Thesis Desk
Privacy Policy
Last updated 11 September 2026
This policy explains what we collect, why we hold it, who else sees it and how long it stays. Two things are worth knowing before you read the rest. Your brief and your uploads are sent to the artificial intelligence providers listed in clause 6, because that is how a document gets written. And we never see your card details or your password, because neither one passes through us.
1Who is responsible for your information
1.1Thesis Desk is the controller of the personal information described in this policy. In this policy, “we”, “us” and “our” mean that operator, and “you” means the person using the service.
1.2This policy covers the website at thesis-deck-six.vercel.app, the signed-in product, the writing engine that produces documents, and the support correspondence attached to an order. It does not cover any other site you reach from a link we show you.
1.3It was last updated on 11 September 2026. It should be read with the Terms of Service, which govern the service itself.
1.4Questions, requests and complaints about privacy go to hello@thesisdesk.com, and we read them Monday to Saturday, 08:00 to 22:00.
2The short version
The summary below is here so nobody has to read nine thousand words to learn the important things. It is a guide to the policy, not a substitute for it, and where the two differ the detailed clauses govern.
- We collect what you type into a brief, what you upload with it, and what your account needs in order to exist.
- Your brief and the text of your uploads are sent to third-party artificial intelligence providers so that a document can be written. Do not put anything in a brief that you would not be willing to share with a processor outside this company.
- We never receive your card details. Payment happens entirely inside the payment provider.
- We never receive your password. Sign-in is handled by our identity provider.
- We do not sell your information, we do not advertise to you, we run no third-party analytics, and we do not use your documents to train models.
- Files belonging to a finished order are deleted thirty days after final handover. Keep your own copy.
- You can read, correct, export and delete your information, and you can close your account. Clause 14 says how.
- We do not contact your university, your supervisor or your employer, and we do not tell them you used us, unless the law makes us.
3What we collect
3.1The table below lists every category of personal information the product holds, and what sits inside each one.
| Category | What it contains |
|---|---|
| Account | Your name, your email address, whether you signed in with a password or with Google, and the date you joined. |
| Credentials | Handled by our identity provider. We never receive, store or transmit your password, and we cannot read it. |
| Profile | Your phone number, student or staff registration number, university, department, default citation style, academic level, and any institution logo you upload for a cover page. All of it is optional, and all of it is there so a brief does not have to be retyped. |
| Brief content | The kind of document, its title, field, academic level, supervisor name, word target, source count, citation style, research method, chapter plan, due date and your free-text notes. Anything you type into a brief is held, including anything personal you choose to put there. |
| Cover page | University, department, author name, registration number and degree, as you enter them for the front of the document. |
| Uploads | Rubrics, marking schemes, handbooks, reading lists, figures and their captions, institution logos, correction attachments and sample CVs. Their contents, including any personal information inside them, are held as you supplied them. |
| Career documents | For a CV brief: your full name, headline, email, phone, location, links, employment history with employers, dates, locations and duties, education and qualifications, skills, publications, referees’ names and contact details, the role you are applying for, and the advert text or its address. |
| Order records | Order references, status, the engine’s stage and progress notes, chapter lists, delivered files, correction rounds and the messages attached to an order. |
| Money | The credit ledger: credits bought, credits spent, the order each spend belongs to, the package purchased, the amount paid, and the payment provider’s transaction references and status. No card number, expiry date, security code or mobile wallet PIN ever reaches us. |
| Technical | Internet address, browser and device information, timestamps, request and error logs, rate-limit counters, and the result of the bot check on sign-up. |
| Preferences | Notification settings, including whether you want to hear about offers, which is off unless you turn it on. |
3.2We do not ask for special category information: health, ethnicity, religion, political opinion, trade union membership, sexual life, biometric or genetic data. A brief on a sensitive subject, or a CV describing a role in a sensitive field, may nonetheless contain it because you chose to write it. Where it does, it is processed only to write the document you asked for, and only because you provided it for that purpose.
3.3Please do not upload another person’s information without their knowledge. A referee’s phone number on a CV, a classmate named in a rubric and an interviewee quoted in your data are all somebody else’s personal information, and the Terms of Service put that responsibility on you.
4Where it comes from
4.1Most of it comes from you: what you type into the brief form, the settings screen, the corrections panel and the messages screen, and what you attach to any of them.
