Privacy Policy
Effective Date: March 19, 2026
This policy describes what information Thistle collects, how we use it, who we share it with, and what choices you have. We know you are trusting us with sensitive information about your family. We take that seriously.
1. Who We Are
Thistle is operated by Winter Green Solutions LLC, a Vermont limited liability company. When this policy says "we," "us," or "our," it means Winter Green Solutions LLC.
2. Information We Collect
Information you provide directly
- Your account information: email address and timezone
- Your child's profile: name, age, pronouns, and any notes you provide about their situation during onboarding
- Daily logs: free-text observations about your child and structured ratings (sliders for things like nervous system state, flexibility, connection, and your own capacity as a parent)
- Onboarding and flow answers: your responses to onboarding questions and any additional question flows you complete
- Ask questions: free-form parenting questions you submit through the Ask feature
- Parent context notes: any additional context you provide about your parenting situation
Information we generate
- AI-generated content: daily guides, weekly summaries, advice responses, profile summaries, and guide rationale — all produced by our AI pipeline based on the information you provide
- Safety and evaluation data: results of automated safety checks on AI-generated content, including pass/fail status and flagged concerns
Information collected automatically
- Usage data: basic information about how you interact with the app (pages visited, features used, session timing)
- Device and browser information: browser type, operating system, and device type (for web push notifications and app compatibility)
- Email delivery data: whether notification emails were delivered and opened
3. How We Use Your Information
To provide the service. Your logs, child profile, and onboarding answers are used as input to our AI pipeline to generate your daily guides, weekly summaries, and advice responses. This is the core function of Thistle.
To deliver notifications. Your email address and notification preferences are used to send you daily guides and weekly summaries on your preferred schedule.
To maintain safety. All AI-generated content is checked against safety rules before it reaches you. We log safety evaluation results to monitor and improve our safety systems.
To improve the service. We may review aggregated, de-identified patterns in how the service is used to improve Thistle's features and guidance quality. We do not review individual family data for this purpose without your consent.
To communicate with you. We may send you service-related emails (account verification, important updates, responses to your inquiries).
4. How AI Processes Your Data
This section explains specifically how your information flows through our AI system, because we believe you should know exactly what happens with data about your child.
What we send to AI providers
When generating your guides and advice, we send your logs, onboarding answers, child profile information, and relevant historical summaries to third-party AI providers via their APIs.
Before any data reaches an AI provider, we remove identifying information. Your child's name is replaced with a generic placeholder like "[CHILD]". The AI model does not see your child's real name. After the AI generates a response, we restore the real name before showing it to you.
Which AI providers we use
We currently use AI services from Google (Gemini) and Anthropic (Claude) via their commercial APIs. These providers process your data to generate responses and return them to us. Under their API terms of service, these providers do not use your data to train their AI models.
What the AI providers can and cannot do
Our AI providers:
- Process your data solely to generate a response to our request
- May temporarily retain inputs and outputs for abuse monitoring and safety purposes, as described in their own terms of service
- Do not use API customer data to train or improve their models
- Do not share your data with third parties
We select providers whose API terms prohibit training on customer data. If a provider's terms change in a way that affects this commitment, we will notify you and, if necessary, switch providers.
5. Who We Share Your Information With
We share your information only in these limited circumstances:
AI providers. As described above, de-identified data is sent to AI providers to generate your content.
Infrastructure providers. We use Fly.io for hosting and PostgreSQL for data storage. These providers process your data as part of operating our infrastructure but do not access or use it independently.
Email delivery. We use an email service provider to deliver your notification emails. These emails contain your child's name and guide content.
Legal requirements. We may disclose your information if required by law, subpoena, or court order, or if we believe disclosure is necessary to protect the safety of a child or prevent imminent harm.
We do not sell your information. We do not share your information with advertisers. We do not share your information with other Thistle users.
6. Children's Privacy
Thistle is designed for use by parents and caregivers, not by children. Children do not create accounts, log in, or interact with Thistle directly. All information about children is provided by their parent or authorized caregiver.
We collect information about children only as provided by their parent or caregiver, and we use it only to provide the parent with personalized guidance. We do not knowingly collect information directly from children under 13 (or under any applicable age threshold).
If you believe a child has somehow accessed Thistle directly or that we have collected information about a child without appropriate parental consent, please contact us immediately and we will delete that information.
7. Data Retention
We retain your data for as long as your account is active. This includes your logs, child profiles, generated guides and summaries, onboarding answers, and Ask history. We retain this data because it feeds into the AI pipeline — your historical context makes future guides more personalized and relevant.
When you delete your account, we will delete all associated data within 30 days. This includes all logs, child profiles, generated content, and account information. Some data may persist in encrypted backups for up to 90 days after deletion, after which backups are rotated and the data is permanently removed.
8. Data Security
We take reasonable measures to protect your information:
- All data in transit is encrypted via TLS
- Your data is stored in encrypted databases
- Authentication is passwordless (magic link), reducing the risk of credential theft
- Child names are scrubbed from data before it reaches AI providers
- AI-generated content passes through automated safety review before delivery
- Administrative access is restricted and logged
No system is perfectly secure. If we discover a breach that affects your data, we will notify you promptly and take steps to mitigate the impact.
9. Your Rights and Choices
You have the following rights regarding your data:
Access. You can request a copy of all data we hold about you and your child.
Correction. You can update your child's profile, your logs, and your account information at any time through the app.
Deletion. You can request that we delete all your data. This is permanent and means we can no longer provide you with personalized guidance.
Data export. You can request a machine-readable export of your data.
Notification preferences. You can change your email and push notification settings at any time in the app.
To exercise any of these rights, contact us at info@thistleguide.com. We will respond within 30 days.
10. Third-Party Links and Services
Thistle may occasionally reference external resources or link to third-party websites. We are not responsible for the privacy practices of those sites. This privacy policy applies only to Thistle.
11. Changes to This Policy
We may update this policy from time to time. If we make material changes — especially changes to how we handle your child's data or how data is shared with AI providers — we will notify you by email at least 14 days before the changes take effect.
12. Contact
If you have questions or concerns about this policy or how we handle your data: info@thistleguide.com
© Winter Green Solutions LLC