Features Plans & Pricing CLI Docs & Tools Marketplace New Integrations WorkSim Simulator
Engineering Blog System Status Interactive Demo About Us Contact Us Verify Certificate
Login Get Started
Data Protection & Privacy Standards

Our Privacy Policy

How ThinkNCollab collects, encrypts, and handles your personal data, terminal streaming sessions, AI inputs, and collaborative room media.

Effective: 21/07/2026
Read Time: ~10 mins
Standard: DPDP Act (India) & GDPR
Core Privacy Pledge: ThinkNCollab never sells, monetizes, or brokers your personal information. We never use your private repository source code or terminal streams to train public artificial intelligence models.
// 01 Commitment

Introduction & Legal Framework

ThinkNCollab ("we", "us", or "our") is dedicated to safeguarding the privacy, confidentiality, and security of developers, engineering teams, and organizations accessing our platform via thinkncollab.com, the thinkncollab-shell CLI, WebRTC rooms, and programmatic APIs.

This Privacy Policy explains our practices regarding the collection, processing, transmission, storage, and erasure of personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act, India), the General Data Protection Regulation (GDPR, EU), and applicable international privacy standards. For the purposes of DPDP, ThinkNCollab acts as the Data Fiduciary, and you act as the Data Principal.

// 02 Data Collection

Information We Collect

TL;DR — Minimal Data Collection
We only collect data strictly necessary to authenticate your account, render collaborative boards, process billing, and connect your team's developer integrations. We do not store raw credit card numbers.
2.1 Personal & Account Identifiers
  • Registration Details: Name, verified email address, optional contact phone number, and bcrypt-salted passwords.
  • Profile Information: Developer handle, avatar image (hosted via Cloudinary), job title, and bio information.
  • Payment & Billing Data: Payment methods and invoices processed securely through our PCI-DSS Level 1 compliant gateway (Razorpay). ThinkNCollab never stores raw credit card numbers or banking secrets.
  • Workspace & Board Records: Room names, Kanban cards, task assignments, due dates, tags, and team chat messages.
2.2 Technical & Operational Metadata
  • Network Logs: IP address, browser user-agent, operating system, and endpoint access timestamps (retained for security audits and DDoS protection).
  • Socket Connection States: Active room presence and connection heartbeats to display real-time member presence.
// 03 Terminal Privacy

ThinkNCollab CLI & Live Terminal Streaming

TL;DR — Terminal Streams Are Ephemeral
When you share a terminal via thinknsh share start, raw terminal bytes stream in-memory over encrypted WebSockets. We do NOT save, log, or mine your terminal output unless you explicitly record it.
3.1 Ephemeral Pseudo-Terminal (PTY) Relay

When you execute thinknsh share start in the ThinkNCollab CLI, an in-memory socket channel is established on the /thinknsh namespace. Terminal output chunks are relayed dynamically to authenticated room viewers. Terminal streams are entirely ephemeral — they are not recorded, transcribed, or stored on our servers unless the room owner explicitly activates session recording.

3.2 Local Developer Files (Never Uploaded)

The CLI creates local configuration files in your home directory that remain strictly on your local machine:

  • ~/.thinknsh_history — Your local shell command history (never leaves your computer).
  • ~/.thinkncollab/config.json — Local aliases and prompt settings.
  • ~/.tncrc — Encrypted local authentication token required for automated CLI operations.
Security Advisory: Ensure you do not echo or cat sensitive secrets (such as production .env files or master API keys) in shared terminal windows. ThinkNCollab is not responsible for credentials displayed in your terminal output.
// 04

How We Use Your Information

We process your personal information strictly for legitimate operational purposes and service delivery:

  • To authenticate your identity across our web workspace and CLI applications.
  • To render real-time collaborative Kanban boards, active user presence, and notification alerts.
  • To relay audio/video signals and screen-sharing packets during live developer meetings.
  • To calculate automated task priority recommendations via the TaskScoreCalculator algorithm.
  • To synchronize authorized GitHub commits, pull requests, and Google Calendar milestones.
  • To process subscription payments and prevent platform fraud, abuse, or DDoS vectors.
// 05

How We Share Your Information

ThinkNCollab maintains a strict policy: We do not sell, rent, or trade your personal data. Information is shared only under strict boundaries:

  • With Room Collaborators: Your name, avatar, online status, and room contributions are visible to authorized members within your workspace.
  • Authorized Subprocessors: Cloud infrastructure partners (MongoDB Atlas, Cloudinary, Razorpay, Nodemailer) bound by strict confidentiality and data protection agreements.
  • Legal Compliance: When strictly required by law enforcement, court subpoenas, or regulatory authorities pursuant to valid legal processes.
// 06 Security & WebRTC

Data Security & Encryption Architecture

TL;DR — Zero-Cloud Meeting Storage
Audio/video calls use browser-level encryption. Meeting recordings render directly in your browser and download to your local drive — our servers never hold or inspect meeting recordings.
  • Client-Side End-to-End Encryption (E2EE): Meeting audio/video media is encrypted inside isolated Web Workers using ECDH-P256 key exchanges and AES-256-GCM. Session keys are derived peer-to-peer in your browser and are never revealed to our signaling servers.
  • Zero-Cloud Recording Policy: Video meetings recorded via our built-in canvas recorder render locally on your machine's hardware and download directly to your disk. We do not store, stream, or buffer video meeting files on our cloud servers.
  • TLS 1.3 in Transit: All web traffic, CLI interactions, and WebSocket relays require TLS 1.3 / HTTPS encryption.
  • Data at Rest: Database records are encrypted at rest using AES-256 in MongoDB Atlas managed clusters.
// 07 AI Protection

AI & Machine Learning Model Training Shield

ThinkNCollab provides intelligent assistance, including the AI Project Manager (AI PM), automated task scoring, and meeting transcripts.

