THEA Logo

    Privacy Policy

    Last updated: 16 July 2026

    THEA ("THEA", "we", "us") is an AI-powered practice management platform for architecture and AEC firms, operated by THEA-AI LTD, registered in the United Kingdom. This policy explains what information we collect when you use heythea.ai and the THEA application, how we use and protect it, and the choices you have. If you have any questions, contact us at privacy@heythea.ai.

    Information we collect

    • Account information — your name, email address, and profile details you provide when you create an account. Authentication is handled by our sign-in provider, Clerk.
    • Workspace content — the information you and your team add to THEA to run your practice: projects, leads, proposals, budgets, timesheets, contacts, files, and related records.
    • Connected-service data — if you choose to connect Google, Microsoft, or QuickBooks accounts, the data described in the sections below.
    • Payment information — subscription billing is processed by Stripe. We do not store your card details.
    • Usage and device information — standard technical logs (such as browser type and pages visited) and analytics on our marketing site collected via Google Tag Manager, used to operate, secure, and improve the service.

    How we use information

    We use your information solely to provide, secure, support, and improve THEA — for example, to sync your calendar, let you import files you choose from your cloud storage, generate documents you request, process your subscription, and respond to support requests. We do not sell your personal information, and we do not use your data for third-party advertising.

    Google user data

    If you connect your Google account, THEA requests the following permissions. We only access the minimum data needed for the features you use:

    • Google Calendar (view and edit events) — used to display your calendar inside THEA and to create or update events for scheduling features you initiate.
    • Google Drive (read-only) — used to let you browse your own Drive from within THEA and to download only the specific files you select for import (for example, a proposal template or project document). We never modify or delete anything in your Drive, and we never scan or access files you have not selected beyond listing them so you can browse.
    • Basic profile information — your name and email address, used to identify the connected account.

    Files you import are copied into your THEA workspace and handled like any other workspace content. Access tokens for your Google account are stored encrypted on our backend and are never exposed to other users or third parties. You can disconnect Google from THEA at any time in your profile's Integrations tab (which deletes our stored tokens), and you can also revoke THEA's access from your Google Account security settings.

    THEA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models. Data obtained through Google APIs is used only to provide the user-facing features described above; where an AI feature you initiate processes a document you imported, that processing serves only your request and is never used for model training.

    Microsoft user data

    If you connect a Microsoft account, THEA requests equivalent permissions: calendar (view and edit events), OneDrive files (read-only, so you can browse and import files you select), and basic profile information. The same rules apply as for Google data: minimum necessary access, encrypted token storage, no advertising use, no sale, no model training, and the ability to disconnect at any time from your profile's Integrations tab or your Microsoft account settings.

    QuickBooks data

    If you connect QuickBooks Online, THEA accesses your accounting data (such as customers and invoices) only to provide the sync features you configure, under the same protections described above.

    How we store and protect data

    THEA runs on established cloud infrastructure. Data is encrypted in transit (TLS) and at rest. Application data is stored with our backend provider, Convex; the website and application are hosted on Vercel. Access to production systems is restricted and integration tokens are stored encrypted.

    When we share information

    We share data only with the service providers that power THEA, under agreements that limit their use of your data to providing their service to us:

    • Vercel (hosting) and Convex (application backend and database)
    • Clerk (authentication) and Stripe (payments)
    • Resend (transactional email, e.g. notifications)
    • CloudConvert (document format conversion when you import or export documents)
    • AI model providers such as Anthropic and OpenAI, only to process the specific AI features you initiate (for example, generating a proposal draft or transcribing audio you record)
    • Langfuse (AI observability and monitoring, to trace and improve the reliability and quality of the AI features you use)
    • Sentry (error monitoring, to keep the service reliable)

    We may also disclose information if required by law, or as part of a merger or acquisition (in which case this policy will continue to apply to your data).

    Data retention and deletion

    We keep your data for as long as your workspace is active. Disconnecting an integration deletes our stored access tokens for it. You can request deletion of your account and workspace data at any time by emailing privacy@heythea.ai; we will delete it within 30 days except where the law requires us to keep specific records (for example, billing records).

    Your rights

    Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact privacy@heythea.ai.

    Children

    THEA is a business tool and is not directed at children under 16.

    Changes to this policy

    If we make material changes to this policy, we will update this page and, where appropriate, notify you by email or in the application. The "Last updated" date above reflects the most recent revision.

    Contact

    THEA-AI LTD, United Kingdom
    privacy@heythea.ai