1. Introduction
Thelooma ("we", "us", "our") operates the Thelooma platform. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our services. We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller responsible for your personal data is:
Given the current scale of our data processing operations, we have not appointed a Data Protection Officer (DPO) under GDPR Art. 37. If our processing activities require a DPO in the future, we will appoint one and update this policy accordingly. For all privacy inquiries, contact us at the email above.
3. Data We Collect
3.1 Account Data
- Name, email address, and password (hashed)
- Workspace and company information you provide during onboarding
- Billing information (processed by Stripe — we do not store full card numbers)
3.2 Usage Data
- Chat messages between you and AI agents
- Files and documents created within the Platform
- Board content (items, connections, comments)
- Knowledge base entries and decisions you add
- Token usage and billing records
- Login timestamps and session data
3.3 Integration Data
When you connect third-party accounts (Google, GitHub, Slack, Twitter/X, LinkedIn, Facebook, Instagram, Telegram), we store:
- OAuth access tokens and refresh tokens (encrypted with AES-256-GCM)
- Provider user ID and username for display purposes
- Authorized scopes (the specific permissions you granted)
We do not store your passwords for third-party services. OAuth tokens grant limited, revocable access as defined by the scopes you approve. Integration tokens are used only when you or your configured agents explicitly trigger an action that requires them.
3.4 Voice & Audio Data
- Voice messages you send to agents (audio files and transcriptions)
- Voice messages are processed for transcription and stored associated with your conversation
- Audio files are sent to third-party transcription providers for processing
Voice data is processed under your explicit consent (GDPR Art. 6(1)(a)), which you provide by choosing to record and send a voice message. You may withdraw consent at any time by ceasing to use voice features. Previously submitted voice data can be deleted upon request.
4. How We Use Your Data
We use your data for the following purposes:
- Service delivery: Operating the Platform, processing AI agent requests, executing tool actions on your behalf
- Authentication: Verifying your identity and managing sessions
- Billing: Processing payments, tracking token usage, generating invoices
- Communication: Sending notifications (email, Telegram) about agent activity, blockers, and account updates
- Service improvement: Analyzing aggregated, fully anonymized usage statistics (such as feature adoption rates and error frequencies) to improve the Platform. This processing is based on our legitimate interest (GDPR Art. 6(1)(f)) and uses only irreversibly anonymized data that cannot identify individual users
- Security: Detecting abuse, preventing fraud, and maintaining Platform integrity
We do not use your content, prompts, conversations, or files to train AI models.
5. Legal Basis for Processing (GDPR)
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the services you subscribed to, including AI agent interactions, file management, and project features
- Consent (Art. 6(1)(a)): For optional features including third-party integrations, voice/audio processing, and notification preferences. You may withdraw consent at any time
- Legitimate interest (Art. 6(1)(f)): For security, fraud prevention, and service improvement using anonymized data. We have conducted a balancing assessment and concluded that these interests do not override your rights. Details are available on request
- Legal obligation (Art. 6(1)(c)): For tax, billing, and regulatory compliance
6. Data Sharing & Sub-Processors
We share your data only in the following circumstances:
- AI providers: Chat messages are sent to AI model providers for real-time processing of your requests. These providers do not use your data for training
- Payment processor: Billing data is processed by Stripe under their privacy policy
- Third-party integrations: When you use connected services, relevant data is sent to those services (e.g., email content to Gmail, posts to Twitter)
- Legal requirements: When required by law, court order, or governmental authority
We do not sell your personal data to third parties.
Sub-Processors
The following third-party sub-processors handle personal data on our behalf under GDPR Art. 28 data processing agreements:
- Anthropic (US) — AI model provider (Claude). Transfer mechanism: Standard Contractual Clauses (SCCs)
- OpenAI (US) — AI model provider (GPT-4o). Transfer mechanism: Standard Contractual Clauses (SCCs)
- Stripe (US) — Payment processing. Transfer mechanism: Standard Contractual Clauses (SCCs)
- Runway (US) — AI video generation. Transfer mechanism: Standard Contractual Clauses (SCCs)
All international data transfers to US-based sub-processors are protected by EU Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c), ensuring an adequate level of data protection.
7. Data Storage & Security
- Data is stored on servers located in the European Union
- All sensitive credentials (OAuth tokens, SMTP passwords, API keys) are encrypted at rest using AES-256-GCM
- Passwords are hashed using bcrypt with salt
- All data in transit is encrypted via TLS/HTTPS
- Access to production systems is restricted to authorized personnel
- We conduct regular security reviews of our infrastructure
Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (Art. 34).
8. Data Retention
- Account data: Retained while your account is active and for 30 days after deletion
- Chat history: Retained while your account is active, with a maximum retention period of 24 months. You can delete individual conversations at any time
- Voice data: Retained for the same duration as associated chat conversations
- Billing records: Retained for 7 years as required by tax regulations
- OAuth tokens: Deleted immediately when you disconnect an integration
- Temporary data: Link codes, CSRF tokens, and session state are automatically purged after expiration (typically 10 minutes)
9. Automated Decision-Making
The Platform uses AI agents that take automated actions on your behalf (e.g., generating content, sending messages, executing code). These actions are:
- Initiated by your explicit instructions or configurations you have set up
- Not used for profiling or making decisions that produce legal or similarly significant effects on you
- Subject to your review — you can inspect all agent actions in your conversation history
Under GDPR Art. 22, you have the right not to be subject to solely automated decision-making that produces legal or significant effects. If you believe an automated process has affected you in this way, contact us for human review.
10. Your Rights (GDPR)
Under the GDPR, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Request that we limit how we process your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Revoke consent for optional processing at any time
To exercise any of these rights, contact us at privacy@thelooma.io. We will respond within 30 days. In cases of complex or numerous requests, we may extend this period by an additional 60 days, in which case we will notify you within the initial 30-day period.
11. Cookies & Local Storage
Thelooma uses minimal cookies and local storage:
- Authentication cookies: HTTP-only cookies to maintain your session (strictly necessary)
- CSRF token: Cookie used for cross-site request forgery protection (strictly necessary)
- User preferences: Theme and UI settings stored in localStorage (functional)
We do not use tracking cookies, analytics cookies, or advertising cookies. All storage we use is strictly necessary or functional for the service. Under the EU ePrivacy Directive, strictly necessary storage does not require consent. You can clear localStorage at any time via your browser settings.
12. Children's Privacy
Thelooma is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or prominent in-app notification at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
14. Contact & Complaints
For privacy-related questions or to exercise your rights:
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia (www.ip-rs.si) or your local data protection authority.