Introduction & Legal Framework
ThinkNCollab ("we", "us", or "our") is dedicated to safeguarding the privacy, confidentiality, and security of developers, engineering teams, and organizations accessing our platform via thinkncollab.com, the thinkncollab-shell CLI, WebRTC rooms, and programmatic APIs.
This Privacy Policy explains our practices regarding the collection, processing, transmission, storage, and erasure of personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act, India), the General Data Protection Regulation (GDPR, EU), and applicable international privacy standards. For the purposes of DPDP, ThinkNCollab acts as the Data Fiduciary, and you act as the Data Principal.
Information We Collect
- Registration Details: Name, verified email address, optional contact phone number, and bcrypt-salted passwords.
- Profile Information: Developer handle, avatar image (hosted via Cloudinary), job title, and bio information.
- Payment & Billing Data: Payment methods and invoices processed securely through our PCI-DSS Level 1 compliant gateway (Razorpay). ThinkNCollab never stores raw credit card numbers or banking secrets.
- Workspace & Board Records: Room names, Kanban cards, task assignments, due dates, tags, and team chat messages.
- Network Logs: IP address, browser user-agent, operating system, and endpoint access timestamps (retained for security audits and DDoS protection).
- Socket Connection States: Active room presence and connection heartbeats to display real-time member presence.
ThinkNCollab CLI & Live Terminal Streaming
thinknsh share start, raw terminal bytes stream in-memory over encrypted WebSockets. We do NOT save, log, or mine your terminal output unless you explicitly record it.When you execute thinknsh share start in the ThinkNCollab CLI, an in-memory socket channel is established on the /thinknsh namespace. Terminal output chunks are relayed dynamically to authenticated room viewers. Terminal streams are entirely ephemeral — they are not recorded, transcribed, or stored on our servers unless the room owner explicitly activates session recording.
The CLI creates local configuration files in your home directory that remain strictly on your local machine:
~/.thinknsh_history— Your local shell command history (never leaves your computer).~/.thinkncollab/config.json— Local aliases and prompt settings.~/.tncrc— Encrypted local authentication token required for automated CLI operations.
.env files or master API keys) in shared terminal windows. ThinkNCollab is not responsible for credentials displayed in your terminal output.
How We Use Your Information
We process your personal information strictly for legitimate operational purposes and service delivery:
- To authenticate your identity across our web workspace and CLI applications.
- To render real-time collaborative Kanban boards, active user presence, and notification alerts.
- To relay audio/video signals and screen-sharing packets during live developer meetings.
- To calculate automated task priority recommendations via the TaskScoreCalculator algorithm.
- To synchronize authorized GitHub commits, pull requests, and Google Calendar milestones.
- To process subscription payments and prevent platform fraud, abuse, or DDoS vectors.
How We Share Your Information
ThinkNCollab maintains a strict policy: We do not sell, rent, or trade your personal data. Information is shared only under strict boundaries:
- With Room Collaborators: Your name, avatar, online status, and room contributions are visible to authorized members within your workspace.
- Authorized Subprocessors: Cloud infrastructure partners (MongoDB Atlas, Cloudinary, Razorpay, Nodemailer) bound by strict confidentiality and data protection agreements.
- Legal Compliance: When strictly required by law enforcement, court subpoenas, or regulatory authorities pursuant to valid legal processes.
Data Security & Encryption Architecture
- Client-Side End-to-End Encryption (E2EE): Meeting audio/video media is encrypted inside isolated Web Workers using ECDH-P256 key exchanges and AES-256-GCM. Session keys are derived peer-to-peer in your browser and are never revealed to our signaling servers.
- Zero-Cloud Recording Policy: Video meetings recorded via our built-in canvas recorder render locally on your machine's hardware and download directly to your disk. We do not store, stream, or buffer video meeting files on our cloud servers.
- TLS 1.3 in Transit: All web traffic, CLI interactions, and WebSocket relays require TLS 1.3 / HTTPS encryption.
- Data at Rest: Database records are encrypted at rest using AES-256 in MongoDB Atlas managed clusters.
AI & Machine Learning Model Training Shield
ThinkNCollab provides intelligent assistance, including the AI Project Manager (AI PM), automated task scoring, and meeting transcripts.
- Zero Foundation Model Training: We NEVER use your proprietary source code, private Git repositories, terminal stream outputs, or confidential room conversations to train public artificial intelligence models.
- Ephemeral Inference: AI summaries and task prioritization prompts are processed ephemerally and discarded once generated.
