Privacy Policy

What Thesis-It stores, what never leaves your device, who processes it and where, and the rights you have over it.

Last updated 16 September 2026

1. Introduction

This Privacy Policy explains how Workcyte Digital Academy (SSM Registration No. 202603071928), operating the Thesis-It service, collects, uses, discloses and protects your personal data. This Policy is issued in accordance with the Malaysian Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"). It is also informed by internationally recognised data protection principles, including the EU General Data Protection Regulation ("GDPR"), for users outside Malaysia. We act as the "data controller" for the personal data described in this Policy.

2. What stays on your device

The thesis template, guideline or exemplar you use to set up your structure is read inside your browser. The file itself is never uploaded to Thesis-It: only the headings, rules and text the app extracted from it, and the structure you adopted, are stored in your account. A PDF you add to your source library is read the same way: its text is indexed and stored so the app can search it and check your citations against it, and the PDF file itself is not stored. If you use your own Gemini API key instead of the included AI, the key stays on your device and never reaches our servers.

3. Personal data we collect

Account and authentication data: your email address (required, for signing in by emailed link), your name if you give it, session cookies and sign-in tokens. Content: your thesis text and structure, the extracted text and rules from the templates and guidelines you use, your source library and the indexed text of your sources, the figures and tables you add, your notes, meeting records, checklists and progress records, and the documents you export. Collaboration data: the email addresses of the supervisors and readers you invite, the role you give them, and the comments and sign-offs they leave on your thesis. AI usage data: when you use the included AI, the number of tokens each step used, kept to apply your monthly allowance; the text sent is not retained beyond the request. Billing data: subscription status and renewal history, and payment metadata such as transaction references and amounts. We do not store your card or bank details; those are held by our payment processor, CHIP. Technical data: IP address (for security and abuse prevention), user agent, access logs and an audit trail of account and billing actions.

4. Purposes of processing

We process your personal data to sign you in and provide the Service; to run the drafting and checking steps you start, which for the included AI means sending the text you chose to Google's Gemini API on your behalf; to share your thesis with the people you invite; to process your subscription payments and send billing emails; to communicate with you about the Service (transactional emails only, no marketing without your consent); to prevent, detect and investigate abuse, fraud and security incidents; to improve the Service in aggregated, non-identifying form; and to comply with our legal obligations.

5. Legal basis for processing

We process your personal data under contract performance (to provide the Service you subscribed to); legitimate interest (to secure the Service, prevent abuse and improve reliability); consent (where you have given it, for example when you invite a supervisor or send text to the included AI); and legal obligation (where required by applicable law).

6. Data sharing and sub-processors

We do not sell your personal data. We share your data only with the following categories of recipients. Infrastructure sub-processors necessary to operate the Service: Vercel Inc. (United States) for web application hosting and for Vercel Blob storage of the figures you add (stored in the Singapore region); Neon (Singapore, ap-southeast-1) for the PostgreSQL database; Fly.io (Singapore) for rendering document previews; Resend (Tokyo, ap-northeast-1) for transactional email; Sentry (European Union) for application error monitoring. Payment processor: CHIP In (Malaysia) for subscriptions in Malaysian Ringgit. AI processing: Google LLC (United States) through the Gemini API, which receives the text of each included-AI step you start and answers it; Thesis-It does not retain the prompt or the reply beyond the immediate request, and every AI-written passage is marked in your records until you accept it. Academic metadata services queried on your behalf when you search for or verify a source: Crossref (United States) and OpenAlex, operated by OurResearch (United States). People you invite: a supervisor or reader you share your thesis with sees your thesis text, your name and the email you signed in with. Legal and compliance: government authorities or courts where required by law.

7. Cross-border data transfers

Some of our sub-processors are located outside Malaysia. We transfer personal data to these locations in accordance with the PDPA and the Personal Data Protection Guidelines No. 03/2025 on Cross-Border Personal Data Transfer, relying on one or more of: performance of your subscription contract (PDPA Section 129(3)(b)); your consent, given by accepting this Privacy Policy (PDPA Section 129(3)(a)); or substantially similar law or adequate protection where destinations such as Singapore (under its PDPA 2012) and Japan (under its APPI) provide protection assessed by us as at least equivalent to the Malaysian PDPA (PDPA Section 129(2)). We conduct Transfer Impact Assessments as required by law before onboarding new sub-processors handling personal data.

8. Data retention

We retain your personal data for as long as your Account is active. After your subscription ends, your Account becomes read-only and we keep your Content so you can read it, export it and, if you resubscribe, continue it, unless you ask us to delete it. Upon written request to security@thesisit.app, we delete your Account and Content within 30 days, subject to legal retention obligations (for example, billing records for tax purposes, retained for 7 years under Malaysian tax law). Deleted data may persist in encrypted backups for up to 30 days after deletion, after which it is permanently removed. A draft an AI step produced that you rejected is kept for 30 days so you can recover it, then removed.

9. Your rights

Under the PDPA and, where applicable, the GDPR, you have the right of access (to obtain confirmation of whether we process your personal data and receive a copy); the right of correction (to correct inaccurate or incomplete personal data); the right to withdraw consent; the right to data portability (to receive your personal data in a structured, machine-readable format and, where technically feasible, have it transmitted directly to another controller, per PDPA Section 43A; your thesis can be exported as a Word document or as Markdown at any time from inside the app); the right to erasure (to request deletion, subject to our legal retention obligations); and the right to object (to processing based on legitimate interest, in specific circumstances). To exercise any of these rights, email security@thesisit.app. We will respond within 21 days as required by the PDPA. If you believe our processing of your personal data violates the PDPA, you may file a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, JPDP) at pdp.gov.my.

10. Data breach notification

In the event of a personal data breach that is likely to cause significant harm to you, we will notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours where feasible, as required by Section 12B of the PDPA; notify you directly, without unnecessary delay; and provide guidance on protective steps you can take.

11. Cookies and similar technologies

We use only strictly necessary cookies: a session cookie to keep you signed in, and a CSRF token cookie to protect against cross-site request forgery. We do not use marketing cookies, advertising trackers, cross-site tracking or third-party analytics. Your thesis is also kept in your browser's own storage so you can keep working when the connection drops; that copy stays on your device and syncs to your account when you are back online.

12. Children

The Service is intended for users aged 18 and older. We do not knowingly collect personal data from children under 18. If you believe we have collected data from a child, contact security@thesisit.app and we will delete it.

13. Security measures

We implement technical and organisational measures to protect your personal data, including encryption in transit (TLS); encryption at rest for the platform AI credential (AES-256-GCM); access rules that let only you, and the people you invite, read your thesis; audit logging of account and billing actions; regular security reviews and updates; and sub-processor security assessments.

14. Changes to this policy

We may update this Policy from time to time. We will notify you of material changes by email at least 14 days before the changes take effect.

15. Contact

Data Controller: Workcyte Digital Academy (SSM Registration No. 202603071928), Malaysia. Privacy and data protection matters: security@thesisit.app. General support: support@thesisit.app.