Data Privacy Document

AI Agent, Integrations & Opt-In Data Practices

Updated: July 2026

This document supplements, and is incorporated by reference into, the Theanna Terms of Service and Privacy Policy.

I. INTRODUCTION AND RELATIONSHIP TO OTHER POLICIES

This Data Privacy Document (this “Document”) describes, in additional detail, how Theanna’s AI agent (including “Build Mode” and the underlying orchestration layer), its third-party Connectors, and the related opt-in data flows work. It is written for founders using the Services directly and for the security and privacy teams of Enterprise Customers evaluating Theanna.

This Document supplements, and is incorporated by reference into, the Terms of Service and the Privacy Policy. Defined terms not otherwise defined here (for example, “Plan,” “Credit,” “Connector,” “Connector Data,” “MSA,” and “Enterprise Customer”) have the meanings given in the Terms of Service. Where this Document conflicts with the Privacy Policy on the specific topics of the AI agent, Connectors, or opt-in data flows, this Document controls; the Privacy Policy governs all other data practices, and the Terms of Service governs your contractual relationship with us generally.

II. THE AGENT: BUILD MODE AND THE ORCHESTRATION LAYER

2.1 What the Agent Does

Theanna’s core product helps you track your progress against a set of startup “Milestones.” The first seven (7) Milestones are available to every user regardless of Plan; additional Milestones and AI-assisted guidance scale with your Plan. As you make progress, the agent may proactively prompt you toward your next step. For example, reminding you to watch an onboarding video for an upcoming Milestone, or prompting you to reach out to a partner or co-founder. Where the agent drafts a communication on your behalf (for example, an email to a partner), it prepares a draft for your review; it does not send communications on your behalf without your affirmative action, unless you have separately enabled an autonomous-sending feature that we have made available to you and clearly disclosed at the point you enable it.

We expect to expand these proactive, multi-step capabilities over time (for example, autonomous workflows that chain several actions together). Any such expansion will be reflected in an update to this Document, consistent with Section X below.

2.2 The Orchestration (Context) Layer

Build Mode and related features use an orchestration layer that maintains context about your prompts, milestones, and connected data so the agent can give relevant, personalized responses. This context is scoped as follows:

  • Across users: never shared. No user’s content, prompts, Connector Data, or agent context is accessible to, or shared with, another user’s account, under any circumstances.
  • Across your own projects: also isolated. If your Plan supports more than one business idea or workspace, each business idea has its own separate agent context; the agent does not carry over memory, prompts, or Connector Data from one of your business ideas to another.
  • Not model training: this context layer personalizes your own experience within your own account or business idea. It is a memory and retrieval layer, not a mechanism for training or fine-tuning the underlying AI models described in Section 2.3. Consistent with our Terms of Service and Privacy Policy, we do not use your prompts, Connector Data, or outputs to train foundation models for ourselves or third parties.

2.3 Model Providers

AI processing is performed using Anthropic as our primary model provider, with Google (including its Gemini models) as a fallback provider, hosted on infrastructure providers such as AWS. We may change model or infrastructure providers at any time, consistent with Section 4.5 of the Terms of Service. Each user, and each business idea within a user’s account, has a logically separated data environment; we implement controls designed to prevent cross-access.

2.4 Human Review of Agent Actions

Where Build Mode proposes or takes an action on a Connector (for example, opening a pull request on GitHub, updating a Linear ticket, or changing a Cloudflare configuration), Section 4.6 of the Terms of Service governs your review and approval rights and our related liability allocation. This Document describes the underlying data flows; the Terms of Service governs responsibility for the actions themselves.

III. CONNECTORS AND INTEGRATIONS

3.1 Overview and the Opt-In Principle

A “Connector” is any third-party account or service you choose to connect to the Services. Connectors are always opt-in: we do not access a Connector until you have affirmatively enabled it, and we request only the OAuth permission scopes needed for the features you use. The table below is illustrative of our current Connectors and is not exhaustive; we will update it as we add new integrations.

ConnectorIllustrative Data PulledPrimary PurposeRetention After Disconnect
GitHubRepository contents, commit history, issues, pull requests you selectBuild Mode code review/generation; opening or updating pull requests30 days, then deleted
LinearTickets, projects, issue status and commentsBuild Mode ticket creation/updates; workspace and KPI tracking30 days, then deleted
CloudflareDNS records, WAF/security configuration, analyticsBuild Mode infrastructure changes; security monitoring context30 days, then deleted
Google DriveDocuments and files you selectAI context for Build Mode and other AI features30 days, then deleted
Google Workspace (Calendar)Calendar events you selectScheduling and milestone-driven reminders (e.g., a nudge to attend a call)30 days, then deleted
QuickBooksAccounting and financial recordsFinancial and KPI Data; Traction Board metricsRetained per Retention section of the Privacy Policy
Stripe (as a connected integration)Revenue, subscription, and customer metricsTraction Board KPI reporting (separate from Stripe as our payment processor)Retained per Retention section of the Privacy Policy

3.2 Sensitive Content Within Connector Data

Connector Data (particularly source code, infrastructure configuration, and similar technical content from GitHub, Linear, and Cloudflare) may incidentally include credentials, secrets, or other sensitive technical information. We do not use Connector Data for any purpose beyond providing the Services to you as described in this Document and in Section 4.6 of the Terms of Service, and Connector Data is never published, distributed, or displayed to other users. You are responsible for your own account hygiene (for example, not committing plaintext secrets to a connected repository) and for representing that you are authorized to connect the account, as set out in the Terms of Service.

