THEROS

Privacy Policy

Last updated: October 10, 2026

This is a translation. In case of discrepancy, the Portuguese version prevails. Read the original in Portuguese.

Your privacy is fundamental to us. This Privacy Policy describes, transparently and in detail, what data we collect, how we use it, with whom we share it, how we protect it, and what your rights over it are in the Theros app.

What changed on October 10, 2026: we detailed which AI and search providers we use and how each one handles data (sections 5.3 and 5.9), that we also process AI data outside Brazil, the rating of AI responses (5.10), the installation identifier used against abuse (5.11), and the 15-day notice for material changes (section 14). We also now ask for your permission before your first use of AI, with a separate option, turned off by default, for other AI providers, and you can change both in Settings > Privacy > AI providers (sections 2, 5.0, 5.9, 8 and 12). Finally, we describe precisely the notices and the automatic removal of files when a paid plan expires (section 9) and how we announce changes to this policy (section 14).

What changed on October 6, 2026: this version includes rules for health data (appointments, medical tests, medications, nutrition, workouts and well-being) and for the data of family members that you record (sections 3.17 to 3.19); the food diary with AI photo analysis (3.19); ideas, canvases and attachments (3.20); AI memory and tone (3.4); calendar subscription by link, Telegram, the public API with webhooks, and automation rules (4.4 to 4.7); who can access stored data (7.2); retention periods and what happens when a paid plan expires (section 9); and the corrected description of voice chat (3.5 and 5.1). The full summary is in section 14.

1. Data Controller

The controller of your personal data is:

Theros App
Contact e-mail: rafaelfurlan@lunanexgen.com
Data Protection Officer (DPO): rafaelfurlan@lunanexgen.com

2. Legal Basis for Processing (LGPD, Art. 7)

Theros's processing of your personal data is based on the following legal bases of the Lei Geral de Proteção de Dados (LGPD, the Brazilian General Data Protection Law, Law 13.709/2018):

3. Information We Collect

3.1 Registration and profile data

Purpose: identification, authentication and personalization of the in-app experience.

3.2 Financial data

Purpose: to provide financial management features, reports, projections and personalized insights.

3.3 Task, note and list data

Purpose: personal organization and productivity.

3.4 AI communication data

Purpose: to provide contextualized responses and personalized financial insights through artificial intelligence.

Storage: chat messages and command history are stored in Firestore while your account is active.

AI memories ("remember that..."): when you explicitly ask, in the app chat or in a WhatsApp text message, that Theros remember something (for example, "remember that I'm vegetarian"), we store that phrase, up to 200 characters, together with the source of the request (chat, WhatsApp or typed by you) and the dates. We do not store memories on our own initiative, nor from documents, PDFs, e-mails, images, websites, scheduled agents, automations or audio messages. For security reasons, we do not store passwords, tokens, keys, card numbers, CPF, CNPJ (Brazilian company taxpayer ID), bank accounts or sensitive personal data (health, religion, political opinion, sex life, racial or ethnic origin, biometric data and trade union membership); detection is automatic and based on words and patterns, and is therefore not perfect: avoid writing this type of information. The number of memories depends on your plan. Memories are sent to Google Gemini together with the context in app chat and WhatsApp conversations (section 5.2), marked as your data and never as an instruction; the text of memories is not recorded in server logs.

Your control: in Profile > AI Assistant > Theros Memories you can view, edit, delete, delete all, manually add memories, and turn off the use of memories. When you delete a memory, Theros stops using it immediately; the message in which you asked for it to be stored remains in the chat history, which you control separately.

Assistant tone: your choice of tone is kept in your settings and guides the style of responses in the chat, on WhatsApp, in the morning summary, in the financial check-in and in some notifications. If you do not choose one, nothing changes.

3.5 Voice and audio data

Purpose: to enable voice interaction with the AI assistant.

3.6 Location data

Purpose: location-based reminders and automations voluntarily set up by you; weather forecast and Closet suggestions; regional targeting and performance measurement of in-app notices.

Control: you can turn off location permission at any time in your device settings. The weather forecast also works if you provide only a city and, in the Closet, you can enter the city or revoke the use of location in Closet settings.

3.7 Health and well-being data

Purpose: personal hydration tracking; calculation of your daily well-being score (activity, recovery and sleep pillars), sleep debt, trends and anomaly alerts compared only against your own history (for example, resting heart rate above your usual level or a series of poorly slept nights). Each type of data is displayed on the Health screen and used exclusively for this feature.

