Theos Platform Privacy Policy
Effective Date: June 1, 2026
This Privacy Policy explains how Theos Artificial Intelligence, Inc. ("Theos AI," "we," "us," or "our") collects, uses, stores, and shares information when you visit our websites, use the Theos web or mobile applications, connect third-party accounts, use our public API, or otherwise interact with Theos (collectively, the "Service").
By using Theos, you acknowledge that we process information as described in this Privacy Policy. If you use Theos on behalf of a company or other organization, you are responsible for ensuring that your use of the Service and the data you provide complies with applicable law and your agreements with the people you contact.
1. Information We Collect
We collect information directly from you, automatically from your use of the Service, and from third-party platforms you connect to Theos.
Account, workspace, and team information: We collect information such as your name, email address, username, password or authentication details for your Theos account, organization or workspace name, team membership, roles, settings, invitations, and administrative preferences.
Campaign, contact, and lead data: Theos lets you create and manage outreach campaigns, flows, prompts, contact lists, tags, imported leads, and related records. This data may include names, email addresses, phone numbers, job titles, company names, LinkedIn profile URLs, Sales Navigator URLs, Instagram handles, Facebook or WhatsApp identifiers, notes, tags, lead status, campaign schedules, message templates, AI-generated drafts, and other information you import, enter, generate, or receive through the Service.
Conversation and content data: We process messages, comments, replies, call or meeting context, conversation status, timestamps, delivery or engagement metadata, and related history across supported channels. Depending on the features you use, this may include images, audio, documents, file attachments, downloaded media, transcriptions, voice dictation, generated summaries, and other user-provided or AI-assisted content.
Connected account and integration data: If you connect third-party services, we collect and process account metadata, profile information, identifiers, access tokens, refresh tokens, permissions, connection health, sync status, webhook events, provider policy metadata, and operational logs needed to provide those integrations. Supported integrations may include LinkedIn and Sales Navigator, Instagram, Facebook Pages and Messenger, WhatsApp Business Platform, Google Calendar, Microsoft Outlook Calendar, Calendly, and other providers we support.
Meta platform data: If you connect Meta services, Theos may collect and process Facebook Page, Messenger, Instagram Business, and WhatsApp Business Platform data. This can include account and asset metadata, business identifiers, message and comment content, webhook event payloads, WhatsApp template information, onboarding or Embedded Signup data, and related operational records, only as authorized by you and only as needed to provide Theos functionality.
Google Workspace and Google Calendar data: If you connect Google Workspace services such as Google Calendar, Theos may receive raw or derived user data from Google APIs only as authorized by you and only as necessary to provide the integration functionality you request. This may include your Google profile and email address, calendar list, free/busy availability, calendar settings, event details, guest information, meeting links, and event create, update, cancel, watch, or sync data needed for scheduling. Theos's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data or use it for advertising.
Microsoft Calendar and scheduling data: If you connect Microsoft services, Theos may process Microsoft account identity, calendar availability, calendar lists, event details, guests, meeting links, and event create, update, cancel, or sync data needed to provide scheduling and calendar workflows.
Public API, webhook, and developer data: If you use the Theos public API, we collect API key metadata, hashed key identifiers, encrypted key material where applicable, key status, scopes or permissions, rate-limit counters, request metadata, imported payload metadata, webhook endpoints, webhook delivery attempts, errors, and logs needed to authenticate, secure, operate, and troubleshoot API usage.
Billing and subscription data: We collect plan, subscription, credit, usage, invoice, payment status, trial, discount, and billing account information. Payment card and bank details are generally processed by our payment providers, such as Stripe, and are handled under their own terms and privacy policies.
Usage, device, and operational data: We collect information about how you use Theos, including IP address, browser type, device identifiers, operating system, app version, pages or screens visited, features used, button clicks, performance data, crash or error data, model execution metadata, cost and quota information, audit logs, security logs, and other activity records.
Mobile and notification data: If you use the Theos mobile app or enable notifications, we may process device information, push notification tokens, notification preferences, delivery records, read or interaction status, and mobile app usage data.
