Your privacy is fundamental to us. This Privacy Policy describes, transparently and in detail, what data we collect, how we use it, with whom we share it, how we protect it, and what your rights over it are in the Theros app.
What changed on October 10, 2026: we detailed which AI and search providers we use and how each one handles data (sections 5.3 and 5.9), that we also process AI data outside Brazil, the rating of AI responses (5.10), the installation identifier used against abuse (5.11), and the 15-day notice for material changes (section 14). We also now ask for your permission before your first use of AI, with a separate option, turned off by default, for other AI providers, and you can change both in Settings > Privacy > AI providers (sections 2, 5.0, 5.9, 8 and 12). Finally, we describe precisely the notices and the automatic removal of files when a paid plan expires (section 9) and how we announce changes to this policy (section 14).
What changed on October 6, 2026: this version includes rules for health data (appointments, medical tests, medications, nutrition, workouts and well-being) and for the data of family members that you record (sections 3.17 to 3.19); the food diary with AI photo analysis (3.19); ideas, canvases and attachments (3.20); AI memory and tone (3.4); calendar subscription by link, Telegram, the public API with webhooks, and automation rules (4.4 to 4.7); who can access stored data (7.2); retention periods and what happens when a paid plan expires (section 9); and the corrected description of voice chat (3.5 and 5.1). The full summary is in section 14.
1. Data Controller
The controller of your personal data is:
Theros App
Contact e-mail: rafaelfurlan@lunanexgen.com
Data Protection Officer (DPO): rafaelfurlan@lunanexgen.com
2. Legal Basis for Processing (LGPD, Art. 7)
Theros's processing of your personal data is based on the following legal bases of the Lei Geral de Proteção de Dados (LGPD, the Brazilian General Data Protection Law, Law 13.709/2018):
- Consent (Art. 7, I): for optional features such as the Gmail and Google Calendar integrations, calendar subscription by link (ICS), using Theros through Telegram, location collection, AI memories (stored only when you ask), artificial intelligence tagging of Closet items, sending Closet outfit photos via WhatsApp, reading prescriptions from a photo, and AI analysis of meal photos.
- AI features (consent, Art. 7, I): before your first use of AI, we ask for your permission to send your messages and the app data needed to respond to Google (Gemini, on Google Cloud Vertex AI). Without this permission, the AI features remain turned off and the rest of the app works normally.
- Other AI providers (specific consent, Art. 7, I, and Art. 33, VIII): if you turn on the "Other AI providers" option (off by default), ordinary text messages may also be processed by other providers in the United States, as described in section 5.9. This is an international data transfer, carried out with your specific and prominent consent.
- Sensitive personal health data (Art. 11, II, a): appointments, medical tests, medications, nutrition, workouts, mood and well-being score are processed with your specific and prominent consent, expressed when you decide to use each feature and, for features with AI analysis, in a dedicated notice before first use. You may revoke your consent and delete this data at any time (section 3.17).
- Performance of a contract (Art. 7, V): to provide the contracted features of the app (financial management, AI chat, tasks, etc.).
- Legitimate interest (Art. 7, IX): for service improvements and operational communications.
- Compliance with a legal obligation (Art. 7, II): when required by law or court order.
3. Information We Collect
3.1 Registration and profile data
- Required: name, e-mail and password (or authentication via Google Sign-In).
- Optional (provided by you): profile photo, phone number, date of birth, CPF (Brazilian individual taxpayer ID), gender, occupation.
Purpose: identification, authentication and personalization of the in-app experience.
3.2 Financial data
- Transactions (income and expenses), bank accounts and budgets.
- Financial goals, investments and net worth.
- Income data: salary, deductions, type of employment contract, salary history.
- Recurring expenses and income.
- PLR (Profit Sharing).
Purpose: to provide financial management features, reports, projections and personalized insights.
3.3 Task, note and list data
- Tasks, personal notes, shopping lists and Kanban boards you create.
Purpose: personal organization and productivity.
3.4 AI communication data
- Messages sent to the AI chatbot (text).
- Voice commands (transcribed text) and history of executed commands.
- Responses generated by the AI.
- Conversation history.
- AI memories: phrases you ask Theros to remember (for example, "I'm vegetarian"), stored only when you ask.
- Tone chosen for the assistant (gentle, direct or firm), if you choose one.
- Messages exchanged with the Theros bot on Telegram (text, captions and photos of receipts), when you use this optional channel (section 4.5).
Purpose: to provide contextualized responses and personalized financial insights through artificial intelligence.
Storage: chat messages and command history are stored in Firestore while your account is active.
AI memories ("remember that..."): when you explicitly ask, in the app chat or in a WhatsApp text message, that Theros remember something (for example, "remember that I'm vegetarian"), we store that phrase, up to 200 characters, together with the source of the request (chat, WhatsApp or typed by you) and the dates. We do not store memories on our own initiative, nor from documents, PDFs, e-mails, images, websites, scheduled agents, automations or audio messages. For security reasons, we do not store passwords, tokens, keys, card numbers, CPF, CNPJ (Brazilian company taxpayer ID), bank accounts or sensitive personal data (health, religion, political opinion, sex life, racial or ethnic origin, biometric data and trade union membership); detection is automatic and based on words and patterns, and is therefore not perfect: avoid writing this type of information. The number of memories depends on your plan. Memories are sent to Google Gemini together with the context in app chat and WhatsApp conversations (section 5.2), marked as your data and never as an instruction; the text of memories is not recorded in server logs.
Your control: in Profile > AI Assistant > Theros Memories you can view, edit, delete, delete all, manually add memories, and turn off the use of memories. When you delete a memory, Theros stops using it immediately; the message in which you asked for it to be stored remains in the chat history, which you control separately.
Assistant tone: your choice of tone is kept in your settings and guides the style of responses in the chat, on WhatsApp, in the morning summary, in the financial check-in and in some notifications. If you do not choose one, nothing changes.
3.5 Voice and audio data
- Voice commands: audio captured by the device microphone and converted to text by Google's speech recognition service (Google Speech Recognition). The audio is not stored by Theros.
- Voice chat: audio captured by the microphone is sent in real time to the Google Cloud speech recognition service (Speech-to-Text), using a short-lived credential issued by our server, which returns the text; that text follows the same path as text chat (section 5). The response, in text, is converted into speech by Google Cloud Text-to-Speech (Chirp 3 HD voice) and played on the device. The audio of your voice and the audio of the response are not recorded or stored by Theros. We only keep a count of minutes used per month, to apply the plan limit.
Purpose: to enable voice interaction with the AI assistant.
3.6 Location data
- Saved places: name, category and address of places you register.
- Location-based reminders: automatic rules associated with saved places (e.g., a reminder to log an expense when arriving at the supermarket).
- Geofencing (location-based reminders): real-time location is used only on the device to check proximity to configured reminders. For this purpose, it is not sent to our servers or stored.
- Weather forecast (Weather card and page, chat and Closet): to show the weather forecast and, in the Closet, to suggest outfits according to the weather, the app uses an approximate position. The coordinate obtained by GPS is rounded on the device itself to a grid of about 11 km (0.1 degree) before being sent to our server (Firebase Cloud Functions); you may also provide just the name of a city. Our server queries the forecast provider (WeatherAPI.com; as a fallback and for the later days of the forecast, MET Norway) sending only that area of about 11 km or the city name, without your name, e-mail, account identifier or IP address, and caches the forecast by area, without identifying you. In the Closet, the approximate position and the name of the chosen city are saved in your Closet preferences and are only used with your consent (section 3.14).
- Earlier versions of the app: versions of the app prior to the one that began using our server for the weather forecast queried the Open-Meteo service directly from the device, sending the GPS coordinate or the city name and, consequently, the device's IP address. Once you update the app, this direct transmission no longer occurs.
- City name from position: to display the name of your city, the app uses the operating system's geocoding service (Apple or Google), which may receive the coordinate obtained by GPS in accordance with those providers' policies, and, as an alternative, the OpenStreetMap Nominatim service, to which the app sends only the coordinate rounded to about 11 km; in that case OpenStreetMap also receives the device's IP address. When you enter a city, our server may look it up on WeatherAPI.com or, if unavailable, on OpenStreetMap Nominatim.
- City and state in your profile: if you have already granted the app location permission, it may, at most once a week, obtain a low-accuracy position, convert it into the name of your city and state, and save only those two fields (and the date of the update) in your profile, in order to target in-app notices by region. Coordinates are not recorded in this entry.
- Taps on in-app notices: when you tap a notice (popup) displayed by the app, we record the tap with your account identifier and e-mail, the date and time and, if location permission has already been granted, the device's low-accuracy position, to measure the performance of the notices.
Purpose: location-based reminders and automations voluntarily set up by you; weather forecast and Closet suggestions; regional targeting and performance measurement of in-app notices.