How we handle sensor data:

3.8 Contact data

Purpose: contact management for sending e-mails and reports. Theros does not import contacts from your phone's address book. All contacts are registered manually by you.

3.9 Settings and preference data

Purpose: personalization of the user experience.

3.10 Automatically collected data

Purpose: technical support, account security, detection of unauthorized access and improvement of the user experience.

3.11 User directory for collaboration

To enable sharing of tasks and Kanban boards, Theros provides an internal search feature by name or e-mail. When you use the app, your name, e-mail and profile photo may be visible to other Theros users who use this search feature for collaboration purposes.

3.12 Waitlist and landing page forms

When you sign up through forms on the website (waitlist, contact, beta), we collect:

3.13 Public testimonials displayed on the landing page

Testimonials displayed on the home page may include a name (or initials), star rating, review quote and date. This data is published only after your explicit consent or when it comes from reviews you have already voluntarily made public (App Store, Google Play). You may request removal at any time through the contact channels (Section 15).

3.14 Digital Closet

The Closet is an optional feature. If you use it, we process the data below.

Purpose: to organize your closet, suggest outfits according to the weather and occasion, calculate information such as cost per wear and unworn items, and allow you to export or share the image of an outfit when you ask. Outfits are put together by rules executed on your device; artificial intelligence only suggests tags for the items (section 5.7), and you always confirm or edit before saving.

Legal basis: performance of the service of storing and organizing your closet (Art. 7, V) and, for AI tagging, the use of location and sending outfit photos via WhatsApp, your consent (Art. 7, I), requested separately, never pre-checked and revocable at any time.

Retention and deletion: until you delete the item, clear the closet (Closet settings) or delete your account. Deleting an item removes its record and images; clearing the closet removes all Closet records and images; deleting the account or using "Clear Data" also removes the Closet images (section 9). The Closet conversation state on WhatsApp and the daily counter are removed together with the closet.

Outfit photos on WhatsApp (optional): if you use Theros through WhatsApp, you can ask for outfit suggestions and receive, in the conversation, the image of the outfit. This only happens after you turn on "Look photos on WhatsApp" in Closet settings, through a dedicated consent, separate from the others and never pre-checked. Without it, Theros responds with text only.

Minors: the Closet is not intended for persons under 18 (section 13).

3.15 Workout (gym and exercise)

Workout is an optional feature. If you use it, we process the data below.

Purpose: to record and track your workouts, show which muscles each exercise and each workout plan targets, calculate statistics and records, and bring into one place the workouts you already record in other apps. The weekly set ranges displayed in the app are general references, not a prescription or medical or physical education advice.

Health data: imported workouts, workout heart rate, weight and body fat are health data (sensitive personal data, LGPD Art. 11). They are only read with your explicit authorization, are never used for advertising, never sold, rented or shared with third parties, data brokers or advertising platforms, and never used for credit, insurance, employment or any other decision with legal effect on you. Workout does not use artificial intelligence: workout data is not sent to Google Gemini.

Legal basis: performance of the service of recording your workouts (Art. 7, V) and, for importing workouts and weight from other apps and for the location-based notice, your consent (Art. 7, I and Art. 11, II, a), requested separately, never pre-checked and revocable at any time.

Retention and deletion: until you delete the workout or the workout plan, or delete your account (section 9). You can turn off import in Workout > Settings > Import; from then on, Theros stops reading those sources. Workouts already imported remain in your account until you delete them.

3.16 Medications and dose reminders

The medication log is an optional feature. If you use it, we process the data below.

Purpose: to remind you to take your medications at the times you chose and show your adherence history. Theros is not a medical device, does not prescribe, does not recommend doses and does not replace the advice of a healthcare professional; reminders are a support tool, and responsibility for the use of the medication is yours.

Health data: medications and doses are health data (sensitive personal data, LGPD Art. 11). They are kept only in your personal account (never in shared accounts, such as the family account), are never used for advertising, never sold, rented or shared with third parties, data brokers or advertising platforms, and never used for credit, insurance, employment or any other decision with legal effect on you. The registered data is not sent to Google Gemini; the only exception is a prescription photo that you yourself choose to send (section 5.8).

Legal basis: performance of the service of reminding you of and recording your doses (Art. 7, V) and, for reading prescriptions from a photo, your explicit consent, requested separately before first use (Art. 11, II, a).

