Privacy Policy
Effective date: March 1, 2026 · Last updated: February 2026
Theorify (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Theorify platform and related services (the “Service”). Please read this policy carefully.
Contents
1. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically as you use the Service, and information from third parties.
Information you provide directly:
- Account information: Your email address when you register for an account.
- Conversations and prompts: Messages, prompts, and inputs you send through the Service, including content within workflow nodes and handoff payloads.
- Memory entries: Preferences, notes, and context you add to the global, project, or workstream memory layers.
- Payment information: Billing details processed by our payment processor. We do not store full payment card numbers on our servers.
- Communications: Messages you send us via support or feedback channels.
Information collected automatically:
- Usage data: Pages visited, features used, actions taken (e.g., nodes created, models selected), and timestamps.
- Device and browser data: Browser type, operating system, IP address, and referring URL.
- Error data: Application errors and crash reports collected via Sentry.
- Cookies: Session tokens and preference data. See Section 7 for details.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service, including routing your messages to the appropriate AI Provider.
- Authenticate your identity and manage your account.
- Inject relevant memory context into your AI conversations (as configured by you).
- Process payments and manage subscriptions.
- Detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service.
- Monitor and improve the performance, security, and reliability of the Service.
- Send transactional emails (account confirmations, billing receipts, security alerts). We do not send unsolicited marketing emails without your consent.
- Respond to your support requests and feedback.
- Comply with legal obligations.
We do not sell your personal data or conversations to third parties. We do not use your conversations to train our own AI models.
3. Third-Party AI Providers
Important disclosure
When you send a message through Theorify, the content of your message — along with relevant context such as handoff payloads and memory injections you have configured — is transmitted to the third-party AI provider whose model you have selected for that conversation node. Some requests are routed through OpenRouter, a third-party API aggregation service that acts as an intermediary between Theorify and the AI provider. This is a core function of the Service.
Theorify currently integrates with the following AI Providers:
- OpenAI (GPT-5.2 and other OpenAI models) — Your data is handled under OpenAI's Privacy Policy.
- Anthropic (Claude models) — Your data is handled under Anthropic's Privacy Policy.
- Google (Gemini models) — Your data is handled under Google's Privacy Policy.
- Perplexity (Sonar and other models) — Your data is handled under Perplexity's Privacy Policy.
- OpenRouter (API routing intermediary) — Some model requests are routed through OpenRouter. Your data is handled under OpenRouter's Privacy Policy.
We encourage you to review the privacy policies of each AI Provider you use through our Service. Each provider has its own data retention and usage policies for API inputs and outputs. Theorify does not control how these providers handle your data once it is transmitted to them.
4. Data Storage & Security
Your data is stored and processed using the following infrastructure and service providers:
- Database: Supabase (PostgreSQL), hosted in the United States. We use Supabase's Row-Level Security (RLS) to ensure that your data is accessible only to your account.
- Hosting and CDN: The Theorify application is hosted on Vercel, with servers located in the United States.
- Payment processing: Payments are processed by Stripe. We do not store full credit card numbers on our servers. Stripe receives your payment information (card number, expiration, billing address) directly and handles it under their own privacy policy and PCI-DSS compliance.
- Email delivery: Transactional emails (account confirmations, magic links, billing receipts) are sent via Resend. Resend receives your email address and the content of transactional emails in order to deliver them.
- Data in transit: All data is transmitted over HTTPS/TLS encryption.
- Data at rest: Your data is stored in a managed PostgreSQL database (Supabase) that encrypts data at rest at the storage layer. Theorify does not require you to provide or store third-party AI provider API keys.
- Error monitoring: Application errors are tracked using Sentry. Sentry may receive error metadata including stack traces and browser information, but we configure Sentry to minimize the capture of personally identifiable information.
While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
5. Data Retention
- Conversations and workflows: Stored for as long as your account is active. You can delete individual conversations, nodes, or entire projects at any time from within the Service.
- Memory entries: Stored for as long as your account is active or until you delete them.
- Account data: Retained for a reasonable period after account closure as required for legal, tax, and accounting purposes (typically up to 7 years for billing records).
- Backups: Deleted data may persist in encrypted backups for up to 90 days, after which it is purged.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your account and associated personal data, subject to legal retention requirements.
- Export: Request an export of your conversation history and memory entries in a portable format.
- Opt out of marketing: Unsubscribe from non-transactional emails at any time using the unsubscribe link in those emails.
To exercise any of these rights, contact us at privacy@theorify.ai. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.
If you are located in the European Economic Area (EEA) or United Kingdom, additional rights may apply under the GDPR or UK GDPR. Please note that our Service is currently designed for US-based users; EU-specific compliance measures are under review.
8. Children's Privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete that information promptly.
If you believe we have inadvertently collected information from a child under 13, please contact us at privacy@theorify.ai.
9. International Data Transfers
Theorify is based in the United States, and our infrastructure (Supabase database, Vercel hosting) is located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your home country.
By using the Service, you consent to the transfer of your information to the United States. If you are located in the EEA, UK, or Switzerland, please note that we are currently evaluating appropriate transfer mechanisms (such as Standard Contractual Clauses) to ensure adequate protection for transfers of personal data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have provided one) and by updating the effective date at the top of this page. We may also post a notice within the Service.
Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this page periodically.
11. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy inquiries: privacy@theorify.ai
- General support: support@theorify.ai
© 2026 Theorify. All rights reserved.