- Zero Data Brokerage: We do not license, sell, or disclose your codebase metadata to third-party AI vendors.
Your Rights (DPDP Act & GDPR Standards)
Under the Digital Personal Data Protection Act, 2023 (DPDP) and GDPR, you possess comprehensive rights as a Data Principal:
- Right to Access & Summary: Request a summary of personal data processed by ThinkNCollab and the identities of any data fiduciaries with whom it was shared.
- Right to Correction & Erasure: Update inaccurate personal details or request the permanent erasure of your account and personal identifiers within 30 days.
- Right to Withdraw Consent: Revoke consent at any time for notifications, third-party integrations, or marketing emails.
- Right to Nominate: Under the DPDP Act, nominate another individual to exercise your rights in the event of death or incapacity.
- Right of Grievance Redressal: Direct complaints to our appointed Grievance Redressal Officer with guaranteed review within 30 days.
Cookies and Tracking Technologies
We use essential cookies strictly required to maintain secure user login sessions, remember workspace theme preferences, and prevent Cross-Site Request Forgery (CSRF). We do not use invasive third-party cross-site advertising trackers.
Children's Privacy
ThinkNCollab is directed at software engineers, teams, and professionals. We do not knowingly collect personal information from children under the age of 13. If you become aware that a child has provided us with personal data, please notify us immediately at privacy@thinkncollab.com for expedited removal.
Google API Services & Limited Use Disclosure
ThinkNCollab enables optional integration with Google Calendar to synchronize team meeting schedules and task due dates.
- Minimal Access Scopes: We request only the
calendar.eventsscope necessary to read upcoming room events and create task milestone reminders. - No Ancillary Scopes: We never request access to Gmail, Google Drive, Google Contacts, or private files.
- Limited Use Compliance: ThinkNCollab's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Revocation: You can disconnect Google Calendar anytime via room settings or your Google Account Permissions page.
GitHub App & Webhook Data Privacy
When connecting GitHub via our official GitHub App, OAuth, or Webhooks:
- Read-Only Metadata: We process commit titles, branch names, pull request numbers, and author handles to update Kanban cards on your board.
- No Proprietary Code Storage: We do not copy, index, or store your private codebase files, proprietary algorithms, or repository source code.
- Immediate Revocation: You can uninstall the ThinkNCollab GitHub App at any time from your GitHub Installation Settings to immediately sever webhook feeds.
Subprocessors and Infrastructure Partners
We engage vetted infrastructure subprocessors to provide database hosting, media delivery, and payment gateways:
| Service Provider | Purpose | Location / Compliance |
|---|---|---|
| MongoDB Atlas | Encrypted Cloud Database & Session Store | AWS/GCP Cloud (SOC 2, ISO 27001) |
| Cloudinary | Profile Avatars & Attachment Storage | Global CDN (ISO 27001) |
| Razorpay | Payment Gateway & Invoicing | India (PCI-DSS Level 1 Compliant) |
| Google Cloud Platform | OAuth 2.0 Sign-in & Calendar API | USA / Global (ISO 27001, SOC 2) |
| Mediasoup WebRTC | SFU Audio/Video Media Relays | Encrypted Peer-to-Peer / SFU Blind Relays |
Data Retention & Automated Erasure Schedule
| Data Category | Retention Window | Purge & Eradication Procedure |
|---|---|---|
| Account Credentials & Profile | Account Lifespan + 30 Days | Permanent DB deletion, tokens revoked, avatar purged |
| Terminal Relays (thinknsh) | 0 Seconds (Ephemeral) | Transmitted in volatile memory only; zero disk persistence |
| Active Web Session Cookies | 30 Days Maximum | Automatic MongoStore TTL index expiration |
| Password Reset Tokens | 10 Minutes | Automatic MongoDB TTL index deletion |
| Server Security Logs | 90 Days | Automated daily log file rotation & purge |
| Transaction & Invoice Records | 7 Years | Required by statutory tax and accounting laws |
Changes to This Privacy Policy
We may update this Privacy Policy to reflect technical advancements or legal revisions. When updates are published, the "Effective Date" at the top of this document will be updated. In cases of material changes, we will provide at least 30 days' advance notice via email or prominent in-app notification.
Grievance Redressal Officer & Contact Details
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, ThinkNCollab has appointed a designated Grievance Redressal Officer:
Office: Data Protection & Grievance Redressal Cell
Organization: ThinkNCollab
Email: support@thinkncollab.com
Postal Address: Sushant AquaPolis, Crossing Republik, 201016, U.P
Support Line: +91 96484 70308