Control: you can turn off location permission at any time in your device settings. The weather forecast also works if you provide only a city and, in the Closet, you can enter the city or revoke the use of location in Closet settings.
3.7 Health and well-being data
- Water intake log (amount in ml, date/time).
- Daily hydration goal.
- Sensor data read, only with your explicit authorization and only if you turn on the Health & Longevity module, from Health Connect (Android) or Apple HealthKit (iOS): steps, active calories, resting heart rate, heart rate variability (HRV), sleep (duration and stages), weight and body fat percentage. On iOS, additionally, continuous heart rate (used only to estimate resting heart rate when your health app does not provide it), oxygen saturation (SpO2) and respiratory rate. Access is read-only; Theros never writes data to Health Connect or HealthKit.
- Workouts (Workout module, optional): if you turn on workout import, the app reads from Apple HealthKit (iOS) and, when available, from Health Connect (Android) your workout sessions: activity type, start and end time, duration, distance, energy burned, and average and maximum heart rate during the workout. See section 3.15.
Purpose: personal hydration tracking; calculation of your daily well-being score (activity, recovery and sleep pillars), sleep debt, trends and anomaly alerts compared only against your own history (for example, resting heart rate above your usual level or a series of poorly slept nights). Each type of data is displayed on the Health screen and used exclusively for this feature.
How we handle sensor data:
- Only daily aggregates (for example, total steps, hours of sleep, average resting HR for the day) are stored in your account, in Firebase Firestore, to generate history and trends. Raw samples never leave the device.
- They are never used for advertising, never sold, rented or shared with third parties, data brokers or advertising platforms, and never used for credit, insurance, employment or any other decision with legal effect on you.
- They are never used to train artificial intelligence models. When you request health insights or talk to the assistant about the topic, only aggregated summaries may be processed by Google Gemini, under the terms of section 5, to generate the response displayed to you.
- You can revoke access at any time in Health Connect / the Health app or in Health > Sources > Disconnect; from then on, Theros stops reading the sensors. Aggregates already recorded are deleted together with your account (section 8) or upon request.
3.8 Contact data
- Contacts you manually register in the app: name, e-mail and optional data (phone number, notes, etc.).
- Contact groups for organization.
Purpose: contact management for sending e-mails and reports. Theros does not import contacts from your phone's address book. All contacts are registered manually by you.
3.9 Settings and preference data
- Layout preferences, widgets and security settings (PIN).
Purpose: personalization of the user experience.
3.10 Automatically collected data
- AI usage metrics: token consumption records stored locally on the device (90-day retention) and on the server (to control your plan's quota).
- Notification token (FCM): device identifier for sending push notifications.
- Device data: device model (e.g., "iPhone 15", "SM-S921B"), brand (e.g., "Apple", "Samsung"), operating system and version (e.g., "Android 15", "iOS 18.1"), platform (iOS, Android, Web) and app version.
- Authentication method: type of login used (Google Sign-In or e-mail/password).
- Session data: date/time of last access and session counter.
Purpose: technical support, account security, detection of unauthorized access and improvement of the user experience.
3.11 User directory for collaboration
To enable sharing of tasks and Kanban boards, Theros provides an internal search feature by name or e-mail. When you use the app, your name, e-mail and profile photo may be visible to other Theros users who use this search feature for collaboration purposes.
3.12 Waitlist and landing page forms
When you sign up through forms on the website (waitlist, contact, beta), we collect:
- Name, e-mail and phone number (the latter optional): for contact and identification.
- Feedback / free-form message: to understand your needs.
- IP address: used only to prevent spam and abuse (rate limiting of no more than 2 sign-ups per IP per hour). The IP is automatically deleted after 30 days by a daily cleanup routine, keeping only the other data you knowingly provided. Legal basis: legitimate interest in security (LGPD Art. 7, IX).
3.13 Public testimonials displayed on the landing page
Testimonials displayed on the home page may include a name (or initials), star rating, review quote and date. This data is published only after your explicit consent or when it comes from reviews you have already voluntarily made public (App Store, Google Play). You may request removal at any time through the contact channels (Section 15).
3.14 Digital Closet
The Closet is an optional feature. If you use it, we process the data below.
- Images of items: the photo (camera or gallery) is processed on the device itself: the app downsizes the image, removes embedded metadata (such as EXIF and GPS location) and cuts out the item, removing the background. When automatic cutout works, the original photo is neither sent nor stored: we store in Firebase Storage (region
southamerica-east1) only the cut-out image and a thumbnail. If the cutout does not work and you choose to use the photo without cutout, we store the downsized photo, with the background and without metadata. The app instructs you to photograph only the item; photos of people, faces or documents are not supported.
- Tags and item data: category, type, colors (extracted by code on the device), pattern, material, occasion, season, formality, warmth level, name and, if you choose to provide them, brand, price, currency, purchase date and notes.
- Outfits, usage and preferences: saved outfits, usage history ("wore today"), ratings of suggested outfits (liked/disliked and reason) and Closet preferences (sensitivity to cold, air-conditioned environment, default occasion and display format).
- Approximate location: if you allow it, an approximate position (grid of about 11 km) or the name of a city, used for the weather forecast (section 3.6).
- Record of your consents: what you allowed or declined (AI tagging, location and sending outfit photos via WhatsApp), the version of the text presented, the date and time, the channel in which you decided (app or WhatsApp, in the case of outfit photos), and the statement that you are 18 years of age or older (requested only for AI tagging).
- Using the Closet via WhatsApp (optional): the conversation state (the last outfit suggestion made to you, to respond to requests such as "another outfit" or "wore it") and a daily counter of images sent, used to limit abuse. Usage entries marked via WhatsApp ("wore today") go into your usage history just like those made in the app.
- Feature usage metrics: aggregated events (for example, onboarding step, success or failure of the cutout, export format), without names, photos or identifiers of your items, and monthly usage counters per account.
Purpose: to organize your closet, suggest outfits according to the weather and occasion, calculate information such as cost per wear and unworn items, and allow you to export or share the image of an outfit when you ask. Outfits are put together by rules executed on your device; artificial intelligence only suggests tags for the items (section 5.7), and you always confirm or edit before saving.
Legal basis: performance of the service of storing and organizing your closet (Art. 7, V) and, for AI tagging, the use of location and sending outfit photos via WhatsApp, your consent (Art. 7, I), requested separately, never pre-checked and revocable at any time.
Retention and deletion: until you delete the item, clear the closet (Closet settings) or delete your account. Deleting an item removes its record and images; clearing the closet removes all Closet records and images; deleting the account or using "Clear Data" also removes the Closet images (section 9). The Closet conversation state on WhatsApp and the daily counter are removed together with the closet.
Outfit photos on WhatsApp (optional): if you use Theros through WhatsApp, you can ask for outfit suggestions and receive, in the conversation, the image of the outfit. This only happens after you turn on "Look photos on WhatsApp" in Closet settings, through a dedicated consent, separate from the others and never pre-checked. Without it, Theros responds with text only.
- What is sent: a collage assembled by our server with the cut-out images of your own items (the same ones already in your account), without photos of people. On the free plan, the image may carry the Theros watermark. We do not include your name, e-mail, location or other app information in the image. The text messages in the conversation (for example, the description of the outfit) follow the same path as the other messages on the WhatsApp channel.
- Who processes it: Meta, through the WhatsApp Business platform (WhatsApp Cloud API), which delivers the image to your WhatsApp. The image passes through Meta's servers (sections 7 and 12).
- What we keep: we do not keep the collage image after sending: it is generated on demand for each request. Once delivered, the image remains in your WhatsApp conversation and, in Meta's systems, is handled in accordance with WhatsApp/Meta's terms and privacy policy, which we do not control (therefore we cannot promise any timeframe or method of deletion by Meta). We limit the daily number of images sent per account to prevent abuse.
- How you allow and revoke it: you can allow or decline in the app (in the Closet onboarding or in Closet settings) or in the WhatsApp conversation itself, by tapping the buttons Theros shows along with the explanation of what will be sent (allowing only takes effect after that tap). You can turn off "Look photos on WhatsApp" at any time in Closet settings or by asking on WhatsApp to turn off the photos. From then on, Theros stops sending outfit images and responds with text, and no new images are sent. Images already in your WhatsApp conversation can be deleted by you in WhatsApp itself.
- Age: outfit images are not sent to artificial intelligence models and this feature does not require the 18+ statement, but Theros is still not intended for persons under 18 (section 13).
Minors: the Closet is not intended for persons under 18 (section 13).
3.15 Workout (gym and exercise)
Workout is an optional feature. If you use it, we process the data below.
- Workout plans and exercises: the workout plans you create (name, days of the week, exercises, planned sets) and the custom exercises you register. The exercise catalog is part of the app and is not your data.