4.2Some is collected automatically when you use the site, namely the technical information in the table above, which our hosting and database providers record in order to serve and protect the service.
4.3If you sign in with Google, Google tells us your name, your email address and an account identifier. We ask for nothing else, and we never receive your Google password.
4.4Our payment provider tells us whether a payment succeeded, its reference and its status. It does not send us the instrument you paid with.
5Why we use it, and on what legal basis
5.1Every use below is tied to a purpose and a basis. Where a law in your country uses different terms for these bases, the equivalent basis under that law applies.
| Purpose | Information used | Basis |
|---|---|---|
| Create and run your account | Account, credentials, technical | Performance of our contract with you |
| Write the document you ordered | Brief content, uploads, cover page, career documents | Performance of our contract with you |
| Find real published sources to cite | Title, field and keywords derived from your brief | Performance of our contract with you |
| Take payment and keep the credit ledger straight | Money, account | Performance of our contract with you, and our legal obligation to keep accounting records |
| Answer your messages and handle corrections | Order records, account | Performance of our contract with you |
| Tell you when a chapter is delivered or a reply arrives | Account, preferences | Performance of our contract with you |
| Keep the service up, debug failures and improve it | Technical, anonymised order statistics | Our legitimate interest in a service that works |
| Stop bots, fraud, payment abuse and misuse | Technical, money, account | Our legitimate interest in protecting the service, and our legal obligations |
| Defend ourselves in a dispute or a claim | Whatever is relevant to that dispute | Our legitimate interest in establishing and defending legal claims |
| Send you news of offers | Account, preferences | Your consent, which you may withdraw at any time |
| Comply with the law and with lawful requests | Whatever the law requires | Our legal obligation |
5.2Where we rely on a legitimate interest, we have considered whether it is outweighed by your interests and rights, and we have recorded the conclusion. You may object to any such use under clause 14.
6The writing engine and artificial intelligence providers
This is the clause to read if you read only one. To write a document, we send the content of your brief, and text extracted from the files you uploaded, to external artificial intelligence providers over their interfaces. There is no way to produce the document without doing so.
6.1What is sent: the brief, the chapter plan, the text of rubrics and requirement files, figure captions, correction instructions, the details of published sources found in the literature search, and, for a career document, everything you entered on the CV brief together with the advert text or the text of the advert page you linked.
6.2Your name reaches a provider only where you have put it into the work itself, which happens by design on a cover page and on a CV. We do not attach your account email address, your phone number, your payment history or your account identifier to a request unless you typed them into the brief.
6.3A single document is written by several models in turn, because different steps suit different models and because a request that fails on one provider falls through to the next. Which providers are reachable depends on which are configured at the time, so treat the list in clause 8 as the full set that may be used, rather than a promise about any one document.
6.4Providers process what we send under their own interface terms. Those terms generally exclude interface traffic from model training and allow a provider to keep a copy for a short period to monitor abuse, commonly up to thirty days. We cannot control a provider’s policy, we do not warrant it, and it may change. The safe rule is the one at the top of this policy: do not put anything in a brief you would not be willing to share with a processor outside this company.
6.5We do not use your briefs, uploads or documents to train any model of our own, and we do not supply them to anyone for that purpose.
6.6Nothing in the engine makes a decision about you that produces a legal effect or anything similarly significant. It writes text. Decisions about your work, your grade and your career are taken by people elsewhere, on their own evidence.
7Literature searches
7.1To cite real work, the engine searches public scholarly databases: OpenAlex, Crossref, Europe PMC and Unpaywall. What travels to them is a search query built from your title, your field and the keywords in your brief, together with identifiers of works already found.
7.2Those services ask callers to identify themselves so they can manage load. The contact address we send is ours, not yours. Your name, your account and your identity are never part of a search.
7.3For a career document, the engine will fetch a job advert at an address you give us and read the page. That request goes to the site hosting the advert, which will see it as an ordinary visit from our server. Do not paste a link that only works because you are signed in somewhere.
