Privacy Policy

Effective Date: [Month DD, YYYY]

ThingCore ("ThingCore," "we," "us," or "our") provides tools and services that connect physical objects to AI-powered digital experiences. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our website, platform, and related services. By using ThingCore, you agree to the practices described in this Privacy Policy.

1. Information We Collect

We may collect account information (name, email, login credentials), contact information from inquiries, billing information processed by third-party payment providers, object and content data you upload to the platform, usage data about how you use the platform, device and technical data, audio/text/interaction data from voice and conversational features, and cookies and similar technologies.

2. Voice, Audio, and Transcript Data

When visitors use voice features, audio is sent to our speech-to-text provider (Google Cloud) to produce a transcript, processed by an AI model to generate a response, and synthesized back to speech (text-to-speech). We do not retain raw audio after a turn is processed; transcripts of conversations may be stored to power conversation history, analytics, and (if enabled by the object owner) object memory. Object owners can disable conversation memory per object. Transcripts are associated with the object and, where applicable, the visitor session.

3. Location Data

Some objects use optional geofencing, which requires the visitor's browser to share approximate or precise location so we can verify the visitor is within an owner-defined radius. Location is checked server-side at the time of interaction. Coarse location may also be recorded as part of scan/anomaly signals (below). Visitors can decline location sharing in their browser, though location-locked objects will not function without it.

4. Scan, Verification, and Anomaly Signals

To detect abuse and support QR/NFC verification, we record scan events that may include a hashed (not raw) IP address, coarse location, timestamp, user-agent, and a computed risk score. These signals are used for suspicious-scan detection, rate limiting, and verification history. We store a one-way hash of IP addresses for this purpose rather than the raw IP.

5. How We Use Information

We use information to provide and operate ThingCore, create and manage accounts, deliver object-based AI interactions, process transactions and credits, respond to support requests, monitor and improve performance, detect fraud and security issues, comply with legal obligations, and enforce our terms and policies.

6. AI Output Limitations

Responses generated by AI features may be inaccurate, incomplete, or not reflect the object owner's intent. AI output should not be relied upon as professional, legal, medical, or financial advice. Object owners are responsible for the knowledge and configuration they provide to their objects.

7. How We Share Information

We may share information with service providers that help operate the platform (hosting, analytics, payment processors, AI and speech providers), when required for legal compliance and protection, in connection with business transfers such as mergers or acquisitions, and when you direct us to share information.

8. Data Retention

We retain information for as long as reasonably necessary to provide the service, maintain business records, comply with legal obligations, resolve disputes, and enforce agreements. Scan event logs are intended to be retained on a rolling window and periodically purged. Raw audio is not retained after a turn completes.

9. Cookies and Analytics

We may use cookies, pixels, local storage, and similar technologies to support authentication, remember preferences, understand user behavior, and improve the platform. You may control certain cookies through your browser settings.

10. Data Security

We use reasonable administrative, technical, and organizational measures to protect information. No system is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

11. Children's Privacy

ThingCore is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can take appropriate action.

12. Your Choices and Rights

Depending on your location, you may have rights to access, correct, delete, or request a copy of your personal information, including conversation transcripts and lead/contact data associated with your account. Object owners control retention settings for their objects where such controls are provided. To make a privacy-related request, including deletion of visitor data tied to an object you operate, contact us at support@thingcore.ai.

13. Third-Party Services

ThingCore may integrate with third-party services (including Google Cloud for speech, AI model providers, Stripe for payments, and hosting/analytics providers) whose privacy practices are governed by their own terms and policies.

14. International Use

If you access ThingCore from outside the country where our operations are based, your information may be transferred to and processed in other jurisdictions.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the Effective Date and may provide additional notice.

16. Contact Us

If you have questions about this Privacy Policy or want to make a privacy request, contact us at support@thingcore.ai. ThingCore is based in North Attleboro, Massachusetts.

This Privacy Policy is a general website policy draft and should be reviewed with legal counsel before final publication.