- Completed workouts: exercises, sets, loads, repetitions, duration, perceived exertion, notes, personal records and the workout in progress (a draft saved to your account so you can resume it later). From this information we calculate, using rules on the device, sets per muscle, statistics, estimated recovery and charts.
- Weight and body fat: values you record in Workout or, if you allow it, that the app reads from HealthKit/Health Connect.
- Imported workouts (optional): from Apple HealthKit (iOS) and Health Connect (Android, when available), always with your authorization. Imported workouts enter your history as activities, without strength training sets.
- Gym check-in: the date and time of the check-in and the name and identifier of the gym chosen from your saved places. When you tap "Check-in", the app may compare the device's current position with your saved places, on the device itself and only if location permission has already been granted; this position is not sent to our servers or stored.
- Notice on arriving at the gym (optional): uses the same geofencing feature described in section 3.6, executed on the device, and requires background location permission, requested only after explaining why. Location is not sent to our servers. You can turn it off at any time in Workout > Settings.
- Preferences: unit (kg or lb), default rest time, weekly goal, chosen gym and which imports are turned on.
- Experience points: the app awards gamification points for completed workouts and records.
Purpose: to record and track your workouts, show which muscles each exercise and each workout plan targets, calculate statistics and records, and bring into one place the workouts you already record in other apps. The weekly set ranges displayed in the app are general references, not a prescription or medical or physical education advice.
Health data: imported workouts, workout heart rate, weight and body fat are health data (sensitive personal data, LGPD Art. 11). They are only read with your explicit authorization, are never used for advertising, never sold, rented or shared with third parties, data brokers or advertising platforms, and never used for credit, insurance, employment or any other decision with legal effect on you. Workout does not use artificial intelligence: workout data is not sent to Google Gemini.
Legal basis: performance of the service of recording your workouts (Art. 7, V) and, for importing workouts and weight from other apps and for the location-based notice, your consent (Art. 7, I and Art. 11, II, a), requested separately, never pre-checked and revocable at any time.
Retention and deletion: until you delete the workout or the workout plan, or delete your account (section 9). You can turn off import in Workout > Settings > Import; from then on, Theros stops reading those sources. Workouts already imported remain in your account until you delete them.
3.16 Medications and dose reminders
The medication log is an optional feature. If you use it, we process the data below.
- Registration: medication name, dosage, dose times (including the "every X hours" schedule and the time of the first dose), days of the week, treatment end date, notes and whether the reminder is turned on.
- Dose log: which doses you marked as taken (medication, day, time and the moment of marking). From these entries we calculate, on the device, the monthly adherence map (complete days, partial days and days with missed doses), the adherence percentage and the streak of days.
- Reminders: the server schedules a notice for each dose, at the times you set. The text of the notice includes the medication name, dosage and time, passes through the push notification services of Google (Firebase Cloud Messaging) and Apple (APNs), and is visible on the device's notification screen (section 7.1). You can turn off the reminder for each medication, or the app's notifications, at any time.
- Reading prescriptions from a photo (optional): see section 5.8.
Purpose: to remind you to take your medications at the times you chose and show your adherence history. Theros is not a medical device, does not prescribe, does not recommend doses and does not replace the advice of a healthcare professional; reminders are a support tool, and responsibility for the use of the medication is yours.
Health data: medications and doses are health data (sensitive personal data, LGPD Art. 11). They are kept only in your personal account (never in shared accounts, such as the family account), are never used for advertising, never sold, rented or shared with third parties, data brokers or advertising platforms, and never used for credit, insurance, employment or any other decision with legal effect on you. The registered data is not sent to Google Gemini; the only exception is a prescription photo that you yourself choose to send (section 5.8).
Legal basis: performance of the service of reminding you of and recording your doses (Art. 7, V) and, for reading prescriptions from a photo, your explicit consent, requested separately before first use (Art. 11, II, a).
Retention and deletion: until you delete the medication or delete your account (section 9). When you delete a medication, its future reminders are no longer sent.
3.17 Health data: common rules
Appointments, medical tests, medications, doses, nutrition and weight, workouts, mood, hydration and the well-being score are sensitive personal data (LGPD, Art. 5, II and Art. 11). The rules below apply to all of them, in addition to the specific rules of each feature.
- Legal basis and purpose: specific and prominent consent (Art. 11, II, a), expressed when using each feature, and performance of the service you requested. We use this data only to organize, remind, calculate and show you what you recorded, and for the AI functions you trigger.
- Never for advertising: we never use health data for ads, never sell, rent or share it with third parties, data brokers or advertising platforms, and never use it for credit, insurance, employment or any other decision with legal effect on you.
- Who processes it: only the processors necessary for the app to function: Google Cloud / Firebase (storage and infrastructure, São Paulo region) and, for the AI functions you trigger, Google (Vertex AI / Gemini), under the terms of section 5. The providers are listed in section 7.
- No diagnosis: Theros is not a medical device; it does not diagnose, does not prescribe, does not recommend doses, diets or treatments, and does not replace the advice of a physician, nutritionist or other healthcare professional. The AI only organizes and summarizes what you provided.
- Your control: you can edit or delete any health record at any time in the app, delete all data with "Clear Data" or delete your account (section 9), and revoke consent by no longer using the feature or by turning off imports and AI in the settings of each one.
- Only in your personal account: these records are kept in your personal space and never in shared accounts, such as the family account.
- Notifications: by default, health notices show the minimum necessary (for example, only the time of an appointment), since they appear on the lock screen (section 7.1).
- Technical records: we do not record the content of appointments, medical tests, medications or meals in logs, usage analytics or error reports; we keep only technical identifiers, counts and error codes.
3.18 Appointments, medical tests and people you track
The Appointments module (Health and Well-being) is optional. If you use it, we process:
- People: name, relationship, date of birth, blood type, allergies, health insurance plan and member card number, notes and color of each person you register (yourself, family members or dependents).
- Appointments: person, specialty, professional (name, CRM (Brazilian medical license number) and phone number), location or link, date, reason, agenda (questions and symptoms), appointment record (what was said, diagnosis as reported by you, instructions and prescription), follow-up, tests ordered, cost and reimbursement, attachments and notification preferences.
- Medical tests: person, test, status, dates, laboratory, result (notes and key values) and attachments.
- Attachments: prescriptions, medical reports, referral forms and results as images or PDFs, stored in Firebase Storage (São Paulo region) and counted toward your plan's storage quota.
Data of family members and dependents: when recording health data of another person, you represent that you have authorization or standing to do so (for children and legally incapacitated persons, as their legal guardian), and the app asks for this confirmation before the first entry. This data is kept only in your personal space and never in the shared account. The person to whom the data relates may request access, correction or deletion through the account holder or via the e-mail in section 15. Record only what you have the right to record.
Purpose and AI: to organize appointments, medical tests, reminders and history. When you talk to the assistant about an appointment or test, a short summary may be sent to Google Gemini (section 5.2); the diagnosis, instructions and notes from the record are not included automatically, and the content is treated as data, never as an instruction. The appointment appears in the app's calendar as read-only and is not sent to Google Calendar or Apple Calendar. With one tap, you can create a task, note or financial entry (cost or reimbursement, Health category, in the personal ledger) from an appointment; these items then follow the rules of the respective features.
Notifications: by default, an appointment notice shows only the time; you can choose, for each appointment, to also display the specialty and the person.
Retention and deletion: until you delete it. "Clear Data" and "Delete Account" delete people, appointments, medical tests and attached files. Deleting a person who already has an appointment or test archives that person, so as not to lose the history; to erase the history, delete the appointments and tests or the account data. These health files are never deleted automatically due to plan expiration (section 9).
3.19 Nutrition (food diary)
The food diary is optional. If you use it, we process:
- Meals: dish name, portions, calories, carbohydrates, protein and fat, health rating, ingredients with grams, time and source of the entry; favorite dishes.
- Nutrition profile and goals: sex, date of birth, height, weight, activity level, objective (lose, maintain or gain weight), calorie and macro goals, meals and reminder times. They are used only to calculate your goal and reminders.
- Photo thumbnail: if you save a meal logged by photo, we store only a thumbnail (at most 24 KB) in your entry; the original photo is not stored by the server.
- Water, workouts and calories burned: the diary reads existing hydration, workout and health records for the calorie ring, without duplicating them.
- Monthly AI analysis counter: only your identifier, the number of analyses for the month and the date, to apply the plan limit.