Website, demo, and contact form data: When you submit a landing page contact form, demo form, or similar request, we collect the information you provide, such as name, email, phone or WhatsApp number, company, role, sales team size, budget, decision timeline, challenges, message content, and scheduling preferences. We may also collect page URL, referrer, IP address, user agent, captcha verification status, and related anti-abuse metadata.
Captcha, security, and anti-abuse data: To protect the Service, we may use tools such as Google reCAPTCHA and internal rate limiting. These tools may process IP address, user agent, token hashes, captcha score, action, hostname, timestamps, and limited request context.
Communications and support data: If you contact us by email, chat, phone, WhatsApp, form, or other channels, we collect your contact details and the content of those communications.
2. How We Use Information
We use information to provide, secure, improve, and support Theos.
To operate the Service: We use information to authenticate users, manage accounts and workspaces, run campaigns, display contacts and conversations, synchronize connected accounts, schedule meetings, process notifications, manage billing, and provide web, mobile, and API functionality.
To provide integrations: We use connected account data to perform user-authorized actions, such as sending messages, reading or responding to comments or conversations, importing or updating contacts, synchronizing calendars, creating or updating meetings, processing webhooks, managing WhatsApp templates, and showing account connection health.
To provide AI-powered features: We may send selected prompts, messages, contact details, conversation context, files, transcripts, or other content to AI providers when needed to generate drafts, summarize conversations, classify replies, suggest next steps, create prompts or campaign flows, transcribe audio, or perform other AI features you request. We use these providers to provide the Service and do not permit them to use customer content to train their general models unless you have agreed otherwise or the provider's terms independently apply to your own account or credentials.
To support landing, sales, and customer success workflows: We use demo and contact form submissions to respond to inquiries, qualify requests, schedule demos, route leads to internal sales or support channels, prefill scheduling tools, and follow up about Theos. For example, a landing contact request may be relayed to our sales team through WhatsApp or another communication provider.
To secure the Service and prevent abuse: We use logs, captcha data, rate-limit data, device information, and other operational data to detect unauthorized access, spam, fraud, misuse, credential abuse, platform abuse, and security incidents.
To improve reliability and product quality: We analyze usage, performance, errors, aggregated metrics, and feedback to debug issues, improve features, plan capacity, measure product usage, and understand how the Service performs.
To communicate with you: We use contact information to send service notices, security alerts, product updates, billing notices, support responses, onboarding messages, and marketing communications where permitted. You can opt out of marketing emails, but we may still send transactional or service-critical messages.
To comply with legal obligations: We may process information to comply with law, enforce our Terms, resolve disputes, respond to lawful requests, maintain business records, and protect the rights, safety, and property of Theos, our users, and others.
3. How We Share Information
We do not sell personal information. We share information only as described below or with your consent.
Within your workspace: If you use Theos as part of a team or organization, workspace administrators and authorized team members may access campaign data, contacts, conversations, settings, usage, billing information, and other workspace records according to their roles and permissions.
Service providers and processors: We use third-party providers to host, operate, secure, analyze, and support Theos. These providers may include cloud infrastructure, database, storage, authentication, analytics, captcha, payment, email, messaging, customer support, push notification, AI, transcription, calendar, scheduling, and communication providers. Examples may include Google Cloud Platform, Supabase, Stripe, Google, Microsoft, Meta, Calendly, Unipile, Expo, PostHog, email delivery providers, and AI model providers such as OpenAI, Anthropic, Google, Groq, xAI, DeepSeek, Cerebras, or similar services. These providers process information under our instructions or under the terms applicable to the integration you choose.
Third-party integrations: When you connect a third-party service, Theos exchanges data with that service to perform the actions you request. For example, we may send message content to Instagram, LinkedIn, Facebook, or WhatsApp; create or update meetings in Google Calendar, Microsoft Calendar, or Calendly; receive webhook events; or retrieve profile, contact, conversation, calendar, and asset metadata. Those third-party services process information under their own terms and privacy policies.
AI providers: We share only the information reasonably needed for the AI task being performed, such as generating a reply, summarizing a conversation, classifying a lead, transcribing audio, or analyzing campaign context.
Business transfers: If we are involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate protections.
Legal compliance and protection: We may disclose information when required by law, legal process, or governmental request, or when we believe disclosure is necessary to enforce our agreements, prevent abuse, protect security, or protect the rights, property, or safety of Theos, our users, or others.
