Controller and contact
Open Thermal AI is currently operated by Jing Yanrong (individual operator). Legal notices: B5-905, Tahoe Fuzhou Yard, Cangshan District, Fuzhou, Fujian, China. Until a business entity is registered, this individual is the controller for this website.
Public-interest and data commitment
Core knowledge, basic project screening, and public calculators will remain free through at least September 2028. Open Thermal AI does not sell user data. High-compute-cost interfaces retain reasonable rate limits to protect reliable public access.
Cookie & optional-service settings
Necessary browser storage supports your settings and local Project Center. Optional analytics, Baidu indexing push, and the external QR service are off until you choose otherwise. Your preference is stored in this browser and can be changed at any time.
What is stored locally
Project Center projects, analysis versions, reports, and Workspace context are stored in this browser (localStorage). Clearing site data can permanently delete them. This is not cloud storage.
What may be sent to the LLM proxy
When you choose to send a message to live Copilot, you are interacting with AI. Brief text and related project parameters may be sent to our server-side proxy, which currently calls DeepSeek. Do not enter personal data, confidential customer information, trade secrets, passwords, controlled drawings, or regulated data. Deterministic engineering numbers come from registered calculators — not from the model inventing results. API keys never leave the server.
What is stored on our server
The proxy stores logically separated analytics, lead, rate-limit, cost, challenge-nonce and security tables in a server-only SQLite database. API keys and full project records are not stored there. Raw anonymous analytics are retained for up to 90 days; security logs up to 30 days; rate buckets and challenge nonces are short-lived. The Project Center remains browser-local.
Third-party services
DeepSeek: Copilot chat and parameter extraction only when you choose to send a message. Hosting: GitHub Pages and Alibaba Cloud Lightsail / Nginx for the static site and API proxy. Notion is used for the operator’s reference knowledge base; user projects, Copilot messages, and lead records are not written to Notion. The current production build does not use third-party web analytics. It uses limited first-party funnel analytics with a short-lived random session id; no names, emails, project titles, exact engineering inputs, or AI text are included. Optional services are off until you choose them: api.qrserver.com generates a vCard QR image, and Baidu URL push supports search indexing (not visit analytics). Cloudflare Turnstile may be used only when human verification is required to protect an API or form. Hosting logs, security logs, and API operational logs may be retained by their providers under their own terms. Contact forms open your email client — no third-party form SaaS is required. Last reviewed: 2026-09-03.
Conversations
Chat history shown in Workspace is primarily local to the browser session / project. Do not paste secrets, passwords, or regulated personal data into briefs.
Files
Project files can be attached locally in this browser (IndexedDB). Sending file text/metadata to AI requires explicit user confirmation per file. There is no permanent cloud file vault yet — clearing site data removes local files. Secure multi-user cloud storage remains Planned.
Model training
We do not claim that provider models never use API traffic for training. Check each enabled provider’s current API terms (DeepSeek today). Prefer redacting customer names and proprietary process details when possible.
How to delete data
- In Project Center → project Settings: export, then delete the project.
- Or clear this site’s data in your browser settings.
- Export important projects regularly — local data can be lost.
Engineering disclaimer
Screening reports and calculators are illustrative aids. They are not PE-stamped design, procurement documents, or legal advice. Have qualified engineers review before investment.
Leads, analytics & retention
If you submit a lead (email report or expert review), we store contact and consent fields separately from anonymous product analytics. Analytics events use a short-lived random session id and never include names, emails, project titles, exact engineering numbers, or AI prompt/response text. Current maximums are: raw analytics 90 days before aggregation, security logs 30 days, inactive non-marketing leads 180 days before deletion or anonymization, privacy-request records 180 days, and aggregate AI cost records 365 days. Rate-limit buckets expire within 2 days and used challenge tokens within 5 minutes. Marketing consent is optional and off by default.
Your rights (leads)
You may request export or deletion of lead records, or withdraw marketing consent, via the form below or by email. Requests are queued pending identity verification so another person cannot delete your record using only your email address. Local project data is deleted in Project Center or by clearing site data in your browser — submitting an email never uploads your full project automatically.