Photo or text analysis (AI): the analysis is triggered only by you and is available on paid plans. The image is downsized and re-encoded on the device, without metadata (no EXIF or location), and sent to our server (Firebase Cloud Functions, São Paulo region) and, from there, to Google (Vertex AI / Gemini), which returns the dish name, the items, an estimate of calories and macros, and a rating. The image is not stored by the server or recorded in logs: it exists only during processing; technical records keep only counts and error codes. The AI is instructed not to identify people or read personal data from the image, but, if the photo shows faces, labels or documents, they are part of the image sent: frame only the dish. You review and can edit everything before saving. Requests made by text in the chat or on WhatsApp ("I ate...") record an estimate made by the AI, which you can delete in the diary.
Estimates, not advice: calories and macros are estimates (from the AI or from tables), may differ from actual values and do not replace a nutritionist or physician. Theros does not prescribe diets and does not make diagnoses.
Retention and deletion: the numerical diary entry is kept for as long as the account exists or until you delete it. Thumbnails expire automatically: 90 days on the Essential plan, 365 days on Pro and 730 days on Premium; the numerical meal entry remains. You can delete a meal (and its thumbnail) whenever you wish. "Clear Data" and "Delete Account" delete the diary, thumbnails, favorites and goals. The food diary is not shared with your family or with third parties.
3.20 Ideas, canvases and attachments
Ideas, notes, canvases (free-form boards with cards, connections and images) and their attachments are your content and are private: they are kept in your account and only you can access them, unless you choose to share them (section 7). The images and files you place on a canvas or attach to an idea are kept in your storage on Firebase Storage (São Paulo region) and count toward your plan's quota.
AI triggered by you: when you use AI assistance on an idea, note or canvas (for example, to generate, expand, summarize or ask), the text of the selected card or note is sent to Google Gemini to generate the response. This text is treated as data to be analyzed, never as an instruction. The AI is only triggered when you ask, and usage consumes your plan's AI quota. Processing follows the safeguards described in section 5.
Retention and deletion: until you delete the idea, card, canvas or attachment, or delete your account. Images and PDFs may be removed due to storage limits only under the conditions of section 9 (expired paid plan); text and app data are never deleted automatically.
4. Connected Services (Optional)
The integrations below are entirely optional and are only activated with your explicit authorization.
4.1 Google Calendar
- Scope:
calendar (reading and writing events).
- Data accessed: your calendar events.
- Purpose: to sync calendar events with the app.
- Storage: events are synced and stored in Firestore for display in the app.
- Revocation: you can disconnect at any time in the app settings.
4.2 Gmail
IMPORTANT NOTICE — Limited Use of Gmail Data
Theros's use of data received from Gmail APIs complies with the Google API Services User Data Policy, including the Limited Use requirements (Limited Use). This means that:
- Theros only accesses Gmail data when you explicitly authorize the connection.
- Gmail data is used exclusively to provide the features described below and visible to you in the app.
- Theros does not transfer Gmail data to third parties, except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger/acquisition/sale of assets with prior notice.
- Theros does not use Gmail data to serve ads, including retargeting, personalized or interest-based ads.
- No human reads your Gmail data, except with your explicit affirmative consent, for security purposes (investigating abuse or illegal activity), to comply with applicable law, or when the data is aggregated and anonymized for internal operations.
Scopes used:
gmail.readonly — reading e-mails (read-only).
gmail.send — sending e-mails through the app.
gmail.labels — managing Gmail labels.
Gmail features in Theros:
| Feature |
Data accessed |
What is stored |
What is NOT stored |
| Reading e-mails (Inbox) |
Subject, sender, date, body, labels |
Nothing. E-mails are loaded on demand and displayed in real time. When you leave the screen, the data is discarded from memory. |
E-mail body, attachments, full metadata |
| Detection of financial transactions |
E-mails from banks (Nubank, Inter, Itau, Bradesco, C6, PicPay, Mercado Pago, PayPal) |
Only extracted metadata: amount, merchant, date and provider of the transaction. |
Full e-mail body, attachments, data from other senders |
| Sending e-mails |
Recipient(s), subject, body of the e-mail you compose |
Audit record in Firestore (recipient, subject, body, date sent) for your personal history of sent e-mails. |
N/A |
| Label management |
List of Gmail labels |
Nothing. Labels are displayed in real time. |
N/A |
Processing of Gmail data:
- All e-mail processing takes place on the user's device (client-side). No Gmail data is sent to our servers (Cloud Functions).
- E-mail content is not sent to artificial intelligence (Google Gemini) or to any other third-party service.
- Transaction detection uses regular expressions (regex) processed locally on the device to extract monetary amounts and merchant names.
- Gmail access is completely optional. The app works fully without the Gmail integration.
Revocation and deletion:
- You can disconnect Gmail at any time in the app settings (Settings > Gmail).
- When you disconnect, OAuth authentication tokens are invalidated immediately.
- You can also revoke access directly at myaccount.google.com/permissions.
- Transactions previously detected from e-mails remain in your profile until you delete them manually or delete your account.
- When you delete your account, all e-mail transactions and the history of sent e-mails are permanently removed.
4.3 Amazon Alexa ("Meu Theros" skill)
Theros offers an official Alexa skill that lets you control the app with voice commands on Echo devices or through the Alexa app.
What we collect when you link the skill:
- Anonymous Amazon user identifier (amazonUserId): an opaque identifier provided by Amazon that allows us to associate voice commands with your Theros profile. It does not contain your name, e-mail or phone number.
- Echo device identifier (deviceId): an opaque identifier of the device. Used only for telemetry and diagnostics.
- Transcribed text of the voice command: Amazon transcribes your speech into text before sending it to Theros. We receive only the transcribed text (never the raw audio).
- Command result: what you asked for (e.g., "log an expense of 50 reais") and what we responded.
What we use this data for:
- Performing the requested action (logging a transaction, creating a task, checking a balance, etc.).
- Personalizing the response using data from your Theros account (name, custom categories, recent transactions).
- Diagnosing errors and improving voice command recognition (telemetry stored in the alexa_interactions collection).
What we do NOT collect via Alexa:
- Raw audio (Amazon transcribes your speech on its own servers and sends only the text to Theros).
- Conversations you have with Alexa outside the "Meu Theros" skill.
- Data from other devices or skills in your Amazon account.
Account Linking:
- Linking uses OAuth 2.0 with a 6-digit pairing code generated within the Theros app.
- After linking, we generate a JWT token containing only your Theros identifier, valid for 30 days and renewed automatically.
- We do not store or have access to Amazon credentials (login/password).
How to revoke:
- In the Alexa app on your phone: More → Skills & Games → Your Skills → Meu Theros → Disable Skill. The link is removed immediately and your token is no longer valid.
- You can relink at any time through the same pairing flow.
- When you delete your Theros account, the Alexa link is revoked automatically.
Limits by plan: direct commands (log an expense, check balance, list tasks, etc.) are available on all plans. Open-ended questions answered by artificial intelligence via Alexa are available starting with the Essential plan and are subject to your plan's monthly token limit.
4.4 Calendar by link (ICS, read-only)
- What it is: you can subscribe to a calendar from Outlook, Apple (iCloud), Google, Proton or another service by pasting the secret address of the .ics file (or webcal://). We do not ask for your login or password for these services.
- Data accessed: for each event, only the title, start and end, location and description (truncated at 500 characters). We do not read attendees, organizer, attachments or the other fields of the file. Events marked as private or confidential at the source are imported with only the title and time.
- Purpose: to show these events in the Theros calendar and include them in reminders. Theros only reads: nothing is sent back to your source calendar.
- How it works: our servers download the file when you add the calendar or tap sync and, on plans with automatic updates, every 3 hours. We import from 7 days in the past up to 90 days ahead, up to 3 calendars per account. The source service receives an HTTP request from a Google Cloud server, identified as "Theros-Calendar-Subscription", with no data about you other than the address itself.
- Address security: the address works like a password (anyone who has it can read the calendar). We store the address only in encrypted form (AES-256-GCM), in an area of the database inaccessible to the app, and we never display it back. We only accept https addresses and we block access to internal networks.
- Third-party data: titles and descriptions may mention other people. Subscribe only to calendars you have the right to read. Imported events receive the same treatment as the other events in your calendar, including reminders (push and, if turned on, WhatsApp) and use by the AI assistant (section 5.2).
- Retention and revocation: events are kept until you remove the subscription or delete your account, and cease to exist in Theros if they disappear from the source calendar. In Calendar > Sync > Subscribe to a calendar by link, removing the subscription immediately deletes the encrypted address and the imported events. To also end access at the source, disable or generate a new address in Outlook, Apple or Google. "Clear Data" keeps the subscription and deletes the imported events, which come back at the next update.
4.5 Telegram (Theros bot)
This channel will only be active after the Theros bot is published on Telegram; until then, no data is processed through it.
