1. Scope and operator
ThinkDeepWide is operated by PENGQIAN LU in Sydney, Australia. This policy covers thinkdeepwide.com, the ThinkDeepWide desktop application, and its account and authorization services, including services made available to testers. For privacy matters, contact support@thinkdeepwide.com.
Public downloads and purchasing are not open yet. Payment processing that has not yet been enabled is described separately below.
2. Visiting the website
Cloudflare serves our pages, images, and video. It receives your IP address, requested URL, request time, and necessary information sent by your browser to deliver content, protect the network, and diagnose problems.
This website has no advertising, third-party visitor analytics, or marketing tracking scripts. The default entry uses network location provided by Cloudflare to direct visitors in mainland China to CN pages. A direct CN URL stays in that region. Switching between Chinese and English changes only the page language. We no longer set or read a region-preference cookie. Launch-notification signup, confirmation, and unsubscribe use an HttpOnly session cookie and an anti-forgery request token, without requiring a product account login. Clear this website’s browser data to remove this session.
The purchase page follows your current site. Sign-in uses an HttpOnly session cookie, and account actions use an anti-forgery request token. Signing out does not delete your account; clearing this website’s browser data removes these sessions.
The interactive walkthrough uses fixed, public examples and makes no AI requests. The main video and author photo are hosted on this website. Following the YouTube backup or X profile link takes you to a third-party site governed by its own privacy policy.
3. Launch notification list
If you choose to join launch updates, we store your email address, selected language, explicit consent record, and confirmation and unsubscribe status to send a notice when ThinkDeepWide launches. Joining does not create a product account or grant trial eligibility, a subscription, or a payment.
After you submit an address, we send a confirmation link that is valid for 24 hours. The link opens this website’s explicit confirmation or unsubscribe button; the service processes the request only after you click that button, so email scanners cannot complete it automatically. An unconfirmed address is not on the launch-notification sending list. Submitting an address that is already confirmed still says to check email, but does not send another confirmation message.
You can use the unsubscribe link in an email to stop future launch updates. After an unsubscribe, an old confirmation link cannot rejoin the list. An invalid or expired confirmation link offers a way to sign up again; a link that already confirmed an active address can be safely retried without another email or a change to the subscription.
4. Accounts, trials, and device authorization
Our account and authorization services process email addresses, account creation times, login verification and session records, device names and operating systems, installation identifiers and public keys, device bindings and last-seen records, and trial or subscription entitlement status. We use these to authenticate users, issue access, manage the two-device limit, and provide support.
The 5-message preview records transformed machine and installation identifiers, usage counts, request identifiers, action types, request digests, and acceptance times. These let us count usage across projects and conversations, identify repeated requests, and recover interrupted operations. A digest does not contain readable conversation text or project files, and the account service does not receive that content through this process.
When you choose to start a trial and verify your email, we check email, machine, and installation histories separately and keep the original trial dates and applicable deadline. This prevents reinstalling, changing email, or changing devices from granting a new trial. Transformed device identifiers, platform identifiers, and trial records already created in earlier test versions still preserve the original deadline; they are not used to find or merge product email accounts. The current email trial does not require Apple or Microsoft account verification. If platform verification is enabled in the future, its data uses will be explained separately.
The server checks login codes and session credentials using verification values. It also briefly retains protected session-recovery material and operation results to recover interrupted requests. Security rate limits use keyed representations of email, installation, or IP identifiers. These linkable identifiers are not fully anonymous. Service infrastructure may still receive raw IP addresses and other network information.
Amazon Web Services SES sends login codes, currently from its Singapore region. The provider receives the email address and message content needed for delivery. Requesting a code, signing in, or starting a trial does not join the launch-notification list; launch updates require separate signup and confirmed consent.
5. Conversations, projects, and model accounts
ThinkDeepWide’s account and authorization service does not receive your chat contents, project files, or model-provider credentials. Conversations and project data reside on your computer or a remote host you configure.
Using a model, web search, or other tools may send relevant questions, context, selected files, or tool inputs to your chosen model providers and services. Their data retention and use depend on the service, account plan, and settings you select. This policy does not replace their policies.
If you send a support email, screenshot, or error report, we process what you submit to help resolve the issue. Send only necessary information, without login codes, access tokens, or unrelated confidential project data.
6. Providers and international processing
We use Cloudflare for website and account infrastructure and AWS SES for login codes and launch-notification emails you consent to receive. Their global infrastructure or personnel may process data outside your country; we do not promise storage only in your country or region. We process or disclose data as needed to deliver and secure services, respond to your requests, or meet legal obligations. We do not sell your personal information.
Payments are not enabled. When Lemon Squeezy checkout is enabled, it will act as merchant of record and process payment and order information. We will receive order identifiers, purchase emails, and subscription status needed for access and support, without storing full payment-card details ourselves. We will update this policy before enabling checkout.
The current email trial does not use Apple or Microsoft verification. If you previously took part in platform-verification tests, the platform handles the information provided then under its own policies. Provider information: Apple Privacy Policy, Microsoft Privacy Statement, Cloudflare Privacy Policy, AWS Privacy Notice, and Lemon Squeezy Privacy Policy.
7. Retention and security
Expired login challenges, sessions, rate-limit records, replay-prevention records, and short-term recovery records are deleted by scheduled cleanup, rather than necessarily at the moment of expiry. Account, device-binding, entitlement, and support records are retained as needed to operate the service, resolve disputes, or meet legal obligations. There is currently no single automatic deletion period for all such records.
To preserve used preview allowances and original trial periods, transformed email, machine, and installation identifiers, preview usage records, and trial dates are retained long-term and are not automatically purged. Transformed platform and device identifiers and trial facts from earlier test versions are also retained separately from temporary sessions. Account deletion or device unbinding does not automatically reset trial eligibility. We assess and explain any retention when handling a deletion request, based on necessity and applicable law.
We use measures including encrypted transmission, access controls, and stored credential verification values. No system can guarantee absolute security. You are also responsible for protecting your computer, remote hosts, and exported files.
8. Choices, requests, and complaints
Contact support@thinkdeepwide.com to request access, correction, or deletion of personal information we hold, or to raise a privacy question or complaint. We may reasonably verify your identity. If information must be retained for security, disputes, or legal obligations, we will explain why. Where applicable law provides rights to restrict or object to processing, withdraw consent, or obtain portable data, you can use the same contact.
Clearing the website’s browser data affects only local data. Signing out or unbinding a device does not delete your account. Deleting account-service information does not automatically delete content on your own computer, remote hosts, or with third-party providers. You may also complain to a privacy regulator with jurisdiction.
9. Policy changes
We will update this page and its effective date when our data practices change. For material changes, we will use a website notice or available account contact details, and seek consent separately where required by law.