Therese AI Therese AI

Privacy policy

Last updated 2 October 2026.

This page explains what personal data Therese AI processes, why, how long we keep it, and how you can access or delete it. We keep the personal data we hold to a minimum.

Who we are

Therese AI is a product of Loheden AI Solutions AB, which is the data controller for the personal data described here. You will find how to reach us at the bottom of this page.

What data we process

  • Account data: your email address and, if you set it, your name. Used to sign you in and to send the briefs you ask for.
  • Team data: which team you belong to and your role, the email address of a person a team admin invites (kept until the invitation is accepted, revoked or expires after seven days), what you write on a brief (votes, comments, who took a card, reviews), the one line you may add about what you post about, and the posts of your own voice. Your team's admins can see what you did on its briefs and the activity summary for each profile.
  • Profile data: the businesses and people you set up, their settings, and the briefs generated for them. This is business information, not personal data about you.
  • Source content: public web content we read to build a brief. We store only short snippets (at most 300 characters) and a link; full articles are analysed in the moment and not kept.
  • Technical data: the IP address, the browser and the timestamps recorded in the security and activity log described below.
  • Purchase data: whether you bought as a business or as a private person and when you said so, your billing country, the name and any tax id you gave at checkout, the version of the terms you accepted and whether you ticked the box accepting them, and the time, IP address and browser of the purchase. We keep it as evidence of the agreement and for bookkeeping.

Activity log

We keep an append-only log of meaningful actions on your account (signing in, viewing a brief, marking an idea used or skipped) with the time, the IP address and the browser it came from. We use it to keep the service secure and as evidence of the service delivered if a payment is ever disputed. This log is included in your data export and is deleted when you delete your account, apart from what the record described under Your rights keeps.

Legal basis

We process account and profile data to provide the service you signed up for (performance of a contract). We keep the security and activity log under our legitimate interest in running a secure service and defending against disputes.

Who we share it with

We do not sell your data and we do not share it for advertising. Four companies process data on our instructions, under data-processing agreements and only to deliver the service:

  • Hetzner: the servers the service runs on, inside the EU.
  • Cloudflare: domain name service, the proxy every request passes through, the mail that delivers your briefs, and encrypted backup storage.
  • OpenRouter: passes the material for a brief to the AI model that writes it, run by the company that makes that model.
  • Stripe: takes the payment for a plan: the card details never reach us, Stripe holds them and the invoices; we hold the customer and subscription identifiers Stripe gives us, the amount and the dates

We may also disclose data where the law requires it.

Transfers outside the EU/EEA

To generate briefs, limited data may be processed by providers outside the EU/EEA. Where that happens, we rely on appropriate safeguards, such as the European Commission's standard contractual clauses, to protect it.

How long we keep it

We keep your account and profile data for as long as your account is open. The activity log is kept for as long as your account is open too, for security and as evidence if a payment is disputed. When you delete your account, the teams you own and everything under them are deleted. If a team you own still has other members, you hand it to one of them first. What you did inside another person's team (votes, comments, reviews) stays with that team without your name; the posts of your own voice are deleted with you.

How we protect it

We hold data on servers in the EU, encrypt it in transit, keep encrypted backups, and limit access to what is needed to run the service. Exactly one administrator account exists.

Your rights

You can access, export and delete your data at any time. Under the GDPR you also have the right to correction, to object to processing, to restriction, and to data portability.

When you delete your account, any subscription is cancelled at once and everything under the account is erased. One record survives, because bookkeeping law and a possible dispute or legal claim require it (GDPR article 17(3)): your email address and the team's name, the dates the account was opened and deleted, how often you signed in and how many briefs each profile received, the invoices you paid with their Stripe identifiers, the payer's name, address and any tax id as Stripe holds them, and what you accepted when you bought: the version of the terms, whether you ticked the box, and the time, IP address and browser of that moment. It is kept for seven years and used for nothing else.

If a payment was ever disputed with your bank, or we closed the account, that record also keeps the disputes (what the bank said, what it concerned, how it ended) and the activity report, meaning what was delivered to you and when, because we may need them to defend a legal claim (GDPR article 17(3)(e)). They are kept for the same seven years and used for nothing else. A closed account is deleted 90 days after closing.

Sign in to download your data or delete your account from your account page.

If you believe we handle your data incorrectly, you have the right to complain to the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.

Cookies and analytics

We set three cookies and all three are necessary: one keeps you signed in, one protects the forms you submit, and one remembers the language you picked. Your light or dark setting is kept in your browser and never sent to us.

Our public pages are counted with Cloudflare Web Analytics, which sets no cookie, gives you no identifier and builds no profile of you. There is nothing there to consent to, which is why you see no cookie banner.

What your browser loads

Everything a page needs (fonts, styles, scripts, images) is served from thereseai.com. We use no third-party content network, so displaying a page never makes your browser hand another company your IP address. The one exception is the analytics counter above, which comes from Cloudflare, the provider already carrying every request to us.

Terms of use

Your use of Therese AI is also governed by our terms and conditions.

Changes and contact

If we change this policy we will update this page and the date at the top. For any privacy question, or to exercise a right, reach us at [email protected].

Are you sure?