on-device for authentication
- No project content, transcriptions, or personal data is cached on your device
Security Incidents
If a security incident affects your personal information, we will notify you and any applicable regulators as required by law, without undue delay.
7. Analytics & Tracking
We do not use any analytics, tracking, or crash-reporting services. There are no third-party SDKs (such as Google Analytics, Mixpanel, Firebase Analytics, or Sentry) in the App. We do not track your behavior, collect device identifiers, or build user profiles for advertising. If this ever changes, we will update this policy before releasing the change and notify you as described in Section 13.
8. Data Sharing
We do not sell, rent, trade, or share your personal information with third parties for marketing or advertising purposes. We do not "sell" or "share" personal information as those terms are defined under U.S. state privacy laws, and we do not use your information for targeted advertising or profiling.
Your data is shared only with the AI service providers listed in Section 3, solely to deliver the App's core functionality (transcription, research, and script generation), and with our hosting provider (Railway), which stores our database. These providers process data under their API terms, do not use your data for their own purposes, and do not use API inputs for model training. We may also disclose information if required by law, such as in response to a valid legal process, or to protect the rights, safety, or property of our users or others.
9. Data Retention
| Data Type | Retention |
|---|---|
| Account info (name, email) | Until you delete your account |
| Project content (transcriptions, scripts, research) | Until you delete the project or your account |
| Voice recordings (audio files) | Deleted from our servers immediately after transcription — not retained (AI providers may retain for up to ~30 days for abuse monitoring; see Sections 2–3) |
| Video recordings | Stored on your device only — never on our servers |
| JWT session tokens | Expire after 7 days |
10. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Deletion — delete your account and all associated data (projects, transcriptions, scripts) directly from within the App, or request deletion by email. Upon deletion, all your data is permanently removed from our database.
- Export — export your project content (scripts, transcriptions) from within the App
- Correction — update your name or email from your profile settings
- Withdraw consent — see Section 11
To exercise any of these rights, use the tools in the App or contact us at hello@thoughtdrops.us. We will respond within 30 days. We will never discriminate against you (such as by denying service or degrading functionality) for exercising your privacy rights.
U.S. State Privacy Rights
Depending on your state of residence (including California, New Jersey, Colorado, Virginia, Connecticut, and other states with comprehensive privacy laws), you may have specific statutory rights to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of the sale of personal information, targeted advertising, and certain profiling. We extend the rights above to all of our users regardless of state, and — because we do not sell personal information, do not engage in targeted advertising, and do not profile users — there is no sale, sharing, or targeted-advertising activity to opt out of. If we decline a request, you may appeal by replying to our response, and we will review the appeal within the timeframe required by your state's law.
11. Consent & How to Withdraw It
We rely on your consent (and on the necessity of processing to provide the service you request) to process your data. You provide consent when you create an account and accept this Privacy Policy, and when you actively initiate a feature — for example, recording a voice memo, which sends audio for transcription and text for AI processing as described in Sections 2 and 3.
You may withdraw consent at any time by:
- Deleting a specific project (removes that project's content from our database)
- Deleting your account from within the App or by emailing us (removes all your data from our database)
- Declining or revoking device permissions (microphone, camera, photo library) in your device settings — the related features simply won't run
- Ceasing to use the App
Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal.
12. Children's Privacy
ThoughtDrops is not intended for use by anyone under the age of 13, and we require age confirmation at registration. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at hello@thoughtdrops.us and we will promptly delete the account and all associated data.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email to the address on your account or by an in-app notice before the changes take effect, in addition to updating the "Last updated" date at the top of this page. Continued use of the App after the effective date of an updated policy constitutes your acceptance of it.
14. International Users
The App is operated from the United States and is currently intended for users in the United States. Your information is processed and stored on servers in the United States. If you access the App from outside the United States, you understand that your information will be transferred to and processed in the United States.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
ThoughtDrops LLC
Email: hello@thoughtdrops.us
Address: 136 NJ State Route 10, #120, East Hanover, NJ 07936
Website: thoughtdrops.us