Retention and deletion: until you delete the medication or delete your account (section 9). When you delete a medication, its future reminders are no longer sent.

3.17 Health data: common rules

Appointments, medical tests, medications, doses, nutrition and weight, workouts, mood, hydration and the well-being score are sensitive personal data (LGPD, Art. 5, II and Art. 11). The rules below apply to all of them, in addition to the specific rules of each feature.

3.18 Appointments, medical tests and people you track

The Appointments module (Health and Well-being) is optional. If you use it, we process:

Data of family members and dependents: when recording health data of another person, you represent that you have authorization or standing to do so (for children and legally incapacitated persons, as their legal guardian), and the app asks for this confirmation before the first entry. This data is kept only in your personal space and never in the shared account. The person to whom the data relates may request access, correction or deletion through the account holder or via the e-mail in section 15. Record only what you have the right to record.

Purpose and AI: to organize appointments, medical tests, reminders and history. When you talk to the assistant about an appointment or test, a short summary may be sent to Google Gemini (section 5.2); the diagnosis, instructions and notes from the record are not included automatically, and the content is treated as data, never as an instruction. The appointment appears in the app's calendar as read-only and is not sent to Google Calendar or Apple Calendar. With one tap, you can create a task, note or financial entry (cost or reimbursement, Health category, in the personal ledger) from an appointment; these items then follow the rules of the respective features.

Notifications: by default, an appointment notice shows only the time; you can choose, for each appointment, to also display the specialty and the person.

Retention and deletion: until you delete it. "Clear Data" and "Delete Account" delete people, appointments, medical tests and attached files. Deleting a person who already has an appointment or test archives that person, so as not to lose the history; to erase the history, delete the appointments and tests or the account data. These health files are never deleted automatically due to plan expiration (section 9).

3.19 Nutrition (food diary)

The food diary is optional. If you use it, we process:

Photo or text analysis (AI): the analysis is triggered only by you and is available on paid plans. The image is downsized and re-encoded on the device, without metadata (no EXIF or location), and sent to our server (Firebase Cloud Functions, São Paulo region) and, from there, to Google (Vertex AI / Gemini), which returns the dish name, the items, an estimate of calories and macros, and a rating. The image is not stored by the server or recorded in logs: it exists only during processing; technical records keep only counts and error codes. The AI is instructed not to identify people or read personal data from the image, but, if the photo shows faces, labels or documents, they are part of the image sent: frame only the dish. You review and can edit everything before saving. Requests made by text in the chat or on WhatsApp ("I ate...") record an estimate made by the AI, which you can delete in the diary.

Estimates, not advice: calories and macros are estimates (from the AI or from tables), may differ from actual values and do not replace a nutritionist or physician. Theros does not prescribe diets and does not make diagnoses.

Retention and deletion: the numerical diary entry is kept for as long as the account exists or until you delete it. Thumbnails expire automatically: 90 days on the Essential plan, 365 days on Pro and 730 days on Premium; the numerical meal entry remains. You can delete a meal (and its thumbnail) whenever you wish. "Clear Data" and "Delete Account" delete the diary, thumbnails, favorites and goals. The food diary is not shared with your family or with third parties.

3.20 Ideas, canvases and attachments

Ideas, notes, canvases (free-form boards with cards, connections and images) and their attachments are your content and are private: they are kept in your account and only you can access them, unless you choose to share them (section 7). The images and files you place on a canvas or attach to an idea are kept in your storage on Firebase Storage (São Paulo region) and count toward your plan's quota.

AI triggered by you: when you use AI assistance on an idea, note or canvas (for example, to generate, expand, summarize or ask), the text of the selected card or note is sent to Google Gemini to generate the response. This text is treated as data to be analyzed, never as an instruction. The AI is only triggered when you ask, and usage consumes your plan's AI quota. Processing follows the safeguards described in section 5.

Retention and deletion: until you delete the idea, card, canvas or attachment, or delete your account. Images and PDFs may be removed due to storage limits only under the conditions of section 9 (expired paid plan); text and app data are never deleted automatically.

4. Connected Services (Optional)

The integrations below are entirely optional and are only activated with your explicit authorization.