Our Developer AI Guarantee:
  • Zero Foundation Model Training: We NEVER use your proprietary source code, private Git repositories, terminal stream outputs, or confidential room conversations to train public artificial intelligence models.
  • Ephemeral Inference: AI summaries and task prioritization prompts are processed ephemerally and discarded once generated.
  • Zero Data Brokerage: We do not license, sell, or disclose your codebase metadata to third-party AI vendors.
// 08 Compliance

Your Rights (DPDP Act & GDPR Standards)

Under the Digital Personal Data Protection Act, 2023 (DPDP) and GDPR, you possess comprehensive rights as a Data Principal:

  • Right to Access & Summary: Request a summary of personal data processed by ThinkNCollab and the identities of any data fiduciaries with whom it was shared.
  • Right to Correction & Erasure: Update inaccurate personal details or request the permanent erasure of your account and personal identifiers within 30 days.
  • Right to Withdraw Consent: Revoke consent at any time for notifications, third-party integrations, or marketing emails.
  • Right to Nominate: Under the DPDP Act, nominate another individual to exercise your rights in the event of death or incapacity.
  • Right of Grievance Redressal: Direct complaints to our appointed Grievance Redressal Officer with guaranteed review within 30 days.
// 09

Cookies and Tracking Technologies

We use essential cookies strictly required to maintain secure user login sessions, remember workspace theme preferences, and prevent Cross-Site Request Forgery (CSRF). We do not use invasive third-party cross-site advertising trackers.

// 10

Children's Privacy

ThinkNCollab is directed at software engineers, teams, and professionals. We do not knowingly collect personal information from children under the age of 13. If you become aware that a child has provided us with personal data, please notify us immediately at privacy@thinkncollab.com for expedited removal.

// 11 Google Scopes

Google API Services & Limited Use Disclosure

ThinkNCollab enables optional integration with Google Calendar to synchronize team meeting schedules and task due dates.

  • Minimal Access Scopes: We request only the calendar.events scope necessary to read upcoming room events and create task milestone reminders.
  • No Ancillary Scopes: We never request access to Gmail, Google Drive, Google Contacts, or private files.
  • Limited Use Compliance: ThinkNCollab's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • Revocation: You can disconnect Google Calendar anytime via room settings or your Google Account Permissions page.
// 12 GitHub Scopes

GitHub App & Webhook Data Privacy

When connecting GitHub via our official GitHub App, OAuth, or Webhooks:

  • Read-Only Metadata: We process commit titles, branch names, pull request numbers, and author handles to update Kanban cards on your board.
  • No Proprietary Code Storage: We do not copy, index, or store your private codebase files, proprietary algorithms, or repository source code.
  • Immediate Revocation: You can uninstall the ThinkNCollab GitHub App at any time from your GitHub Installation Settings to immediately sever webhook feeds.
// 13

Subprocessors and Infrastructure Partners

We engage vetted infrastructure subprocessors to provide database hosting, media delivery, and payment gateways:

Service Provider Purpose Location / Compliance
MongoDB Atlas Encrypted Cloud Database & Session Store AWS/GCP Cloud (SOC 2, ISO 27001)
Cloudinary Profile Avatars & Attachment Storage Global CDN (ISO 27001)
Razorpay Payment Gateway & Invoicing India (PCI-DSS Level 1 Compliant)
Google Cloud Platform OAuth 2.0 Sign-in & Calendar API USA / Global (ISO 27001, SOC 2)
Mediasoup WebRTC SFU Audio/Video Media Relays Encrypted Peer-to-Peer / SFU Blind Relays
// 14 Retention

Data Retention & Automated Erasure Schedule

Data Category Retention Window Purge & Eradication Procedure
Account Credentials & Profile Account Lifespan + 30 Days Permanent DB deletion, tokens revoked, avatar purged
Terminal Relays (thinknsh) 0 Seconds (Ephemeral) Transmitted in volatile memory only; zero disk persistence
Active Web Session Cookies 30 Days Maximum Automatic MongoStore TTL index expiration
Password Reset Tokens 10 Minutes Automatic MongoDB TTL index deletion
Server Security Logs 90 Days Automated daily log file rotation & purge
Transaction & Invoice Records 7 Years Required by statutory tax and accounting laws
// 15

Changes to This Privacy Policy

We may update this Privacy Policy to reflect technical advancements or legal revisions. When updates are published, the "Effective Date" at the top of this document will be updated. In cases of material changes, we will provide at least 30 days' advance notice via email or prominent in-app notification.

// 16 Grievance Redressal

Grievance Redressal Officer & Contact Details

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, ThinkNCollab has appointed a designated Grievance Redressal Officer:

Office: Data Protection & Grievance Redressal Cell

Organization: ThinkNCollab

Email: support@thinkncollab.com

Postal Address: Sushant AquaPolis, Crossing Republik, 201016, U.P

Support Line: +91 96484 70308

// privacy officer

support@thinkncollab.com

DPDP / GDPR Inquiries

// general support

support@thinkncollab.com

Technical Assistance

// web portal

thinkncollab.com/contactus

Online Helpdesk