Privacy Policy
Thought Architecture — operated by TK Publications (ABN 76 792 942 026)
Last updated: 29 July 2026
1. About this Policy
This Privacy Policy explains how TK Publications, a partnership registered in Queensland, Australia (ABN 76 792 942 026), trading as Thought Architecture (we, us, our), collects, holds, uses, discloses and protects personal information when you use the Thought Architecture coaching application and thoughtarchitecture.com.au (together, the Service).
We are committed to handling personal information consistently with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
By creating an account or using the Service, you confirm that you have read this Policy.
2. Personal information we collect
We collect the information reasonably needed to provide, secure and support the Service. This may include:
- Account information: your email address, Firebase user identifier, email-verification status and authentication information used to create and secure your account.
- Profile information: information you choose to provide during onboarding or in Settings, such as your name, role, industry, team size, decision types, coaching preferences and what you want to improve.
- Coaching information: the questions, messages, reflections and work situations you enter; coaching responses; stage information; Thought Readiness Scores; session summaries; Thought Blueprints; optimised prompts; and names you give sessions or saved Blueprints.
- Subscription information: your selected plan, subscription status, billing interval, trial status, Stripe customer and subscription references, invoice state and relevant billing dates. Stripe—not Thought Architecture—collects and stores your full payment-card details.
- Technical and operational information: timestamps, activity and session counts, request status, message lengths, model and stage names, error classifications, session or playbook references, and pseudonymised account references used to operate, secure and diagnose the Service.
- Safety information: if automated safety controls flag an interaction, we may temporarily record the flagged message, reason, session reference and account reference to investigate misuse and protect the Service.
- Support information: information you include when you contact us about your account, billing or the Service.
Coaching information may become personal or sensitive depending on what you choose to enter. Do not enter unnecessary identifying, confidential or sensitive information about another person. You are responsible for having an appropriate basis to provide any third-party information.
We do not currently collect information for marketing emails through the Service.
3. How we collect information
We collect personal information:
- directly from you when you create an account, complete onboarding, use a coaching session, save a Blueprint, manage a subscription or contact us;
- automatically through Firebase, our application and security systems when you use the Service; and
- from service providers such as Stripe when they send us subscription, invoice and payment-status events.
4. Why we use personal information
We use personal information to:
- create, verify, secure and manage your account;
- provide and personalise coaching sessions;
- generate coaching responses, scores, summaries, Thought Blueprints and optimised prompts;
- provide your dashboard, session history and Playbook;
- create and administer trials, subscriptions, renewals, failed-payment recovery and cancellations;
- enforce session limits and other account controls;
- detect, investigate and prevent errors, misuse, fraud and security incidents;
- respond to support, billing, privacy and legal enquiries;
- maintain, diagnose and improve the reliability and usability of the Service; and
- comply with legal, regulatory, taxation, accounting and record-keeping obligations.
5. Artificial intelligence and automated processing
Your coaching content is sent to Google's paid Gemini API to generate coaching responses, Thought Readiness Scores, summaries, Thought Blueprints and optimised prompts.
Under Google's terms for paid Gemini API services, Google does not use prompts or responses to improve its products. Google may process or retain limited information as described in its terms, including for security, abuse monitoring, legal compliance and operation of the service. Google's terms and practices may change; current information is available in the Gemini API Additional Terms.
The Thought Readiness Score is generated automatically from session content. It is a reflective indicator, not a professional assessment. It does not make a decision that has a legal or similarly significant effect on you and does not determine whether you may access the Service.
6. Who we disclose information to
We do not sell personal information.
We disclose personal information only where reasonably necessary to provide or protect the Service, including to:
- Google: Firebase Authentication, Firestore, App Hosting, Cloud Logging and the paid Gemini API for account, hosting, database, diagnostic and AI-processing services.
- Stripe: to create checkout and customer-portal sessions, process payments and manage trials, subscriptions, invoices, failed payments and cancellations.
- Sentry (Functional Software, Inc.): to receive error and performance diagnostics so we can detect and fix faults. We configure Sentry to remove or redact request bodies, coaching content, credentials, cookies and known personal identifiers where technically available.
- Professional advisers and contractors: such as legal, accounting, security or technical advisers where reasonably necessary and subject to appropriate confidentiality obligations.
- Regulators, courts and law-enforcement bodies: where required or authorised by law or reasonably necessary to establish, exercise or defend a legal claim.
7. Where information is stored and processed
Your account information, coaching content, scores and related Firestore records are stored in Google Cloud Firestore's nam5 multi-region in the United States.
The production Thought Architecture application runs on Firebase App Hosting in Google's asia-southeast1 region in Singapore.
When you use the coach, content is sent to Google's paid Gemini API and may be processed outside Australia. Stripe may store or process subscription and payment-related information in countries including the United States. Sentry processes diagnostic events through its European infrastructure.
