THEA

    Privacy Policy

    Last updated: 14 August 2026 · 12 minutes to read

    THEA ("THEA", "we", "us") is an AI-powered practice management platform for architecture and AEC firms. THEA-AI LTD, registered in the United Kingdom, operates it. This policy explains what information we collect when you use heythea.ai and the THEA application. It also covers how we use that information, how we protect it, and the choices you have. If you have any questions, email us at privacy@heythea.ai.

    In short

    • We collect your account details, and whatever you and your team put into THEA.
    • We use it to run THEA for you. We do not sell it, and we do not use it for advertising.
    • Your workspace data is stored in the European Union (Ireland).
    • Connecting Google, Microsoft or QuickBooks is your choice, and you can disconnect at any time. Microsoft's permissions are wider than Google's, and we explain that below rather than gloss over it.
    • Data from your connected Google or Microsoft account is never used to train AI models. AI providers only see what an AI feature you start sends them.
    • Delete your workspace and it is recoverable for 30 days. If your subscription ends we keep it for 90 days. After that we erase it permanently.
    • You can ask to see, correct, export or delete your information at any time. Email privacy@heythea.ai.
    • If you are unhappy with how we handle your information, tell us. We will acknowledge it within 30 days and tell you the outcome. You can also complain to the Information Commissioner's Office at any time, without coming to us first.

    This is a summary, not the policy. The full detail is below, and it is what applies.

    Information we collect

    • Account information. Your name, email address, and the profile details you give us when you create an account. Our sign-in provider, Clerk, handles the sign-in itself.
    • Workspace content. The information you and your team add to THEA to run your firm: projects, leads, proposals, budgets, timesheets, contacts, files, and related records.
    • Connected-service data. If you connect a Google, Microsoft, or QuickBooks account, the data described in the sections below.
    • Payment information. Stripe handles subscription billing. We do not store your card details.
    • Usage and device information. Standard technical logs, such as browser type and pages visited. Our marketing site also collects analytics through Google Tag Manager and Google Analytics, and only if you accept analytics cookies. You can accept or refuse them when you arrive, and change your mind at any time. See our Cookie Policy. We use this to operate, secure, and improve the service.
    • If you book a call with us. The booking form on our contact page is run by Cal.com. It takes your name, your email address, your timezone, and anything you write in the notes. We use it only to hold the meeting you booked.

    How we use information

    We use your information only to run, secure, support, and improve THEA. For example, we sync your calendar, let you import files you choose from your cloud storage, generate documents you ask for, process your subscription, and answer support requests. We do not sell your personal information, and we do not use your data for third-party advertising.

    Why we are allowed to use it

    The law makes us tell you the lawful basis for each thing we do with your information. Here is ours.

    • To run THEA for you. We need your information to do what we agreed to do in our contract with you. This covers your account, your workspace content, the data from services you choose to connect, and support.
    • To take payment. The same reason. We need it to perform our contract. Stripe handles the card details, not us.
    • To keep THEA secure and working. Our basis is our legitimate interests. The interest is keeping the service safe, finding faults, and stopping misuse. We use the least information that does the job.
    • To improve THEA. Our basis is our legitimate interests. The interest is building a better product for the firms that use it. We look at how features are used, not at what is inside your projects.
    • Analytics on our marketing site. Our basis is your consent, which you give or refuse in the cookie banner. You can change your mind at any time. See our Cookie Policy.
    • Where the law makes us keep something. Our basis is our legal obligation. This covers records such as billing records.

    You can ask us for more detail on any of these. Email privacy@heythea.ai.

    Google user data

    If you connect your Google account, THEA requests the following permissions. We only access the minimum data needed for the features you use:

    • Google Calendar (read your calendars, and manage calendars THEA creates) — used to display your calendar inside THEA. Where you ask THEA to put project dates in your calendar, it writes only to a calendar THEA created for that purpose. It cannot change or delete your other calendars.
    • Google Drive (read-only) — used to let you browse your own Drive from within THEA and to download only the specific files you select for import (for example, a proposal template or project document). We never modify or delete anything in your Drive, and we never scan or access files you have not selected beyond listing them so you can browse.
    • Basic profile information — your name and email address, used to identify the connected account.

    Files you import are copied into your THEA workspace and handled like any other workspace content. Access tokens for your Google account are stored encrypted on our backend and are never exposed to other users or third parties. You can disconnect Google from THEA at any time in your profile's Integrations tab (which deletes our stored tokens), and you can also revoke THEA's access from your Google Account security settings.

    THEA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models. Data obtained through Google APIs is used only to provide the user-facing features described above; where an AI feature you initiate processes a document you imported, that processing serves only your request and is never used for model training.

    Microsoft user data

    If you connect a Microsoft account, THEA requests three permissions: your calendars (read and write), your files (read only), and basic profile information.

    Microsoft's permissions are wider than Google's, and we would rather tell you than let you assume otherwise. The calendar permission covers every calendar in your account, not only one THEA created. The file permission covers files you can reach in OneDrive and in SharePoint, including files other people have shared with you. Microsoft does not offer narrower versions of either one, so this is the smallest request that makes the feature work.