4.1 Google Calendar

4.2 Gmail

IMPORTANT NOTICE — Limited Use of Gmail Data

Theros's use of data received from Gmail APIs complies with the Google API Services User Data Policy, including the Limited Use requirements (Limited Use). This means that:

Scopes used:

Gmail features in Theros:

Feature Data accessed What is stored What is NOT stored
Reading e-mails (Inbox) Subject, sender, date, body, labels Nothing. E-mails are loaded on demand and displayed in real time. When you leave the screen, the data is discarded from memory. E-mail body, attachments, full metadata
Detection of financial transactions E-mails from banks (Nubank, Inter, Itau, Bradesco, C6, PicPay, Mercado Pago, PayPal) Only extracted metadata: amount, merchant, date and provider of the transaction. Full e-mail body, attachments, data from other senders
Sending e-mails Recipient(s), subject, body of the e-mail you compose Audit record in Firestore (recipient, subject, body, date sent) for your personal history of sent e-mails. N/A
Label management List of Gmail labels Nothing. Labels are displayed in real time. N/A

Processing of Gmail data:

Revocation and deletion:

4.3 Amazon Alexa ("Meu Theros" skill)

Theros offers an official Alexa skill that lets you control the app with voice commands on Echo devices or through the Alexa app.

What we collect when you link the skill:

What we use this data for:

What we do NOT collect via Alexa:

Account Linking:

How to revoke:

Limits by plan: direct commands (log an expense, check balance, list tasks, etc.) are available on all plans. Open-ended questions answered by artificial intelligence via Alexa are available starting with the Essential plan and are subject to your plan's monthly token limit.

4.4 Calendar by link (ICS, read-only)

4.5 Telegram (Theros bot)

This channel will only be active after the Theros bot is published on Telegram; until then, no data is processed through it.

4.6 Public API and webhooks

On the Pro and Premium plans you can create API keys and webhook endpoints (Profile > Integrations > API and webhooks) to connect Theros to tools such as Make, n8n, Zapier, spreadsheets and scripts.

4.7 Automation rules

"When X happens, do Y" rules are optional and created by you in the app or through the chat. Currently, the triggers are the creation of an entry (with conditions such as type, amount range, category and description text) and an overdue task, and the actions are sending a notification or creating a task. We store the rule (name, conditions, action, status, how many times it fired and when) and, for 14 days, a technical execution record used to avoid repeated firings. The number of rules and of firings per day depends on the plan. Rules do not create or change entries. You can turn off or delete a rule at any time; rules are removed when you delete your account.

5. Artificial Intelligence

5.0 Your permission for AI

Before your first use of an AI feature (chat, voice, WhatsApp and other features), the app shows what data is sent, to whom and for what purpose, and asks for your permission. There are two separate choices:

We store in your account your choice, the date and the version of the text you saw, to evidence consent (LGPD, Art. 8, §2). You can view and change both choices at any time in Settings > Privacy > AI providers; revocation applies to subsequent requests, at no cost, and does not delete your app data (section 8). If we change the text or the list of providers in a material way, we will ask for your permission again. If you do not grant permission, the AI features remain turned off and the rest of the app keeps working; on WhatsApp, Theros may reply with a link to grant permission in the app.

5.1 Models and processing

Theros uses Google Gemini to process:

5.2 Data sent to Google Gemini

To provide contextualized responses, Theros sends Google Gemini a summary of your financial profile containing:

This data is assembled automatically by the server from the information already recorded in the app and sent exclusively to generate the requested response. This transmission only takes place after your permission (section 5.0).

Data without direct account identifiers. The context the server assembles for the AI does not include your e-mail, phone number, CPF or CNPJ, your account's internal identifier, your full name or access tokens: we send at most your first name. This reduces, but does not eliminate, identifiability: what you write in messages and what you record in the app (for example, transaction descriptions, task titles, names of contacts you registered or mentioned) may contain personal data and is sent to generate the response. For this reason we treat this transmission as processing of personal data, with the protections of this section, and not as anonymized data.

5.3 AI safeguards

5.4 Scheduled agents

5.5 Proactive financial check-in

For Premium plan users, Theros runs daily (at 09:00 Brasilia time) an automatic analysis that:

You can turn off this feature by changing your plan or by contacting support.

5.6 Cloud OCR processing

In addition to local text recognition (Google ML Kit), Theros uses Google Gemini for intelligent data extraction from financial documents:

5.7 Closet AI tagging

In the Closet, Theros can automatically suggest the tags for an item (type, material, pattern, occasion, season, formality and whether it is waterproof) from its image. This feature is optional, depends on your explicit consent and is only activated after you allow it and state that you are 18 years of age or older.