This means personal information may be disclosed to recipients outside Australia, including in the United States, Singapore and the European Union. We take reasonable steps appropriate to the circumstances to select reputable providers, limit the information disclosed, configure protective controls and require information to be handled consistently with applicable privacy and security obligations.
8. How long we keep information
We retain personal information only for as long as reasonably needed for the purposes described in this Policy, subject to the following periods:
- Account, profile and coaching information: retained while your account remains open unless you delete individual sessions or all session history sooner. It is deleted from our live Firestore records when you delete your account.
- Safety events: if an interaction is flagged, the flagged message and related technical information are scheduled to expire after 90 days. Safety events are deleted sooner if you delete your account.
- Operational records: limited pseudonymised operational records in Firestore—such as event names, timing, session or playbook references, score totals and error classifications—are scheduled to expire after 90 days. Firestore TTL deletion is asynchronous, so deletion may occur after the expiry time rather than at that exact moment. These records do not contain coaching transcripts, names or email addresses.
- Cloud Logging: a separate copy of some operational events may be retained in Google Cloud Logging according to the configured retention period for that logging service.
- Legal-acceptance receipt: a minimal pseudonymised receipt recording the legal-document version, acceptance time and a hashed account reference is retained for six years. It does not contain your name, email, profile, coaching content, scores, Blueprint or payment-card information and may remain after account deletion.
- Subscription and financial information held by Stripe: Stripe may retain customer, subscription, invoice and transaction information after you delete your Thought Architecture account to provide payment services and meet its own legal, regulatory, fraud-prevention and record-keeping obligations. We do not store full payment-card details in Firestore.
- Backups and recovery systems: information removed from live systems may remain temporarily in provider backup or recovery copies until those copies are overwritten under the provider's normal recovery cycle. We do not restore information you deliberately deleted except where necessary to recover the Service after a failure or where required by law.
9. Your rights and choices
Subject to applicable law, you may:
- ask for access to personal information we hold about you;
- ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading;
- delete individual sessions, all session history or your account using the controls in the Service;
- ask questions about automated processing or how we handle your information; and
- make a privacy complaint.
We will respond within a reasonable period. We do not usually charge for an access or correction request, although the law may permit a reasonable charge in limited circumstances.
10. Account and data deletion
You can delete your account without contacting us: open Settings, expand Data management, choose Delete account and confirm by typing DELETE.
Account deletion:
- removes your profile, sessions, transcripts, scores, Thought Blueprints, Playbook entries and sign-in record from the live application;
- deletes safety events and other user-owned application records included in the deletion process; and
- cancels an active Stripe subscription.
Deletion does not immediately remove:
- the six-year pseudonymised legal-acceptance receipt;
- operational records that are awaiting their scheduled expiry;
- Stripe's customer, subscription, invoice and transaction records; or
- temporary provider backup or recovery copies.
These exceptions are described in section 8. Deleting your Thought Architecture account does not delete records independently held by Stripe under its own obligations.
If you cannot use the self-service control, email us at the address in section 16.
11. Account and billing messages
We do not currently send marketing emails from the Service.
Firebase Authentication may send essential account messages, including email-verification and password-reset messages. Stripe may send essential subscription, invoice or payment-recovery messages. These messages are necessary to administer your account or subscription and are not marketing messages.
12. Security
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include encrypted network connections, authentication, server-side authorisation checks, database security rules, restricted credentials, diagnostic-data scrubbing and monitored error reporting.
No online service can be guaranteed completely secure. You are responsible for protecting access to your email account and for keeping your login details secure.
13. Login storage and browser preferences
The Service uses browser-session storage necessary to keep you signed in while your browser session remains open. Closing the browser ends that stored sign-in session, subject to the way your browser restores sessions and tabs.
We may store small functional preferences, such as whether you collapsed the dashboard guide. We do not currently use advertising cookies or third-party advertising analytics. If we introduce non-essential analytics or tracking in future, we will update this Policy and seek consent where required.
14. Data breaches
If a data breach is likely to result in serious harm, we will assess it and notify affected individuals and the Office of the Australian Information Commissioner where required under the Notifiable Data Breaches scheme.
15. Changes to this Policy
We may update this Policy where the Service, our providers or applicable laws change. We will publish the updated version and effective date. Where a change is material, we will take reasonable steps to notify you and may require you to acknowledge the updated legal documents before starting another coaching session.
16. Contact and complaints
For questions, access or correction requests, account-deletion assistance or privacy complaints, contact:
- TK Publications (Thought Architecture)
- ABN 76 792 942 026
- Email: hello@tkpublications.com.au
We will acknowledge and investigate a complaint within a reasonable time. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.
© TK Publications 2026. All rights reserved. Thought Architecture™




