← Back to Critical Thinking Bot

Privacy Policy

Effective Date: October 7, 2026

This Service is operated by Critical Thinking Labs, based in the United Kingdom.

We aim to collect the minimum personal data necessary to operate this Service.

1. Information We Process

We do not require user accounts.

However, we may process limited personal data, including:

For analytics, we do not store or log conversation text, prompts, replies, transcripts, snippets, or embeddings.

2. Research Use

The bot is a research tool: Critical Thinking Labs studies how people think with AI using only the anonymous totals described in this policy, which carry no identifier and no conversation text. Findings are published as aggregate statistics only. The switch under Analytics below opts you out.

3. Conversations You Choose to Share With Us

Inside the bot, the + menu has “Share with Critical Thinking Labs”. Nothing is sent unless you read what it sends and press Send. When you do, we store the messages in that conversation, the intent and difficulty level you chose, the date, and the version of the consent text you saw. We store nothing else with it: no name, email address, IP address, identifier or device details.

We use shared conversations to study how people think with AI. They may be read by the Critical Thinking Labs team and quoted anonymously in research findings. They are processed on the basis of your consent, which you give by pressing Send.

Because nothing identifies you, we cannot find and delete a specific shared conversation afterwards, so share only what you are happy for us to keep. We keep shared conversations for as long as the research continues and review that at least once a year. If a conversation contains something you would rather keep private, including anything sensitive you typed, do not share it.

4. AI Processing

Text entered into the chat interface is transmitted to a third-party AI provider via API to generate responses.

We do not manually review conversations.

Conversation text is used to generate responses, but is not stored in our analytics database.

We do not sell, rent, or trade personal data.

5. Topic Totals

To understand what kinds of ideas people bring, the first message of each conversation is given one broad topic label (for example, “work and career” or “study and learning”) by the same AI provider that generates replies.

We store only a weekly count for each label, together with the intent chosen for the session. No identifier, timestamp, or text is stored with it, so a label cannot be linked to you or your device. Very small counts are not reported.

6. Local Browser Storage

This Service stores limited browser-side data including:

Earlier versions of the Service stored a random identifier in your browser. It is deleted the next time you open the bot, and no identifiers are stored any more.

Apart from an unsent message, conversation content and conclusion artifacts are not saved in your browser by default.

Any exported or shared content is only created when you explicitly trigger those actions.

7. Analytics

We use:

Our own analytics endpoint only adds your visit to anonymous totals and stores no identifier for you or your device. To count new and returning visitors without identifying anyone, your browser keeps the small visit record described above and sends only the values described under Visit counts, each of which we add to a separate total.

Our analytics endpoint is designed to reject payloads containing common text-content keys and accepts only allowlisted event metadata.

Don't include me in the research. You can turn research counting off for this device at any time.

When research counting is off, this device stops sending usage events (including the intent and difficulty level), visit counts, topic labels and Vercel Web Analytics page views, and its visit record is deleted. The bot works exactly the same. We also honor the Global Privacy Control (GPC) signal.

8. Data Storage

The only conversation text we keep is the conversations people choose to share with us (see above). Nothing else you type is stored by us.

We maintain daily analytics totals, including visit counts, and a table of weekly topic totals, none of which contain identifiers. We also keep, as historical records, the analytics events that earlier versions of the Service stored with pseudonymous browser identifiers (for example, event name, timestamp, session/anonymous IDs, the categories described above, and numeric usage metrics). No new events are added to that table.

However, third-party service providers (including hosting, analytics, and AI providers) may process or temporarily retain data in accordance with their own policies.

9. Children

The Service is intended for adults aged 18 and over, and you confirm this when you start a session. We do not knowingly process data from children. If you believe a child has used the Service, contact us using the address below.

10. Legal Basis (UK GDPR and, where it applies, EU GDPR)

We process limited data on the basis of our legitimate interests: for anonymous usage totals and visit counts, for the research described above, and for operating, securing, and improving the Service.

Conversations you choose to share with us are processed on the basis of your consent, given when you press Send. You can decide not to share at any point before that; after that, nothing identifies the conversation as yours.

The daily and weekly totals contain no personal data and are kept indefinitely.

The visit record in your browser is used only to produce statistics about how the Service is used, so that we can improve it. You can object at any time by turning analytics off on this page.

11. Your Rights

Under UK data protection law, you may have rights to:

To exercise your rights, contact: pr@iamshaeo.com

12. Changes

This Privacy Policy may be updated from time to time.