Privacy policy

Effective September 19, 2026

The Thing is a public conversation at thething.cc. The operator is Chad Boyda, a sole proprietor based in Austin, Texas, United States. This policy explains how he processes information when you read, sign in or contribute. Contact privacy@meinfull.com for privacy requests and support@meinfull.com for service questions, identifying The Thing in your message.

Information we process

We store your email address to verify access to your account and send sign-in codes or links. Your email is not displayed on your public profile. We store session records and an essential sign-in cookie. Sign-in credentials expire after ten minutes; sessions can last up to a year unless revoked.

Your display name, handle, bio, published posts, replies and published attachments are public. Anyone may read, copy or share them, and search engines may index them. We retain earlier handles to prevent another account from taking them. A handle is a public identifier, not a guarantee of anonymity.

Your private in-app notifications record replies, grouped reactions and publication events, along with read positions and your reaction-alert preference. Notifications are scoped to your signed-in account; the service does not send notification email or push alerts. Delivery receipts and reaction-state history support duplicate prevention and reliable delivery.

We also store submitted messages, attachments, assessment results, relevant conversation context, timestamps and queue outcomes. Rejected submissions and detailed feedback are available to their author rather than displayed in the public feed. Service providers process information needed to operate the service.

Saved thoughts are private account bookmarks. Public search returns published contributions, not private submissions or assessment feedback. You can remove bookmarks without changing the public contribution.

Your browser saves drafts, attachment references, appearance preferences and reading position locally. Saved or recovered drafts can remain on that browser until you clear them or clear browser storage. Attaching media uploads it before publication. Links can be sent for preview generation while you compose. Avoid including confidential links, secrets or another person's sensitive information.

Our infrastructure receives network and device information needed to serve requests and prevent abuse. The application uses hashed identifiers for rate limits and approximate view counts. Reactions are associated with your account; aggregate reaction and view counts are public. Hosting and security providers may process network information under their own policies.

The website also loads Cloudflare Web Analytics to measure visits and page performance. Cloudflare states that this analytics service does not use cookies or local storage for analytics and does not fingerprint visitors. Hosting, security checks, sign-in cookies and local drafts are separate from that analytics service.

When you report a post or reply, we retain the reason, your details, a snapshot of the reported content, timestamps, and review status or decision notes. Your report receipts are private to your account; the operator can access the review queue and related audit records. Receiving a report does not mean it has been reviewed. Hiding a publication does not erase its retained submission or reporting records, or copies already delivered to others.

Assessments and providers

We use automated assessments to score contributions, select eligible posts and moderate spam. Assessment input can include the submitted text, attached media descriptions, relevant posts or replies, your public profile and limited recent submission history. These judgments can be wrong and do not establish that a statement is true or identify who wrote it.

Cloudflare provides hosting, storage, delivery and Turnstile security checks. Resend delivers sign-in email. TypeSafe/Jev processes contribution assessments. OpenRouter and its model providers process image and video descriptions; the current models use Google Gemini. Video analysis samples content and can miss details. Provider retention and processing depend on their terms and the services used. We do not promise zero retention or that every provider excludes all data from model improvement.

We use the information to deliver the conversation, authenticate accounts, process contributions, preserve drafts and results, prevent abuse, respond to requests and maintain the service. We may disclose information when legally required, to investigate security or rights complaints, or to protect people and the service. A business transfer may involve service records subject to applicable law and notice requirements. The application does not currently implement advertising sales or ad personalization.

Retention and choices

Account records, public contributions and published media are retained while needed to operate the service or meet legal obligations. You can edit your profile and remove your own not-accepted main submissions from Your contributions. That action removes their text and assessment detail from that record; minimal identifiers, hashes, timing and abuse-prevention records remain. Unpublished media is scheduled for cleanup after seven days. Separate copies or references, published content, and content already copied by others may remain. The service does not promise instant erasure of all backups, provider records or public copies.

The account dialog lets you prepare a JSON download of your retained account records, including submissions and assessment feedback, replies, bookmarks, reactions, notifications, your report receipts and media metadata. Uploaded image files are linked separately; browser-only drafts, authentication secrets and other accounts’ private data are not included. The file is prepared in pages over an interval, not as a single atomic snapshot. Report target snapshots and the operator’s global review queue are excluded. This download does not delete your account or contributions. There is currently no self-service account-deletion control.

You can withdraw a reaction by selecting it again, sign out, and clear local browser storage. Clearing local storage can also remove drafts. For access, correction, export, deletion or other privacy requests available under applicable law, contact privacy@meinfull.com. We may ask for information needed to verify that the request concerns your account. Some records may need to be retained for security, disputes or legal obligations. Where applicable, you may complain to your data-protection authority.

Providers may process information in countries other than your own. Security measures reduce risk but no service can guarantee complete security. We will update this policy when practices change and identify its effective date; material changes will receive additional notice where required.