8Who else sees your information
8.1We share personal information only with the sub-processors below, each for the purpose beside its name, and with the recipients described in clause 9.
| Who | What they do for us | What reaches them |
|---|---|---|
| Supabase | Database, authentication and file storage, hosted in the European Union | Everything the product stores: account, profile, briefs, uploads, orders, messages, credit ledger |
| Vercel | Hosting for the website and the interface | Technical information and the small requests the interface makes. No document ever passes through it |
| Railway or Render | Hosting for the long-running worker that writes documents | Brief content and uploads, while a document is being written |
| Cloudflare | The bot check on the sign-up form | Technical information and the challenge result |
| Paynow, operated by Otto Technologies | Taking payment for credit packages | The amount, a reference and the contact details a payment needs. They hold the card or wallet details; we do not |
| Optional sign-in | Only what is needed to complete a sign-in you started | |
| Artificial intelligence providers: OpenAI, Anthropic, Google, Mistral, DeepSeek, Groq, Cerebras, Together, DeepInfra, Cohere, Z.ai, and OpenRouter as a route to several of them | Generating the text of your document | The brief content described in clause 6 |
| OpenAlex, Crossref, Europe PMC, Unpaywall | Finding real published sources to cite | Search queries built from your brief, as described in clause 7 |
8.2Each sub-processor is bound to use what it receives only to provide its service to us. We review this list when we add a provider, and a provider added to the product belongs in this table.
9When we would disclose information to anyone else
9.1We do not sell your personal information. We have never sold it, and selling it is not part of any plan for this business. We do not share it with advertisers or data brokers, and we run no advertising or cross-site tracking on the site.
9.2We do not resell your documents, and the same document is not supplied to another customer.
9.3We do not report your use of the service to your university, your supervisor, your employer or anyone else, and we do not confirm or deny an account to a person who asks about someone else.
9.4We would disclose information where the law requires it: a court order, a lawful request from a law enforcement or regulatory body with jurisdiction over us, or a statutory obligation. We check that a request is valid and covers what it claims to cover, we disclose no more than it demands, and we tell you unless we are prohibited from doing so.
9.5We would also disclose information where it is necessary to establish, exercise or defend a legal claim, including a claim brought by or against you, and to our professional advisers under a duty of confidence.
9.6If the business is sold, merged or reorganised, information would pass to the buyer as part of it, under the same protections as this policy. We would tell you before that changed anything material for you.
10Where your information goes in the world
10.1The service is international. Our database, authentication and file storage sit in the European Union. Our site hosting, our artificial intelligence providers and the scholarly databases operate from several countries, mostly the United States and the European Union. Our payment provider operates from Zimbabwe.
10.2This means your information is transferred across borders, including to countries whose data protection law differs from the law where you live, and in some cases offers less protection than it does.
10.3Where a transfer is made from a jurisdiction that restricts it, we rely on the safeguards our providers offer for that route, which are typically standard contractual clauses or an adequacy decision covering the destination. You can ask us which safeguard applies to a particular provider and we will tell you.
11How long we keep things
11.1We keep information for the periods below, and then delete it.
| What | How long |
|---|---|
| Account and profile | While your account is open, then thirty days after you close it |
| Brief content, uploads and delivered documents | While the order lives in your account, and in any event deleted thirty days after final handover |
| A document you delete yourself | Removed immediately, with its brief, its uploads, its messages and its files |
| Order and correction history, without the files | Six years, because it is the record of what was sold to whom |
| Credit ledger and payment references | Six years, to meet accounting and tax obligations |
| Messages attached to an order | With the order record |
| Technical and error logs | Up to ninety days, longer for a log kept for a security investigation |
| Rate-limit counters | Hours to days |
| Records kept for a live dispute, claim or legal obligation | Until that matter ends, then deleted on the schedule above |
11.2Because delivered files are deleted thirty days after handover, download and keep your own copy of anything you may want later. We cannot recover a document after its file is gone, and we cannot re-create the identical text.
11.3Deletion means deletion from the live systems. A copy may persist for a short period in routine encrypted backups held by our database provider, and is overwritten as those backups age out.
12How we protect it
12.1Every table in the database enforces row level security, so a signed-in account can read and write only its own rows. That is checked in the database itself rather than in the interface, which means a flaw in a screen cannot expose another person’s data.
12.2Uploaded files live in per-account folders, and the storage rules check the account on every read and every write. Files are reached through signed links that expire, not through public addresses, and a link cannot be guessed.
