Privacy Policy
Last updated: 2026-09-04
Think Mile collects and uses personal data so students can create accounts, store documents, manage applications, and use AI-assisted tools. This page explains what we collect, why we collect it, how long we keep it, and what choices you have. We follow applicable privacy and data-protection rules, including GDPR where it applies.
Who Operates Think Mile
Think Mile is managed by Ankit Jaiswal (Manager). Business registration is in progress. Data-protection and grievance requests can be sent to thinkmile@gmail.com.
Information We Collect
Account and contact data
Name, email address, phone number, country, account identifiers, and communication preferences.
Profile and application data
Education history, grades, target programs, university preferences, work history, essays, CV data, recommendation-letter inputs, and related admissions information.
Uploaded documents
Files you upload such as CVs, SOPs, transcripts, certificates, passports, visa-related files, and other application materials.
AI workflow inputs and outputs
Prompts, extracted document fields, generated drafts, revision history, and feedback you submit on AI outputs.
Technical and security data
IP-derived security logs, device and browser data, timestamps, cookie preferences, and anti-abuse signals.
Google Sign-In and Your Data
If you choose Continue with Google, Google shares your name, email address, email verification status, profile picture when available, and Google account identifier with Think Mile through Supabase, our authentication and database provider. We use this information to create or identify your Think Mile account, sign you in securely, and populate your profile. Your account name and email also support service communications, including welcome messages and account support.
We request only basic identity permissions (openid, email, and profile). Google sign-in does not give Think Mile access to your Google password, Gmail messages, Google Drive files, Google Calendar, or contacts. It does not import application documents or start AI processing. When you choose an AI-assisted feature, the information you provide or select is handled as described below.
Google account and profile information is stored with your Think Mile account in Supabase. Cloudflare delivers and protects the application, and our email provider processes the name and email needed for service messages. Access is limited by account permissions and authorized operational roles, and information is transmitted over HTTPS. The Service Providers and Storage section explains other providers and international processing that may apply when you use a feature.
We retain Google account and profile information while your Think Mile account is active, subject to the Data Retention section below. You can request export or deletion through the dashboard privacy center or email info@thinkmile.in. You can also remove Think Mile's access in your Google Account's third-party connections settings. Removing that connection stops future Google access but does not itself delete information already stored in your Think Mile account. Deletion requests remain subject to the retention exceptions below.
How We Use Data
- Provide the services you request, including document storage, profile management, and guidance workflows.
- Operate AI-assisted features for extracting document data and generating drafts such as SOPs, CVs, LORs, and study plans.
- Authenticate users, secure accounts, prevent abuse, and investigate fraud or misuse.
- Send essential service messages, application updates, and support replies.
- Measure product usage and improve the platform using aggregate statistics that do not identify individual users.
- Comply with legal obligations, enforce our terms, and maintain audit trails for consent and privacy requests.
We use AI tools to process user data for generating documents such as SOPs, CVs, and LORs, and for document-analysis tasks that support those workflows.
Think Mile does not maintain a user-derived model-training corpus or train models on your uploaded documents, prompts, generated drafts, or free-text feedback. If we propose a separate model-improvement dataset in the future, we will first provide a distinct, explicit choice and update this policy with its purpose, data categories, recipients, retention, and withdrawal information.
Legal Bases
- To provide the service you asked us to provide.
- Based on your consent where we ask for it, including cookie choices and AI-processing confirmations.
- To run, secure, improve, and defend the platform where that is reasonably necessary.
- To meet legal or regulatory obligations where required.
Service Providers and Storage
We work with third-party service providers to run the platform. Depending on the feature, your data may be handled by:
- cloud infrastructure, database, authentication, and private file-storage providers
- security and anti-abuse providers for bot detection, abuse prevention, and access protection
- analytics providers used for aggregate website measurement where you allow optional analytics
- email and communication providers used to send transactional updates and support messages
- AI-processing providers used for document analysis, extraction, and draft generation when you use AI-assisted features
Documents and profile data are stored in our cloud-based systems. Some of the companies we rely on may process data outside your home country. Where that happens, we rely on the protections and contractual safeguards available for the relevant service.
Data Retention
- Account and profile records: kept while your account is active. After a verified account-deletion request, we revoke access immediately and remove primary-system records within 30 days unless a specific legal obligation or documented legal claim requires a limited hold.
- Uploaded documents and AI drafts: kept while your account is active so you can use the service. When you delete them or complete a verified account-deletion request, we remove the primary-system copies within 30 days unless a documented legal hold applies.
- Inactive accounts: reviewed after 24 months of inactivity. We give at least 30 days’ notice before deletion unless we need the account for an active service, a legal obligation, fraud prevention, or a documented legal claim.
- Support and administrative notes: kept for up to 24 months after the related case closes, with access limited to people who need them to provide support, protect the service, or resolve a dispute.
- Backups: encrypted backup copies age out within a maximum 180-day rotation. A deletion from primary systems is reflected as backup copies expire; we do not restore deleted personal data into production without reapplying the deletion.
- Billing, tax, and legally required records: kept only for the period required by the applicable law. We retain the minimum record needed for that obligation, not your full documents or AI drafts merely because a billing record exists.
- Consent, privacy-request, security, and operational records: kept only for the limited period needed to demonstrate compliance, prevent abuse, investigate an incident, or resolve a dispute; any longer retention requires a documented legal hold.
Your Rights and Choices
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete information.
- Delete specific uploaded documents directly from your dashboard where that option is available.
- Request export or deletion of account-level data through the dashboard privacy center or by contacting us.
- Withdraw optional consents for cookies or future AI-processing actions before starting a workflow.
- Object to or restrict certain processing where applicable law gives you that right.
Signed-in users can submit export and deletion requests from /dashboard/privacy. You can also email a data-protection or grievance request to thinkmile@gmail.com.
Cookies and Analytics
Essential cookies support security and core functionality. Optional analytics and preference settings depend on your cookie choices. You can review or update those choices at any time on our Cookie Settings page.
Security
We use access controls, private document storage, audit logging, and other technical and organizational measures intended to protect personal data. No system is completely risk-free, so you should also protect your own account credentials and avoid sharing sensitive information unnecessarily.
Changes to This Policy
We may update this policy as the product, business, or legal requirements change. The current version date appears at the top of this page. For important changes, we may ask for renewed acceptance in product flows.
Contact
Privacy questions, DSAR, or grievance requests can be sent to thinkmile@gmail.com. We may ask you to verify your identity before completing certain requests.