- What it is: an optional channel to talk to Theros through Telegram, as on WhatsApp. You link your account in the app (Profile > Integrations > Telegram) with a single-use code, valid for 10 minutes, and send /start and the code to the bot. The bot only chats in private chats and does not start conversations: it only responds to what you send (and confirms in the chat the unlinking that you yourself request). Available on the Pro and Premium plans.
- Data we process: your Telegram chat identifier and, if any, your @username; the date of linking and the status (active or blocked); the text of messages and captions and the photos of receipts you send; and a short conversation history to give context to the responses. We do not collect your Telegram phone number, name, profile photo or contacts. We do not process audio, documents, locations or contacts sent to the bot.
- Purpose: to carry out what you ask (log expenses, create tasks, check balance, etc.) and respond. Messages go through the same AI and the same functions as the app chat and WhatsApp (section 5), with the same plan limits. Photos are sent to the AI only to read the amounts and are not stored by us.
- Who processes it, and no end-to-end encryption: Telegram delivers the messages between you and our bot, on servers that may be located outside Brazil (sections 7 and 12). Conversations with Telegram bots do not use end-to-end encryption. Do not send passwords or data you do not want to share with Telegram. Retention on Telegram follows its own policy, which we do not control.
- Third-party messages: forwarded messages and text within photos are treated only as data to be analyzed, never as instructions. Forward only what you have the right to share.
- Retention: the conversation history with the bot is kept for up to 30 days and is deleted when you unlink; the link is kept until you unlink, use "Clear Data" or delete your account. AI memory is not used in this channel.
- How to revoke: in Profile > Integrations > Telegram > Unlink, or by sending /stop to the bot. This deletes the link and the conversation history on our servers; the history in your Telegram app remains with you, and you can delete it there.
4.6 Public API and webhooks
On the Pro and Premium plans you can create API keys and webhook endpoints (Profile > Integrations > API and webhooks) to connect Theros to tools such as Make, n8n, Zapier, spreadsheets and scripts.
- Keys: the key is shown only once; we store only a digest (SHA-256 hash) of it, the creation date, the chosen validity period and the last use. Anyone who has the key can access, according to its permissions, your entries and tasks: keep it like a password. Revoking the key stops new access.
- Webhooks: you provide a URL; when the chosen event occurs, our server sends the event data (for example, an entry or task) to that URL. The URL and the service that receives it are chosen and controlled by you: Theros does not control what that destination does with the data. The webhook signing secret is stored encrypted.
- Logs: we keep a log of webhook deliveries (event type, attempts, HTTP code and error; at most 200 characters of the response received) for 14 days, and an audit trail of actions on keys and webhooks (what was done and when) for 180 days, deleted automatically after that.
- Deletion: this data is kept in areas of the database that the app neither reads nor writes directly and is removed when you delete your account.
4.7 Automation rules
"When X happens, do Y" rules are optional and created by you in the app or through the chat. Currently, the triggers are the creation of an entry (with conditions such as type, amount range, category and description text) and an overdue task, and the actions are sending a notification or creating a task. We store the rule (name, conditions, action, status, how many times it fired and when) and, for 14 days, a technical execution record used to avoid repeated firings. The number of rules and of firings per day depends on the plan. Rules do not create or change entries. You can turn off or delete a rule at any time; rules are removed when you delete your account.
5. Artificial Intelligence
5.0 Your permission for AI
Before your first use of an AI feature (chat, voice, WhatsApp and other features), the app shows what data is sent, to whom and for what purpose, and asks for your permission. There are two separate choices:
- Google (Gemini): required for the AI features. Google processes the data on our behalf (sections 5.2 and 5.3).
- Other AI providers (optional, off by default): allows ordinary text messages to also be processed by other providers, such as Anthropic (Claude) and DeepSeek, through OpenRouter (United States), to reduce cost and response time (section 5.9). Health data, documents and photos never go through this route.
We store in your account your choice, the date and the version of the text you saw, to evidence consent (LGPD, Art. 8, §2). You can view and change both choices at any time in Settings > Privacy > AI providers; revocation applies to subsequent requests, at no cost, and does not delete your app data (section 8). If we change the text or the list of providers in a material way, we will ask for your permission again. If you do not grant permission, the AI features remain turned off and the rest of the app keeps working; on WhatsApp, Theros may reply with a link to grant permission in the app.
5.1 Models and processing
Theros uses Google Gemini to process:
- Chat messages (text).
- Voice commands (transcribed text).
- Voice chat (the audio is transcribed by Google Cloud Speech-to-Text; the transcribed text is processed as a chat message; the response is spoken by Google Cloud Text-to-Speech). In the default Google configuration we use, these two services do not log the audio, the transcriptions or the synthesized text.
- Financial insights and analyses.
- OCR processing (reading receipts and invoices).
- Tagging of Closet items from images (only with your consent; section 5.7).
- Reading a medical prescription from a photo (only with your consent; section 5.8).
- Analysis of a meal photo or description, when you trigger the feature (section 3.19).
- AI assistance on ideas, notes and canvases, when you trigger it (section 3.20).
- AI memories (phrases you asked Theros to remember), sent together with the context in chat and WhatsApp conversations (section 3.4).
- Scheduled agents (periodic automatic analyses).
5.2 Data sent to Google Gemini
To provide contextualized responses, Theros sends Google Gemini a summary of your financial profile containing:
- Recent conversation history (summarized).
- Profile data (only your first name, to address you in responses) and a financial summary of the month (total income, expenses and balance).
- Recent transactions, budgets, goals and investments in summarized form.
- Pending tasks and upcoming calendar events (including those imported from calendars by link).
- AI memories you asked Theros to store: up to 30 of them, or the 12 most related to your message when there are more than 30. They are not sent if you turn off "Use memories". At this time they are not used in Alexa, the daily summary, the proactive check-in, scheduled agents, automations or Telegram.
- Messages sent through Telegram and photos of receipts sent through that channel, when you use it.
- When you talk about appointments or medical tests: a short summary (date, time, specialty, person and names of pending tests). The diagnosis, instructions and notes from the record are not automatically included in the context: they only appear if you ask to list a completed appointment (section 3.18).
- The user's prompt or question.
This data is assembled automatically by the server from the information already recorded in the app and sent exclusively to generate the requested response. This transmission only takes place after your permission (section 5.0).
Data without direct account identifiers. The context the server assembles for the AI does not include your e-mail, phone number, CPF or CNPJ, your account's internal identifier, your full name or access tokens: we send at most your first name. This reduces, but does not eliminate, identifiability: what you write in messages and what you record in the app (for example, transaction descriptions, task titles, names of contacts you registered or mentioned) may contain personal data and is sent to generate the response. For this reason we treat this transmission as processing of personal data, with the protections of this section, and not as anonymized data.
5.3 AI safeguards
- We do not train models: your data is not used to train, improve or fine-tune AI models. This rule applies to Google and to any other provider you allow (section 5.9).
- Processing to generate the response: data is sent to the AI provider only to generate the response. We do not store the content at the provider for other purposes; the provider may temporarily retain the data for security and abuse prevention, or in memory to speed up responses, under the terms it publishes (for Google Cloud Vertex AI, the product documentation). We do not promise absolute zero retention at Google.
- Caching and web search: Google Cloud Vertex AI may keep an in-memory cache of requests for up to 24 hours. When the AI uses Google search (Google Search) to bring in current information, Google stores the request and the result for up to 3 days for debugging purposes, and this storage cannot be disabled by Theros.
- Where processing takes place: we use Google's global endpoint, which may process the request in any Google Cloud region, including outside Brazil (section 12). We do not guarantee that the AI processes data only in Brazil.
- Provider privacy: the use of Google Gemini is subject to the Google Gemini API Privacy Policy.
5.4 Scheduled agents
- Scheduled agents run prompts defined by you at periodic intervals (daily, weekly, monthly).
- When configured with "web search", Google Gemini may use Google Search (grounding) to supplement the response with information from the internet.
- The generated results are stored in Firestore and may be sent as a push notification.
5.5 Proactive financial check-in
For Premium plan users, Theros runs daily (at 09:00 Brasilia time) an automatic analysis that:
- Collects aggregated data from your budgets, goals, and spending for the previous day and the month.
- Sends this aggregated data (not individual transactions) to Google Gemini to generate a motivational summary and financial alerts.
- Stores the result in Firestore and sends a push notification with a summary.
You can turn off this feature by changing your plan or by contacting support.
5.6 Cloud OCR processing
In addition to local text recognition (Google ML Kit), Theros uses Google Gemini for intelligent data extraction from financial documents:
- Images of receipts, invoices and statements are sent to Google Gemini for structured extraction (total amount, items, dates, merchant, suggested categories).
- The images are stored in Firebase Storage linked to your account.
- The extracted data is saved in Firestore for history and creation of transactions.
- A push notification is sent when processing is complete.
