Therese AI Therese AI

Privacy policy

Last updated 18 August 2026.

This page explains what personal data Therese AI processes, why, how long we keep it, and how you can access or delete it. We keep the personal data we hold to a minimum.

Who we are

Therese AI is a product of Loheden AI Solutions AB, which is the data controller for the personal data described here. You will find how to reach us at the bottom of this page.

What data we process

  • Account data: your email address and, if you set it, your name. Used to sign you in and to send the briefs you ask for.
  • Client data: the businesses you set up, their settings, and the briefs generated for them. This is business information, not personal data about you.
  • Source content: public web content we read to build a brief. We store only short snippets (at most 300 characters) and a link; full articles are analysed in the moment and not kept.
  • Technical data: the IP address and timestamps recorded in the security and activity log described below.

Activity log

We keep an append-only log of meaningful actions on your account - signing in, viewing a brief, marking an idea used or skipped - with the time and the IP address. We use it to keep the service secure and as evidence of the service delivered if a payment is ever disputed. This log is included in your data export and is deleted when you delete your account.

Legal basis

We process account and client data to provide the service you signed up for (performance of a contract). We keep the security and activity log under our legitimate interest in running a secure service and defending against disputes.

Who we share it with

We do not sell your data and we do not share it for advertising. We use a small number of processors purely to run the service: an AI provider that generates the briefs, and our hosting and infrastructure provider. They act on our instructions under data-processing agreements and only for the purpose of delivering the service. We may also disclose data where the law requires it.

Transfers outside the EU/EEA

To generate briefs, limited data may be processed by providers outside the EU/EEA. Where that happens, we rely on appropriate safeguards, such as the European Commission's standard contractual clauses, to protect it.

How long we keep it

We keep your account and client data for as long as your account is open. The activity log is kept for at least 24 months for security and dispute-evidence purposes. When you delete your account, everything under it is deleted.

How we protect it

We hold data on servers in the EU, encrypt it in transit, keep encrypted backups, and limit access to what is needed to run the service. Exactly one administrator account exists.

Your rights

You can access, export and delete your data at any time. Under the GDPR you also have the right to correction, to object to processing, to restriction, and to data portability.

Sign in to download your data or delete your account from your account page.

If you believe we handle your data incorrectly, you have the right to complain to the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.

Cookies and analytics

We use a session cookie to keep you signed in and a cookie to remember your language and theme. Our public pages use privacy-friendly analytics that set no tracking cookies and do not profile you, so there is no cookie banner.

Terms of use

Your use of Therese AI is also governed by our terms and conditions.

Changes and contact

If we change this policy we will update this page and the date at the top. For any privacy question, or to exercise a right, reach us at [email protected].