    What we do with them is the same as for Google. We read your calendar to show it inside THEA, we add only the entries you ask THEA to create, and we download only the files you select for import. We never modify or delete your files. The same rules apply too: encrypted token storage, no advertising use, no sale, no model training, and the ability to disconnect at any time from your profile's Integrations tab or your Microsoft account settings.

    QuickBooks data

    If you connect QuickBooks Online, THEA accesses your accounting data (such as customers and invoices) only to provide the sync features you configure, under the same protections described above.

    How we store and protect data

    THEA runs on established cloud infrastructure. We encrypt your data in transit (TLS) and at rest. Our backend provider, Convex, stores your workspace data in the European Union (Ireland), and the email we send for you is handled there too. Vercel hosts the website and the application. We restrict access to production systems, and we store integration tokens encrypted.

    Some of the providers listed in the next section are in the United States or elsewhere, so some information reaches them outside the United Kingdom and the European Union.

    You can ask us which provider holds what, and which protections apply to a transfer. We will tell you what is in place. Email privacy@heythea.ai.

    When we share information

    We share data only with the service providers that run THEA. Our agreements with them limit their use of your data to providing their service to us:

    • Vercel (hosting) and Convex (application backend and database)
    • Clerk (authentication) and Stripe (payments)
    • Resend (transactional email, e.g. notifications)
    • CloudConvert (document format conversion when you import or export documents)
    • AI model providers such as Anthropic and OpenAI, only to process the specific AI features you initiate (for example, generating a proposal draft or transcribing audio you record)
    • Langfuse (AI observability and monitoring, to trace and improve the reliability and quality of the AI features you use)
    • Sentry (error monitoring, to keep the service reliable). Sentry also records a replay of what was on screen for a small sample of sessions, and for sessions where something went wrong, so that we can see how a fault happened. That replay can include the workspace content you were looking at.
    • Cal.com (the booking form on our contact page)
    • Google (Tag Manager and Analytics on our marketing site, only where you accept analytics cookies)

    We may also disclose information if required by law, or as part of a merger or acquisition (in which case this policy will continue to apply to your data).

    Data retention and deletion

    We keep your data for as long as your workspace is active. Disconnecting an integration deletes our stored access tokens for it. You can ask us to delete your account and workspace data at any time by emailing privacy@heythea.ai. We will delete it within 30 days, except where the law requires us to keep specific records such as billing records.

    If you delete your workspace from inside THEA, it stays recoverable for 30 days so that you can undo the deletion. After 30 days it is permanently erased and cannot be restored.

    If your subscription ends, we keep your workspace data for 90 days so that you can come back and pick up where you left off. This covers cancelling, lapsing, and a free trial that runs out without a subscription. We email the workspace owner when the 90 days begin, and again before they run out. After 90 days we erase the data permanently, and it cannot be restored.

    Everything else we keep only for as long as it is useful for the purpose we collected it for, and then we delete it. Technical logs and error reports last while they are still useful for finding faults. Support emails last while the question is open and for a reasonable period after. Billing records last as long as tax law requires us to keep them. You can ask us what we hold about you, and for how long, at any time.

    Do you have to give us this

    Your name and email address are needed to open an account. We cannot run a workspace without them, so if you do not give them to us we cannot provide the service.

    Everything else is your choice. You decide what your team puts into THEA, and you decide whether to connect Google, Microsoft or QuickBooks. Nothing stops working if you leave those unconnected, apart from the features that need them.

    Your rights

    You can ask us to show you the personal information we hold about you, correct it, export it, or delete it. You can also object to how we use it, or ask us to pause our use of it while a question is sorted out. These are your rights under the UK GDPR. If you live outside the UK, your own data protection law may give you a different set. To use any of these rights, email privacy@heythea.ai.

    Automated decisions

    We do not make any decision about you by automated means that has a legal effect on you, or an effect of similar significance. Our AI features draft and suggest. A person always decides.

    If you are unhappy

    Tell us first, if you are willing to. You have a right to complain to us about how we handle your information. Email privacy@heythea.ai. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome.

    You can also complain to the regulator at any time. You do not need to come to us first. In the United Kingdom this is the Information Commissioner's Office.

    If you are in the European Union you may complain to the supervisory authority in your own country instead.

    If you were contacted about an unpaid invoice

    This policy covers people who use THEA. If you received an email about an invoice you have not paid, you are not a THEA user and a different notice applies to you. It explains who contacted you, where we got your details, what we hold, and how to stop being contacted. Read it at Payment reminders.

    Children

    THEA is a business tool and is not directed at children under 16.

    Changes to this policy

    When we make a material change to this policy, we update this page and change the date above. A material change is anything that alters what we do with your information, such as a new purpose, a new provider, or a change to how long we keep it. Minor corrections, such as clearer wording that changes nothing we do, are made on this page too.

    Contact

    THEA-AI LTD
    Registered in England and Wales, company number 17068364
    Flat 3604 Icon Tower, 8 Portal Way, London, England, W3 6EF
    privacy@heythea.ai