Privacy Policy
Theta Meridian — Privacy Policy Effective Date: June 8, 2026 Last Updated: August 27, 2026
This Privacy Policy explains what data Theta Meridian, LLC ("we," "us") collects when you use Theta Meridian, how we use it, and the rights you have over it.
1. What We Collect
We collect:
- Account information — name, email address, password hash, and billing details.
- Content you create — documents, conversations with AI agents, files you upload, and outputs you generate within the Service.
- Usage data — log files, IP address, browser type, pages visited, timestamps, and feature interactions. This helps us debug and improve the Service.
- Payment information — handled by Stripe; we do not store your full card number on our servers.
2. How We Use Your Data
We use your data to:
- Operate the Service (storage, display, AI processing).
- Bill you and prevent fraud.
- Communicate with you about your account and the Service.
- Improve the Service by analyzing aggregate usage patterns.
3. We Do Not Train AI Models on Your Content
This is a core promise. Your conversations with agents, the documents you upload, and the work you produce in the Service are not used to train AI models — ours or anyone else's. Your work is your intellectual property. We process it to deliver the Service to you. We do not mine it.
4. Third Parties We Share Data With
We use a small number of vendors to operate the Service. Each one processes only the data necessary for its function, and none of them are permitted to use your data for their own purposes:
- Supabase — database and authentication infrastructure.
- Vercel — application hosting and content delivery.
- Anthropic — AI model provider for agent conversations. Anthropic's API terms prohibit training on customer data.
- OpenAI — AI model provider for agent conversations, embeddings, audio transcription, and speech synthesis. OpenAI's API terms prohibit training on customer data.
- Google — AI model provider for real-time voice conversations and agent voice synthesis (Gemini). Google's paid API terms prohibit training on customer data.
- Stripe — payment processing and subscription management.
- Resend — outbound transactional email.
- Exa, Tavily, Brave, and DuckDuckGo — web search providers used to discover candidate sources when you ask an agent to research a topic. Only your search query text is sent to these providers, not your other Service content.
- CourtListener — a legal-research API operated by the Free Law Project (a nonprofit) used to resolve case names and citations you provide to their published court opinions. Only the case name or citation text you enter is sent.
We do not sell your data. We do not share it with advertisers.
5. How Long We Keep Your Data
- Active account data: kept while your account is active.
- After cancellation: your content remains available for export for at least 30 days, and is deleted from our active systems no later than 90 days after cancellation. Residual copies in encrypted backups are purged on our regular backup-rotation cycle.
- Billing and tax records: kept for 7 years to meet legal obligations.
- Aggregated, non-identifying usage data: kept indefinitely.
6. Your Rights
You can:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your account and your content.
- Export your content in a portable format.
- Object to specific uses of your data.
To exercise any of these rights, email support@thetameridian.com. We respond within 30 days.
7. Security
We use industry-standard practices: encrypted transport (HTTPS), encrypted storage at rest, access controls, and audit logs. No system is perfectly secure. We will notify you promptly if a breach affects your data.
8. Children
The Service is not for children under 18. We do not knowingly collect data from anyone under 18.
9. International Users
The Service is operated from the United States. During our beta, access is by invitation only, and we do not invite residents of the EU, EEA, UK, or Switzerland — our invitation process checks and enforces this before any account is created, so our data practices are not designed for GDPR or UK GDPR compliance. We also do not invite California residents during beta; our data practices otherwise follow U.S. law, including CCPA where applicable. If you were invited and access the Service from outside the U.S., you are responsible for compliance with your local laws. Your data is transferred to and processed in the U.S.
10. Changes
We may update this Policy. Material changes will be announced by email at least 14 days before they take effect.
11. Contact
Privacy questions: support@thetameridian.com