5.7 Closet AI tagging
In the Closet, Theros can automatically suggest the tags for an item (type, material, pattern, occasion, season, formality and whether it is waterproof) from its image. This feature is optional, depends on your explicit consent and is only activated after you allow it and state that you are 18 years of age or older.
- What is sent: only the image of the item (the cut-out image or, if you chose to use the photo without cutout, the downsized photo), reduced to at most 512 pixels per side, in JPEG and without metadata (no EXIF or location). We do not send your name, e-mail, account identifier, location or other app information.
- Who processes it: Google, through Google Cloud Vertex AI (Gemini models), on our behalf. According to the service documentation, Google does not use customer data to train or fine-tune models without the customer's (Theros's) prior permission, and requests may be logged temporarily for abuse detection (Vertex AI data governance). This section supplements section 5.3 for Closet images.
- What we keep: we do not store the image sent to Google beyond the cut-out file already in your account, nor the response beyond the tags returned to your device. We keep only the AI consumption (number of tokens) to control your plan's quota.
- Usage limits: AI tagging consumes your plan's monthly AI quota, the same quota as Theros's other AI functions. On the Free plan there are 10 AI taggings for you to try; when the quota runs out, the Closet keeps working and you fill in the tags manually. We also limit the frequency of requests (per minute, hour and day) to prevent abuse.
- Assisted decision: tags are only suggestions. You always confirm or edit before saving; the AI does not put together outfits or make decisions about you.
- Revocation: you can turn off AI tagging at any time in Closet settings. From then on, no new image is sent and you fill in the tags manually. Without your consent, the Closet keeps working with manual tags.
5.8 AI reading of medical prescriptions
In the medication log, Theros can read a prescription from a photo and suggest the medications for you to review. This feature is optional, depends on your explicit consent, requested before first use (LGPD Art. 11, II, a), and only sends something when you take or choose a photo.
- What is sent: only the photo of the prescription, downsized and compressed on the device itself (JPEG, at most 1600 pixels per side), to our servers (Firebase Cloud Functions, São Paulo region) and, from them, to Google Gemini, on our behalf. We do not send your name, e-mail, account identifier, location or other app data. The request made to the model instructs it to ignore the name of the patient, the physician, CRM, CPF and address, and Theros does not record this data; however, if the photo shows it, it is part of the image sent. We therefore recommend framing only the list of medications.
- What we keep: we do not store the photo (neither in Firebase Storage nor in Firestore) and we do not keep the response on the server: it is returned to your device. Medications are only recorded in your account after you review and confirm them. In technical records we keep only counts and error codes, never the image, the text of the prescription or medication names. We also keep the AI consumption (number of tokens) to control your plan's quota.
- Who processes it: Google, through Google Cloud Vertex AI (Gemini models), on our behalf; prescription reading never uses the free Gemini API key. According to the service documentation, Google does not use customer data to train or fine-tune models without the customer's (Theros's) prior permission, and requests may be logged temporarily for abuse detection (Vertex AI data governance). This section supplements section 5.3 for the prescription photo.
- Usage limits: prescription reading is available on the Pro and Premium plans and consumes your plan's monthly AI quota, the same quota as Theros's other AI functions. Without the plan, or when the quota runs out, manual medication entry keeps working normally.
- Assisted decision: the reading may be wrong (name, dose, interval or duration). For this reason nothing is saved automatically: you review and edit each item before importing, and "as needed" medications do not become reminders. The AI does not give treatment advice or make decisions about you.
- Without consent: the medication log and reminders work normally, filled in manually.
5.9 Other AI providers and web search
Theros's main AI provider is Google Cloud Vertex AI (Gemini models). Only if you turn on the "Other AI providers" option (section 5.0; off by default), Theros may also use other AI models, such as Claude (Anthropic) and DeepSeek, through OpenRouter (OpenRouter, Inc., United States), an intermediary that routes the request to the chosen model, or partner models offered within Google Cloud. Without this option, all AI processing involving your data stays with Google, except for the third-party web search described below. Requests that contain no data of yours (for example, the summary of the public transcript of a YouTube video when you do not write any instruction) may use these providers without the option. The rules below apply to any provider:
- No direct identifiers: we apply what is described in section 5.2 (no e-mail, phone number, CPF/CNPJ, account identifier or full name). The text you write is still sent and may contain personal data.
- Sensitive data stays with Google: messages and data concerning health, appointments, medications, nutrition, workouts, documents and photos (including receipts, prescriptions and meals) and detailed financial data are processed only by Google Cloud Vertex AI. Additional providers receive only general text conversations that do not involve this data.
- Zero retention required and no training: in each request to OpenRouter, we require that the model be served by an endpoint that declares it does not store the content (zero data retention). OpenRouter states that it does not keep the text of requests and responses by default (it keeps only metadata such as token count and response time) and does not use the content to train models. Providers that do not offer these conditions or that store data in China are not used for user data.
- Third-party web search: when a question requires current information from the internet and the monthly limit for Google search has been reached, the query may be sent to a third-party search service (currently Exa, through OpenRouter). We send only the shortened question (up to 300 characters), without history, memories or account context, and we do not send queries containing CPF, CNPJ, e-mail, phone number, card, health or personal finance information. This service has its own policy and may use the queries to improve its products; zero retention does not apply to it.
- Transparency: we keep this list up to date and give notice of material changes in accordance with section 14.
5.10 Rating AI responses (like and dislike)
You can rate AI responses in the app and, in some conversations, via WhatsApp. We store your rating (positive or negative), the reasons chosen, an optional comment of up to 300 characters and technical data about the rated response (model used, function type, plan, language and response time). The text of your message and of the response is only stored if you check the option to send it for review (excerpts of up to 300 and 500 characters). We use this data only to measure and improve the quality of the AI; access is restricted to Theros administration, it is not sent to AI providers or used for advertising, and it is deleted within 12 months or when you delete your account.
5.11 Installation identifier (abuse prevention)
To prevent the same device from receiving promotional benefits (trial period and referral rewards) more than once, the app generates a random code specific to the installation, which is not derived from device characteristics and is not used for advertising or cross-app tracking. Only an irreversible digest (SHA-256 hash) of this code leaves the device, and the original code cannot be recovered from it; in the anti-abuse record we keep only a second hash of that digest, computed with a secret key of ours (HMAC), which remains after account deletion to prevent reuse of the benefit. The legal basis is legitimate interest in fraud prevention (LGPD, art. 7, IX). If you believe you were blocked by mistake, contact support.
6. Storage and Security
6.1 Infrastructure
- Google Cloud Firestore: your data is stored in the
southamerica-east1 region (São Paulo, Brazil), with security rules ensuring that only you can access your own data.
- Firebase Storage: files you upload (such as images of receipts, attachments and Closet images) are stored in the
southamerica-east1 region (São Paulo, Brazil), with per-user access security rules.
- Firebase Cloud Functions: server-side processing executed in the same region (
southamerica-east1).
- Local storage: AI usage metrics and the offline sync queue are stored locally on the device using Hive (a local database).
6.2 Security measures
- Encryption in transit: all communications between the app and the servers are protected by HTTPS/TLS.
- Authentication: Firebase Authentication with support for e-mail/password and Google Sign-In. The authentication method used is recorded for account security purposes.
- Local security: 6-digit PIN to protect access to the app on the device.
- Firestore security rules: per-user data isolation — each user can only access their own documents.
- Calendar-by-link (ICS) addresses, webhook secrets and API keys: calendar addresses and webhook secrets are encrypted (AES-256-GCM) with a dedicated key kept in Secret Manager; API keys are stored only as hashes; none of this is returned to the app.
- OAuth2 tokens: Gmail and Calendar access credentials managed by the Google Sign-In SDK with the operating system's native secure storage.
7. Sharing Data with Third Parties
We do not sell, rent or share your personal data with third parties for marketing, advertising or any other commercial purpose.
