Security & Privacy

Your strategy stays yours.

thatcurlymind.space is private by design. We explain where plan content goes, when external processing occurs, and which controls you have over saved source material and reports.

A precise promise—not an absolute one.Your information must be handled by authorized infrastructure to store and analyze it. We therefore describe the safeguards and limits openly instead of claiming that no service can ever process your content.
Current safeguards

Protection built into the workflow

Account isolation

Database row-level security restricts plans and reports to the account that owns them. Other users cannot retrieve them through the application.

Intentional processing

Nothing is sent for analysis until you select a thinking method, acknowledge the processing notice, and choose Run analysis.

Server-only credentials

Database administration and AI service credentials remain on the server and are never delivered to your browser.

User-controlled deletion

You can remove source-plan text while retaining completed reports, or delete an individual report from My Analyses.

Your data journey

What happens to a plan

No analysis begins simply because you saved or pasted content.

01

You save a plan

Pasted plan text is stored with your account in a managed private database so you can run a selected analysis and return to your work.

02

You authorize analysis

After your explicit acknowledgment, the plan is transmitted securely to the external AI processor solely to generate the requested report.

03

Your report is returned

Structured results are saved back to your private workspace and can be reopened from My Analyses.

04

You decide what remains

Remove the original plan without losing its reports, or delete reports you no longer want in active account storage.

Service categories

How the service is supported

We disclose what each supporting service does without exposing the proprietary technology choices behind the analysis workflow.

Managed account and database serviceAuthentication, account isolation, and private plan and report storage
Account data
Secure application hosting serviceApplication delivery, encrypted connections, and server-side processing
Infrastructure
Third-party AI processing servicePlan analysis only after the user acknowledges processing and chooses Run analysis
Analysis
Important limits

What users should know

Under the AI service’s standard API controls, submitted content is not used for model training unless the service account explicitly opts in. Content may still be retained in abuse-monitoring logs for up to 30 days. Background analysis also requires temporary response storage so the application can check when a report is ready.

Removing content deletes it from the application’s active database. Infrastructure backups and processor logs may remain for the limited periods described by each provider’s retention practices.

During this product preview, do not submit personal, regulated, legally privileged, or highly confidential information.

Your controls

Review or remove saved information.

Sign in and open My Analyses to remove source text or delete individual reports.

Open your private workspace

Last updated September 14, 2026. A formal Privacy Policy and Terms of Service will be added before paid public launch.