Security and data handling
Last updated 18 August 2026
Our commitment
Strategy conversations are among the most sensitive discussions a leadership team has. This page sets out, in plain language, how ThinkSprint protects them inside DECODER™.
Access is scoped to your organisation
Every sprint answer, transcript and report belongs to a specific organisation. Access rules are enforced in the database itself, so a member of one organisation cannot read another's content even if they tried to request it directly. Within your organisation, participants see their own sprints; administrators and your assigned ThinkSprint strategist see the team's records so they can support the programme.
Accounts
Accounts are created by invitation only — there is no open public sign-up. You can sign in with Google or with an email address and password, and reset your password by email.
Encryption
Traffic between your device and the platform is encrypted in transit using TLS. Stored data, including database records and uploaded documents, is encrypted at rest by our cloud infrastructure provider.
AI content is not used for training
The coaching conversation and report analysis run through third-party AI models accessed via our platform provider. Content is sent only to generate your output. We do not permit your content to be used to train or fine-tune AI models.
Human review
AI-generated analysis is a draft. A ThinkSprint strategist reviews and approves each synthesis report before it is released to your organisation.
Reporting a problem
If you believe you have found a security issue, please email security@thinksprint.co.nz with enough detail for us to reproduce it. We will acknowledge your report and keep you updated. Please do not publicly disclose an issue before we have had a chance to fix it.