Your data may be processed by the following service providers, strictly to enable the app's features:
| Provider |
Data processed |
Purpose |
| Google Cloud / Firebase |
All app data (financial, personal, health, tasks, ideas, settings, OCR images, Closet images and attachments) |
Backend infrastructure, authentication, storage, notifications, processing |
| Google Gemini API / Google Cloud Vertex AI (Gemini) |
Chat messages, summarized financial context, voice audio, images of receipts, images of Closet items (downsized and without metadata, only with your consent), prescription photo, meal photo or description, text of ideas and notes when you trigger the AI, summary of appointments and medical tests, AI memories |
Artificial intelligence (responses, insights, OCR, agents, Closet item tagging, prescription reading, meal analysis, assistance with ideas and canvases) |
| Google APIs (Gmail, Calendar, Speech) |
E-mails and events (when authorized, processed on the device), voice command audio |
Optional integrations and speech-to-text conversion |
| WeatherAPI.com |
Approximate position (area of about 11 km) or city name, sent by our server, without user identification |
Weather forecast (Weather card and page, chat and Closet). Weather data by WeatherAPI.com |
| MET Norway (Norwegian Meteorological Institute) |
Approximate position (area of about 11 km), sent by our server, without user identification |
Weather forecast (fallback provider and later days of the forecast). Based on data from MET Norway (CC BY 4.0) |
| OpenStreetMap (Nominatim) |
City name (sent by our server, when WeatherAPI.com is unavailable) and coordinate rounded to about 11 km (sent by the app itself, in the web version and as an alternative in the mobile apps; in that case the service receives the device's IP address) |
Geocoding: from city name to coordinates and from coordinates to city name. © OpenStreetMap contributors |
| Open-Meteo (earlier versions of the app only) |
GPS coordinate or city name, sent directly by the device (the service receives the device's IP address) |
Weather forecast, until the app is updated (section 3.6) |
| RevenueCat |
User ID, subscription status |
Management of subscriptions and plans |
| Amazon Alexa ("Meu Theros" skill) |
Anonymous Amazon identifier, Echo device identifier, transcribed text of voice commands |
Voice command recognition, account linking via OAuth and execution of requested actions |
| Telegram (Telegram Messenger Inc. and its group companies, such as Telegram FZ-LLC) |
Chat identifier, @username, text of messages, captions and photos of receipts exchanged with the Theros bot (optional feature, once the bot is published) |
Delivery of messages and responses to your Telegram, at your request |
| Source service of a calendar by link (Microsoft, Apple, Google, Proton or other) |
Receives the address you provided when queried by our server; does not receive any data about you |
Download of the calendar you subscribed to |
| Webhook destination (URL you choose) |
Data of the events you chose (for example, entries or tasks) |
Integration with the tool you use (Make, n8n, Zapier, scripts, etc.) |
| Meta (WhatsApp Business Platform / WhatsApp Cloud API) |
Phone number and messages exchanged with Theros through the WhatsApp channel (optional feature) and, in the Closet, the outfit image (collage of the images of your items), only with your consent |
Delivery of messages and outfit images to your WhatsApp, at your request |
7.1 Data in push notifications
Push notifications sent by Theros may contain summarized financial data for your convenience:
- OCR completed: merchant name and total amount extracted.
- Financial check-in: summary of budget alerts and goal progress.
- Scheduled agents: title and preview of the generated result.
- Health: medication reminders include the name, dosage and time (section 3.16); an appointment notice shows, by default, only the time (section 3.18).
- Events from calendars by link: the event title appears in the reminder notice.
This information is visible on the device's notification screen. For greater privacy, you can disable specific notifications in your operating system settings.
In addition to the providers above, your data may be shared in the following circumstances:
- Voluntary sharing: you may choose to share tasks or Kanban boards with other Theros users. In this case, only the data you choose to share will be accessible to the recipient.
- Legal obligation: when required by Brazilian law, regulation or court order.
7.2 Access by administrators and staff
As with any cloud service, the data stored in your account can technically be accessed by those who administer Theros. Currently, the database security rules allow authenticated administrators of the internal dashboard to read the documents in your user collections (for example, profile, subscription, tasks, health records and AI memories), except for server-only areas (API keys, webhooks and the integrations audit trail), which no app or dashboard reads. Anyone with access to the project's Google Cloud console can also technically access the storage. We use this access for support you requested, security and abuse investigation, compliance with legal obligations and operation of the service, and not to read the content of your records in normal use.
8. Your Rights (LGPD)
In accordance with the Lei Geral de Proteção de Dados (Law 13.709/2018), you have the following rights:
- Confirmation and access (Art. 18, I and II): view all of your stored data directly in the app.
- Correction (Art. 18, III): edit your personal and financial data at any time in the app (including AI memories, in Profile > AI Assistant > Theros Memories). For data of a person you track (section 3.18), that person may submit a request for correction, access or deletion through the account holder or via the e-mail in section 15.
- Anonymization, blocking or deletion of unnecessary data (Art. 18, IV): request by e-mail.
- Portability (Art. 18, V): export your financial data in JSON format (full backup) or PDF (reports). Before any deletion of files due to plan expiration (section 9), you can download your data. Export of health records (appointments, medical tests, people and nutrition) is not yet complete in the app; until it is, request it via the e-mail in section 15.
- Deletion of data (Art. 18, VI): delete your account and all associated data through the "Delete Account" option in the app (Profile > Settings). Deletion is permanent and irreversible.
- Information about sharing (Art. 18, VII): all third parties with whom we share data are listed in Section 7 of this policy.
- Revocation of consent (Art. 18, IX): disconnect Google Calendar and Gmail at any time in the app settings; disable location in the device settings; turn off AI tagging, the use of location and the sending of outfit photos via WhatsApp for the Closet in Closet settings; turn off workout import and the notice on arriving at the gym in Workout > Settings; turn off the use of AI memories, delete a memory or delete all of them; remove a calendar-by-link subscription, revoke API keys and delete webhooks; unlink Telegram in the app (or with /stop in the bot); delete health records, meals and thumbnails; and stop using any AI feature triggered by you.
- Revoke permission for AI (Art. 8, §5, and Art. 18, IX): in Settings > Privacy > AI providers, turn off "Google (Gemini)" (turns off all AI features) or "Other AI providers" (everything goes back to Google, with no loss of features). The change takes effect within moments for new requests.
To exercise any right not available directly in the app, contact us at rafaelfurlan@lunanexgen.com. We will respond within 15 business days.
9. Data Retention
| Type of data |
Retention |
| Financial data, tasks, notes, chat history, voice commands, agents and OCR |
While the account is active, or until manual deletion |
| AI memories (phrases you asked Theros to remember) and the preference for using memories |
While the account is active or until you delete the memory, delete all of them or delete your account. Deletion takes effect immediately; chat history is controlled separately |
| Appointments, medical tests, people you track and health attachments |
While the account is active or until you delete them. Never deleted automatically due to plan expiration |
| Food diary (meals, favorites, goals) |
While the account is active or until you delete it |
| Meal photo thumbnails |
Expire automatically: 90 days (Essential), 365 days (Pro) or 730 days (Premium); after a paid plan expires, 30 days (section 9, expiring plan). The numerical meal entry remains. You can delete them earlier |
| Meal photo sent for analysis |
Not stored or logged: processed only during the analysis |
| Ideas, notes, canvases and attachments |
While the account is active or until you delete them. Images and PDFs are also subject to the expired-plan storage rule (below); text is never deleted automatically |
| Calendar by link (encrypted address and imported events) |
Until you remove the subscription or delete your account; "Clear Data" keeps the subscription and deletes the imported events |
| Telegram link and conversation history with the bot |
Link: until you unlink, use "Clear Data" or delete your account. History: up to 30 days, or until you unlink. Photos of receipts sent through Telegram are not stored by us. On Telegram, retention follows its own policy, which we do not control |
| API keys (hash) and webhook endpoints |
Until you revoke or delete them, or delete your account |
| Webhook delivery log |
14 days (deleted automatically) |
| Audit trail of keys and webhooks |
180 days (deleted automatically) |
| Automation rules and technical execution record |
Rules: until you delete them or delete your account. Execution record: 14 days (deleted automatically) |
| WhatsApp channel messages |
90 days (automatic daily cleanup) |
| Technical error logs (without the content of your messages, images or records) |
90 days (deleted automatically) |
| Medications and dose log |
While the account is active, or until manual deletion of the medication |
| Prescription photo sent for reading |
Not stored: processed only during the reading |
| AI usage metrics (local) |
90 days (automatic cleanup) |
| Voice chat sessions |
Only metadata (duration, date) while the account is active |
| Gmail data |
E-mails: not stored. Detected transactions: while the account is active |
| Device data and login method |
Overwritten at each session (only the most recent record is kept). Removed when the account is deleted |
| Digital Closet (cut-out images and thumbnails, tags, outfits, usage history, preferences and consents) |
While the account is active or until you delete the item, clear the closet (Closet settings) or delete your account. The original photo is not kept when automatic cutout works |
| Outfit images sent via WhatsApp (only with your consent) |
Not kept by us after sending. In your WhatsApp conversation and in Meta's systems, retention follows WhatsApp/Meta's terms and privacy policy, which we do not control. The Closet conversation state on WhatsApp and the daily counter are kept in your account and are deleted with the closet, with "Clear Data" and with account deletion |
| Workout (workout plans, completed and imported workouts, custom exercises, body weight, check-ins, preferences) |
While the account is active or until you delete the workout or the workout plan, or delete your account |
| Exported backups |
Local files on your device (under your control) |
Account deletion: when you delete your account, we permanently remove from our servers: all subcollections of your user in Firestore (including those of the Closet, AI memories, health records and the food diary), the main documents in root collections linked to your ID (for example, salary history, custom categories, shares, feedback, referrals, support conversations, records of taps on in-app notices, survey responses, voice commands, Alexa interactions, invitations and shared public profiles), all files you uploaded to Firebase Storage (including Closet images) and your authentication account in Firebase Auth. We retain, for the period required by law or for audit purposes, records of subscription transactions and administrative support trails. Data held by third-party providers (for example, RevenueCat, app stores and analytics services) is subject to those providers' policies.
