Privacy Policy
Last updated: July 28, 2026
Thermal is a chat-first CRM operated by enc0re inc, a Delaware corporation ("we", "us"). It helps you capture contacts and remember your professional network. This policy describes what we collect, how it is used, and the choices you have.
Account and sign-in
You sign in with your Google account. We receive your name, email address, and profile photo from Google to create and identify your account. We never see your Google password. During onboarding, we also store the survey answers you provide, such as where you heard about us, your role, team size, current system, and setup goals.
Google Contacts access (optional)
Ordinary sign-in does not grant Thermal access to your Google Contacts. If you choose Import from Google, we separately request read-only Contacts access so you can import people into your CRM and see the import result. We do not edit or delete contacts in your Google account. Imported contact details are stored with your Thermal account and are handled like contacts you add manually.
Google Drive access (optional)
Default sign-in and Contacts import do not request Drive access. If you later connect a Drive-backed integration, Thermal requests the per-file Drive scope (drive.file), which lets us create and manage only the files Thermal itself adds to your Drive. We cannot see or access other files in your Drive. Gmail-based auto-filing is planned for a future release and will request its additional permissions, with your consent, only when that feature ships.
Thermal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is only used to provide user-facing features of Thermal, is never transferred to third parties except as necessary to provide those features (or for security or legal compliance), and is never used for serving ads. Humans do not read your Google data except with your explicit consent, for security purposes, or where required by law.
What we store
Your contacts, organizations, interactions, notes, tasks, and chat history are stored in a Postgres database hosted by Neon. If you separately grant Drive access, screenshots you capture can also be archived to your own Google Drive. We retain this data while your account is active.
AI processing
Chat messages, uploaded screenshots, forwarded or detected emails, voice recordings you make with Dictate, and bounded samples of data files you choose to import are sent to OpenAI to extract structured contact and relationship information, transcribe speech, map relevant columns, and power the chat assistant. When you use Dictate, we also send up to 500 characters already present in the composer to help preserve names and other proper nouns. Thermal does not save the audio recording in its database; the transcript is placed in the composer for you to review before sending. Only mapped spreadsheet fields are staged in our database and processed deterministically after the schema is mapped; ignored columns are discarded and we do not send an entire large spreadsheet to the AI provider. This processing happens only to provide features you invoke. Data is written to your CRM only after you explicitly start an import or accept a proposed change.
On plans that include public enrichment, saving a new individual through Thermal's chat or capture review starts a background search for a matching professional profile. Pro members can also explicitly turn on public-profile checks when starting a contact or spreadsheet import. This option is off by default and checks at most 50 imported contacts in one import and 500 per month. For either kind of check, we send only the contact's name and any company, title, or city you saved to OpenAI's public-web search; we do not include the contact's email, phone number, private notes, relationship history, or other flexible imported fields. If you choose to retry with a clue, we also send the short company, title, location, or other identity clue you type specifically for that public search. Thermal shows the cited candidate and asks you to confirm the person before adding a LinkedIn profile or public-background note.
Billing
Payments are processed by Stripe. We never store full card numbers; Stripe shares with us only the subscription status and billing metadata needed to operate your plan.
Data deletion
You can request deletion of your account and all associated data at any time by emailing info@enc0re.com. We will delete your data within 30 days, except where retention is required by law. You can also revoke Thermal's Google access at any time from your Google Account security settings.
Contact
Questions about this policy: info@enc0re.com. See also our Terms of Service.