With consent: We may share information in other ways if you direct us to do so or give us permission.
4. Data Storage, Security, and Retention
Storage location: Theos is operated by a U.S. company and primarily uses cloud infrastructure in the United States. We and our providers may process information in the United States and other jurisdictions where we or our providers operate.
Security measures: We use technical and organizational safeguards designed to protect information, including encryption in transit, encryption at rest where appropriate, access controls, monitoring, logging, credential protection, and operational security practices. No internet or electronic storage system is completely secure, so we cannot guarantee absolute security.
Connected account credentials: Access tokens, refresh tokens, API credentials, and similar secrets are stored using safeguards such as encryption or hashing where appropriate. You are responsible for protecting your Theos credentials, API keys, and third-party accounts.
Retention: We retain information for as long as needed to provide the Service, maintain accounts, operate campaigns, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain business records. If you delete your account or request deletion, we will delete or anonymize eligible information from active systems, subject to retention needed for legal, billing, security, fraud prevention, backup, or legitimate business purposes. Information already transmitted to third-party platforms or message recipients may remain in those external systems.
5. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also have the right to withdraw consent where processing is based on consent.
You can update some information in your account settings. To make a request, email contact@theos.ai. We may ask you to verify your identity and provide enough information to locate your account, workspace, connected integrations, or relevant records.
Account and integration deletion: You may request deletion of your Theos account or data associated with connected integrations. We will delete or anonymize eligible data in our active systems, subject to legal and operational retention. Disconnecting a third-party integration stops future access, but it does not automatically remove information already processed in Theos or information held by the third-party service.
Meta data deletion: If you connected Facebook, Instagram, or WhatsApp through Theos, you may request deletion by emailing contact@theos.ai with the subject "Meta Data Deletion Request" and enough information to identify your account, workspace, and connected platform records. If you submit a deletion request through Meta's tools after removing Theos access, we process that request in accordance with Meta platform requirements and applicable law.
For public step-by-step instructions, see our Theos User Data Deletion Instructions.
California privacy rights: California residents may have rights under California privacy laws, including the right to know, delete, correct, or opt out of certain sharing. Theos does not sell personal information. You can exercise applicable rights by contacting us and specifying that you are making a California privacy request.
European, UK, and Swiss rights: If you are in the European Economic Area, United Kingdom, or Switzerland, you may have rights under applicable data protection laws, including access, rectification, erasure, restriction, objection, portability, and the right to lodge a complaint with a data protection authority. Our legal bases may include performance of a contract, consent, legitimate interests, and compliance with legal obligations.
We will not discriminate against you for exercising privacy rights.
6. Cookies and Tracking Technologies
We use cookies, local storage, pixels, SDKs, and similar technologies to provide the Service, remember preferences, authenticate users, measure usage, analyze performance, prevent abuse, and improve our websites and applications.
On our websites, we may use analytics tools such as PostHog to understand page views, form interactions, traffic sources, performance, and product interest. We may also use reCAPTCHA or similar tools to protect forms and authentication flows. In the mobile app, SDKs may help us provide notifications, understand app usage, diagnose errors, and improve reliability.
Most browsers let you control cookies through settings. If you disable cookies, some parts of the Service may not function properly. At this time, Theos does not respond differently to browser "Do Not Track" signals because no consistent industry standard exists.
7. Children's Privacy
Theos is not intended for children under 16 or the age of digital consent in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child provided information to us, contact us at contact@theos.ai and we will take appropriate steps.
8. International Users
If you use Theos from outside the United States, you understand that information may be transferred to, stored in, and processed in the United States and other countries. These countries may have data protection laws different from those in your jurisdiction. We use appropriate safeguards where required by applicable law.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect product, legal, operational, or security changes. If we make material changes, we will update the effective date and may notify you by email, in-app notice, or website notice. Continued use of the Service after an updated policy becomes effective means you acknowledge the updated policy.
10. Contact Us
If you have questions, concerns, or requests about this Privacy Policy or our privacy practices, contact us at:
Theos Artificial Intelligence, Inc.
- Email: contact@theos.ai
- Phone: +17373747559