Clear Data (without deleting the account): the "Clear Data" option deletes the data recorded in the app (Firestore documents, including those of the Closet), while keeping your account, plan, account preferences, connections to external services (such as Gmail and calendars; the Telegram link is undone and events imported from calendars by link are deleted), notification tokens and plan usage counters. Among the files in Firebase Storage, this option deletes only the Closet images; files from other features (such as images of receipts and attachments) remain until you delete them or delete your account.
Expiring paid plan: storage and files
If a paid plan expires or is canceled, nothing is deleted for 30 days (grace period), and, while your storage is above the Free plan quota, you receive in-app and push notifications on days 0, 7, 21 and 28, and a last notice on day 84, six days before any cleanup. After that:
- if your storage exceeds the Free plan quota, new file uploads are blocked (frozen) and meal photo thumbnails begin to expire after 30 days;
- from day 90 onwards, files (images and PDFs) exceeding the Free plan quota are removed automatically, from oldest to newest, until they fit within the quota, but only if the notifications for days 0, 21 and 28 were delivered to your device (if we cannot deliver them, for example because notifications are turned off, no file is deleted); if, even after removing everything that can be removed, usage would still be above the quota, nothing is deleted;
- we never automatically delete text, app data, health documents, your avatar or items you have marked as "keep" (in Storage, "Keep files forever"; they still count toward the quota);
- you can export your data and save your files before any removal;
- renewing the plan cancels the process.
Closet: in Closet settings you can clear the entire closet (records and images) without deleting your account, and delete items individually.
10. Offline Processing
Theros has offline functionality. When you are not connected to the internet:
- Your financial data is accessible locally through the Firestore cache.
- Operations performed offline are stored in a local sync queue and sent automatically when the connection is restored.
- Basic natural language processing for voice commands may work locally without sending data to servers.
11. Cookies and Tracking
Mobile app (iOS/Android): does not use browser cookies. We collect only technical device metadata (model, operating system, app version) for diagnostics and service improvement.
Corporate website (therosapp.com) and web version (app.therosapp.com): we use:
- TikTok Pixel (only on the therosapp.com landing page): measures the effectiveness of advertising campaigns and conversion attribution (download/sign-up). Data may be transferred to TikTok Inc. servers in the United States. You can block the pixel by disabling third-party cookies in your browser, or with Privacy Badger or a similar tool.
- Google Analytics / Firebase Analytics: aggregated usage measurement (pages visited, session time, device) for product improvement. Identifiers are not linked to personal data.
- Technical cookies / localStorage: store session preferences (login, language) and are essential for operation.
We do not display ads within the app.
12. International Data Transfer
Your data is stored primarily in the southamerica-east1 region (São Paulo, Brazil) of Google Cloud. However, some third-party services may process data on servers located outside Brazil:
- Google Gemini API and Google Cloud Vertex AI: AI processing may take place on Google servers in other regions.
- Additional AI and web search providers (for example, through OpenRouter): operate mainly in the United States and, in some cases, in other countries; they are used only under the conditions of section 5.9 and, when the request contains your data, only with your permission for "Other AI providers" (specific consent under Art. 33, VIII).
- WeatherAPI.com, MET Norway, OpenStreetMap (Nominatim) and, in earlier versions of the app, Open-Meteo: weather forecast and geocoding providers that may operate servers outside Brazil. When called by our server, they receive only an approximate position (area of about 11 km) or the name of a city, without user identification. In transmissions made directly by the device (OpenStreetMap and, in earlier versions of the app, Open-Meteo, described in section 3.6), the service also receives the device's IP address.
- Meta (WhatsApp Business Platform): messages and outfit images sent via WhatsApp pass through Meta's infrastructure, which may operate servers outside Brazil.
- Telegram: messages exchanged with the Theros bot (once the channel is active) pass through Telegram's infrastructure, which may operate servers outside Brazil. Conversations with bots do not use end-to-end encryption.
- RevenueCat: subscription management on servers in the United States.
- Amazon Alexa ("Meu Theros" skill): Amazon transcribes voice commands and manages account linking on servers in the United States. Only the transcribed text reaches our servers in São Paulo.
Each transfer is carried out under a contract with the processor and on the basis of one of the grounds of art. 33 of the LGPD, with each provider's contractual and security safeguards. We do not claim that every provider has adopted the ANPD (Brazilian National Data Protection Authority) standard contractual clauses: for providers that do not yet have a specific instrument for Brazil, we limit transmissions to general text content, without direct identifiers and without sensitive data (section 5.9), and we are working to formalize these clauses.
13. Minors
Theros is not intended for persons under 18. We do not knowingly collect data from minors. If we become aware that we have collected data from a person under 18, we will delete that data immediately. If you believe a minor has provided data to Theros, contact us at rafaelfurlan@lunanexgen.com.
To use Closet AI tagging, you must state that you are 18 years of age or older; in addition, if the date of birth entered in your profile indicates that you are under 18, the feature is not enabled and tags must be filled in manually.
Health data of children and adolescents recorded by a parent or guardian (section 3.18) is the responsibility of the account holder, who represents that they have standing to record it.
14. Changes to this Policy
We may update this Privacy Policy periodically to reflect changes in our practices, features or legal requirements. Significant changes will be communicated 15 days in advance, by in-app notification and, where possible, also by e-mail. The date of the last update will always be indicated at the top of this document. Continued use of the app after the changes constitutes acceptance of the updated policy, without prejudice to your right to revoke consents and delete your data at any time.
Summary of the latest changes (October 10, 2026): details on AI providers, retention and processing by Google (sections 5.3 and 5.9), rating of AI responses (5.10), installation identifier against abuse (5.11) and a 15-day notice period for material changes (14); permission requested before first use of AI, with a separate option, off by default, for other AI providers, which you can change in Settings > Privacy > AI providers (sections 2, 5.0, 5.2, 5.3, 5.9, 8 and 12); an exact description of the notices (days 0, 7, 21, 28 and 84) and of the automatic removal of excess files when a paid plan expires (section 9) and of the channels used to announce changes (14). Previous changes (October 6, 2026): common rules for health data, with legal basis, purpose, user control and a prohibition on advertising use (sections 2, 3.17 and 8); appointments, medical tests and people you track, with the representation of standing for data of family members and dependents (3.18); food diary with AI photo analysis, thumbnails that expire by plan and the photo not being stored (3.19 and 9); ideas, canvases and attachments (3.20); explicit AI memory and assistant tone, without sensitive data or secrets (3.4, 5.1, 5.2, 8 and 9); calendar by link (4.4), Telegram (4.5), public API and webhooks (4.6) and automation rules (4.7), with their retention periods; who can access stored data (7.2); new retention periods for technical records (section 9); rule for expiring paid plans, with a 30-day grace period and without deleting text, app data or health documents (section 9); corrected description of voice chat, which no longer uses the Gemini Live API (3.5 and 5.1). No previous commitment was withdrawn. (October 5, 2026): update of the contact e-mail and of the Data Protection Officer to rafaelfurlan@lunanexgen.com (sections 1, 8, 13 and 15); addition of the medication log with reminders, an every-X-hours schedule and an adherence map, and of optional AI reading of prescriptions from a photo, with dedicated consent (sections 3.16, 5.1, 5.8 and 9). (October 4, 2026): addition of the Workout module, with optional import of workouts from Health/Health Connect, check-in and a notice on arriving at the gym (sections 3.7, 3.15, 8 and 9); optional sending of Closet outfit images via WhatsApp, with dedicated consent and Meta as processor (sections 3.14, 7, 8, 9 and 12). (October 3, 2026): addition of the digital Closet (sections 3.14 and 5.7); description of the use of approximate position for the weather forecast and of other uses of location (section 3.6); weather forecast, geocoding and AI providers, including Open-Meteo in earlier versions of the app (sections 7 and 12); and details on data deletion, including files in storage (section 9).
15. Contact and Exercise of Rights
For questions, requests, complaints or to exercise your rights under the LGPD, contact us:
E-mail: rafaelfurlan@lunanexgen.com
Data Protection Officer (DPO): rafaelfurlan@lunanexgen.com
Response time: within 15 business days
You also have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) if you believe your rights have not been properly addressed.