IV. OPT-IN AND CONSENT FLOWS

4.1 Enabling a Connector

You enable each Connector individually in your account settings. Enabling a Connector authorizes us to request the specific OAuth permission scopes needed for the features you have chosen to use; it does not authorize a bulk import of your entire connected account.

4.2 Relevance-Triggered Retrieval

Once a Connector is enabled, we retrieve data from it only when that data is relevant to your active session, prompt, or request. For example, if you ask Build Mode to review a specific repository and you have enabled the GitHub Connector, we retrieve the relevant repository content for that request; we do not continuously synchronize or bulk-import your entire GitHub account in the background.

4.3 Disconnecting a Connector

You may disable or disconnect a Connector at any time in your account settings. Disconnecting stops future retrieval immediately. Previously retrieved Connector Data is handled as described in the table in Section 3.1 and the Retention section of the Privacy Policy; disconnecting does not automatically or immediately delete data already retrieved, but it will be deleted or de-identified on the schedule described above.

4.4 Approving Agent Actions

Where Build Mode proposes an action on a connected account, we present it for your review before it is taken, unless you have specifically configured a feature to act automatically within a scope you define. See Section 4.6 of the Terms of Service for the related responsibilities and liability allocation.

V. COMMUNITY, MESSAGING, AND EVENT DATA

5.1 Community Forum Content

Community forum posts, comments, and interactions with AI-powered recommendations are processed to operate and improve the Services (including moderation and safety), but are not used to train the underlying AI models described in Section 2.3, consistent with our default no-training commitment.

5.2 Direct Messages Between Users

We do not routinely access or review the content of direct messages between users. We may access direct message content where necessary to investigate a safety or abuse report, enforce the Terms of Service, or comply with legal process. Direct messages are not used to train AI models.

5.3 Events and Workshops

For virtual events, workshops, or panels (for example, hosted over Zoom), the list of attendees is visible to other attendees during the live event, consistent with the standard participant view of the platform used to host the event. Theanna and the relevant platform provider (for example, Zoom) also retain attendance records after the event for administrative and reporting purposes.

VI. DATA SEGREGATION AND ISOLATION

6.1 Cross-user isolation: no user’s Content, prompts, Connector Data, or agent context is ever shared with another user.

6.2 Cross-project isolation: within a single account, each business idea or workspace has its own isolated agent context, as described in Section 2.2.

6.3 Logically separated environments: each user (or business idea, where applicable) is provisioned a logically separated data environment, with controls designed to prevent cross-access, consistent with Section 2.4 of the Privacy Policy.

VII. RETENTION AND DELETION

Connector Data is retained as described in the table in Section 3.1. Build Mode build logs, error logs, and action records are retained to provide the Services, support debugging, and maintain security, consistent with the Retention section of the Privacy Policy. Community content and direct messages are retained consistent with that same section. Where you request deletion of your account or specific data, we will process that request as described in Section VIII (Your Rights) of the Privacy Policy.

VIII. YOUR CONTROLS

You may:

  • Enable or disable any Connector at any time in your account settings.
  • Review and approve (or reject) Build Mode’s proposed actions on a connected account before they are taken, except where you have configured automatic execution within a defined scope.
  • Manage milestone-related reminder and notification preferences in your account settings.
  • Request access to, correction of, or deletion of your Personal Data as described in Section VIII (Your Rights) of the Privacy Policy.

IX. ENTERPRISE CUSTOMERS

If you access the Services as an authorized user of an Enterprise Customer, Section 1.3 of the Privacy Policy describes the controller/processor relationship between Theanna and your organization. Enterprise Customer administrators may have visibility into certain of your account activity and business information through administrative or cohort-reporting dashboards, including engagement and milestone-progress data, financial and KPI data (such as revenue, MRR, and customer counts) pulled from Connectors you have enabled, and integration adoption. This visibility reflects information you have chosen to share. A separate data processing agreement between Theanna and the Enterprise Customer governs that relationship in more detail.

X. CHANGES TO THIS DOCUMENT

We may update this Document from time to time, including as we add new Connectors or agent capabilities. Material changes will be notified consistent with Section XI (Changes) of the Privacy Policy.

XI. CONTACT US

Questions about this Document can be directed to support@theanna.io or to the Data Privacy Officer of Theanna, 2606 Hilliard Rome Rd Unit #V251, Hilliard, Ohio, 43026.