12.3Traffic is encrypted in transit. Keys that can bypass the access rules, and the payment integration key, exist only on the server and never in anything sent to your browser.
12.4Files go straight from your browser to storage and come straight back. Documents do not pass through the application server, which is one fewer place for a copy to sit.
12.5We never hold your password, so we cannot leak it.
12.6No system is perfectly secure. We do not promise that ours cannot be breached, and the limits in the Terms of Service apply to any claim arising from a breach.
13If something goes wrong
13.1If personal information is lost, exposed or taken, we investigate, we stop the cause, and we record what happened.
13.2Where a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority within the period the applicable law requires. Where it is likely to result in a high risk to you, we tell you directly and without undue delay, and we say plainly what was affected and what you should do.
14Your rights over your information
14.1Depending on where you live, you have some or all of the following rights.
- Access
- Ask what we hold about you and receive a copy of it.
- Correction
- Have anything inaccurate corrected, and anything incomplete completed.
- Deletion
- Ask us to delete what we hold, where no legal obligation requires us to keep it.
- Portability
- Receive the information you gave us in a structured, machine-readable form.
- Restriction
- Ask us to stop processing while a dispute about accuracy or grounds is resolved.
- Objection
- Object to processing we base on a legitimate interest, and to direct marketing at any time.
- Withdraw consent
- Withdraw consent for anything based on it, which does not undo what was lawful before.
- Complain
- Complain to the data protection authority in your country.
14.2Some of these you can exercise yourself, immediately: the settings screen corrects your profile and switches notifications off, the document menu deletes an order with all of its files, and the billing page shows your whole credit history.
14.3For anything else, write to hello@thesisdesk.com from the address on your account and say what you want. We may ask for something that confirms you are the account holder, which is protection for you rather than an obstacle. We answer within one month, and where a request is complex we tell you inside that month that we need longer.
14.4There is no charge. We may refuse or charge for a request that is manifestly unfounded or excessive, and if we refuse we tell you why and how to challenge it.
14.5Deleting your account does not delete the accounting record of what you bought. That record is kept for the period in clause 11 because the law requires it, and it is reduced to what the obligation actually needs.
15Cookies and browser storage
15.1We run no advertising cookies, no cross-site tracking and no third-party analytics. Nothing on this site follows you to another one.
15.2Your sign-in session is stored by your browser so that you stay signed in between pages. It is written by our authentication library, it belongs to this site alone, and signing out clears it.
15.3The bot check on the sign-up form sets what it needs to tell a person from a script, and our hosting provider may set a cookie for load balancing and security.
15.4Your unfinished brief is saved as a draft so that closing the tab does not lose your work. It is stored against your account, and submitting or discarding the brief clears it.
15.5All of these are necessary for the service to work, which is why there is no consent banner asking you to accept optional ones. There are none to accept.
16Messages we send you
16.1Service messages are part of the product: a chapter delivered, a reply on an order, a payment confirmed, a change to these documents. You cannot switch those off while you hold an account, because they are how the service tells you what has happened to your work.
16.2Offers and product news are separate, off unless you turn them on, changeable on the settings screen, and every such message carries a way to stop them.
16.3We do not give your address to anyone else to market to you.
17Children
17.1The service is for adults. It is not directed at children, and you may not use it if you are under 18 or under the age of majority where you live.
17.2If we learn that we hold information about a child, we delete the account and the information with it. If you believe that has happened, write to hello@thesisdesk.com and we will deal with it promptly.
18Other sites
18.1The service links out: to a payment provider, to a source’s publisher, to a job advert you gave us. Those sites have their own policies, and this one does not cover them.
18.2A reference in a document is a pointer to somebody else’s work. Following it takes you to them, on their terms.
19Changes to this policy
19.1We update this policy when what we do changes, and the date at the top of the page always says when it was last revised.
19.2Where a change materially affects how we handle information you have already given us, we tell you by email or in the product before it takes effect. Continuing to use the service after that is acceptance of the revised policy.
20How to reach us
20.1For anything in this policy, including a request under clause 14, write to hello@thesisdesk.com. We read messages Monday to Saturday, 08:00 to 22:00.
20.2The controller is Thesis Desk.
20.3If you are not satisfied with our answer, you may complain to the data protection authority for your country. We would rather you came to us first, because most of what goes wrong is something we can simply fix.