1. Who We Are
ThoughtPilot AI ("ThoughtPilot", "we", "us", or "our") is a SaaS platform operated by Muhammad Okasha, based in Dubai, United Arab Emirates. We provide AI-assisted LinkedIn content creation and career intelligence tools.
For privacy enquiries, contact us at: privacy@thoughtpilotai.com
2. Information We Collect
2.1 Information you provide directly
- Account data: name, email address, and password when you register.
- Profile data: your professional role, industry, years of experience, location, skills, achievements, and writing tone preferences — used to personalise generated content.
- CV / résumé text: text you paste or upload for analysis. Stored in your profile as
about_summary.
- Content you create: posts drafted, approved, or scheduled through the platform.
- Payment information: billing is handled entirely by Paddle (our payment processor). ThoughtPilot does not store card numbers or full payment details — only your plan status and Paddle customer ID.
- Communications: messages you send to our support team.
2.2 Information collected automatically
- Usage data: pages visited, features used, posts generated, and actions taken — used to improve the product and enforce plan limits.
- Device and browser data: IP address, browser type, operating system, and timezone — collected for security and service delivery.
- Authentication tokens: a secure HTTP-only cookie (
tp_token) is set on login to maintain your session. It expires after 7 days.
2.3 Information we do not collect
- We do not access your LinkedIn account or require LinkedIn credentials.
- We do not collect data from third parties about you without your knowledge.
- We do not use tracking pixels or cross-site advertising trackers.
3. How We Use Your Information
- Providing the service: generating posts, analysing CVs, matching job descriptions, and delivering your content calendar.
- Personalisation: training the AI co-pilot on your voice profile so output reads like you, not generic AI.
- Account management: authentication, plan enforcement, billing, and notifications.
- Product improvement: aggregate, anonymised analytics to understand how features are used. Individual post content is never used for this.
- Security: detecting abuse, fraud, and unauthorised access.
- Legal compliance: meeting obligations under applicable laws.
4. AI and Your Data
ThoughtPilot uses third-party AI APIs (Groq and Google Gemini) to generate content. When your data is sent to these APIs for processing, it is used only to fulfil your request in real time. Your profile data, posts, and CV are never used to train shared or public AI models — by ThoughtPilot or by our AI providers under our agreements with them.
Your voice profile — the tone, style, and preferences we learn about you — belongs exclusively to you and is stored only in your account.
5. Data Sharing
We do not sell your personal data. We share data only in these limited circumstances:
- AI processing: Groq and Google (Gemini) receive the minimum data necessary to generate content on your behalf, under data processing agreements.
- Payments: Paddle processes billing. Their privacy policy applies to payment data: paddle.com/legal/privacy.
- Email delivery: Resend sends transactional emails on our behalf. Only your email address is shared for this purpose.
- Infrastructure: Railway (backend hosting) and Vercel (frontend hosting) process data as part of service delivery, under data processing agreements.
- Legal requirements: we may disclose data if required by law, court order, or to protect the rights and safety of our users.
6. Data Retention
We retain your account and profile data for as long as your account is active. If you delete your account, all personal data is permanently deleted within 30 days, except where we are legally required to retain it (e.g., billing records for 7 years under UAE commercial law).
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data — most profile data can be updated directly in Settings.
- Delete your account and all associated data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email privacy@thoughtpilotai.com. We respond within 30 days.
8. Cookies
We use a single essential session cookie (tp_token) to keep you logged in. We do not use advertising or tracking cookies. For full details, see our Cookie Policy.
9. Security
We use industry-standard measures including TLS encryption in transit, encrypted storage at rest, and JWT-based authentication. For more detail, see our Security page.
10. International Transfers
ThoughtPilot is operated from the UAE. Our hosting providers (Railway, Vercel) and AI processors (Groq, Google) may process data in the United States or other countries. We ensure appropriate safeguards are in place for any such transfers.
11. Children
ThoughtPilot is intended for users aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify you by email or by a notice in the app at least 14 days before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.
13. Contact
For any privacy questions or requests: privacy@thoughtpilotai.com
ThoughtPilot AI · Dubai, United Arab Emirates