5.8 AI reading of medical prescriptions

In the medication log, Theros can read a prescription from a photo and suggest the medications for you to review. This feature is optional, depends on your explicit consent, requested before first use (LGPD Art. 11, II, a), and only sends something when you take or choose a photo.

5.9 Other AI providers and web search

Theros's main AI provider is Google Cloud Vertex AI (Gemini models). Only if you turn on the "Other AI providers" option (section 5.0; off by default), Theros may also use other AI models, such as Claude (Anthropic) and DeepSeek, through OpenRouter (OpenRouter, Inc., United States), an intermediary that routes the request to the chosen model, or partner models offered within Google Cloud. Without this option, all AI processing involving your data stays with Google, except for the third-party web search described below. Requests that contain no data of yours (for example, the summary of the public transcript of a YouTube video when you do not write any instruction) may use these providers without the option. The rules below apply to any provider:

5.10 Rating AI responses (like and dislike)

You can rate AI responses in the app and, in some conversations, via WhatsApp. We store your rating (positive or negative), the reasons chosen, an optional comment of up to 300 characters and technical data about the rated response (model used, function type, plan, language and response time). The text of your message and of the response is only stored if you check the option to send it for review (excerpts of up to 300 and 500 characters). We use this data only to measure and improve the quality of the AI; access is restricted to Theros administration, it is not sent to AI providers or used for advertising, and it is deleted within 12 months or when you delete your account.

5.11 Installation identifier (abuse prevention)

To prevent the same device from receiving promotional benefits (trial period and referral rewards) more than once, the app generates a random code specific to the installation, which is not derived from device characteristics and is not used for advertising or cross-app tracking. Only an irreversible digest (SHA-256 hash) of this code leaves the device, and the original code cannot be recovered from it; in the anti-abuse record we keep only a second hash of that digest, computed with a secret key of ours (HMAC), which remains after account deletion to prevent reuse of the benefit. The legal basis is legitimate interest in fraud prevention (LGPD, art. 7, IX). If you believe you were blocked by mistake, contact support.

6. Storage and Security

6.1 Infrastructure

6.2 Security measures

7. Sharing Data with Third Parties

We do not sell, rent or share your personal data with third parties for marketing, advertising or any other commercial purpose.

Your data may be processed by the following service providers, strictly to enable the app's features:

Provider Data processed Purpose
Google Cloud / Firebase All app data (financial, personal, health, tasks, ideas, settings, OCR images, Closet images and attachments) Backend infrastructure, authentication, storage, notifications, processing
Google Gemini API / Google Cloud Vertex AI (Gemini) Chat messages, summarized financial context, voice audio, images of receipts, images of Closet items (downsized and without metadata, only with your consent), prescription photo, meal photo or description, text of ideas and notes when you trigger the AI, summary of appointments and medical tests, AI memories Artificial intelligence (responses, insights, OCR, agents, Closet item tagging, prescription reading, meal analysis, assistance with ideas and canvases)
Google APIs (Gmail, Calendar, Speech) E-mails and events (when authorized, processed on the device), voice command audio Optional integrations and speech-to-text conversion
WeatherAPI.com Approximate position (area of about 11 km) or city name, sent by our server, without user identification Weather forecast (Weather card and page, chat and Closet). Weather data by WeatherAPI.com
MET Norway (Norwegian Meteorological Institute) Approximate position (area of about 11 km), sent by our server, without user identification Weather forecast (fallback provider and later days of the forecast). Based on data from MET Norway (CC BY 4.0)
OpenStreetMap (Nominatim) City name (sent by our server, when WeatherAPI.com is unavailable) and coordinate rounded to about 11 km (sent by the app itself, in the web version and as an alternative in the mobile apps; in that case the service receives the device's IP address) Geocoding: from city name to coordinates and from coordinates to city name. © OpenStreetMap contributors
Open-Meteo (earlier versions of the app only) GPS coordinate or city name, sent directly by the device (the service receives the device's IP address) Weather forecast, until the app is updated (section 3.6)
RevenueCat User ID, subscription status Management of subscriptions and plans
Amazon Alexa ("Meu Theros" skill) Anonymous Amazon identifier, Echo device identifier, transcribed text of voice commands Voice command recognition, account linking via OAuth and execution of requested actions
Telegram (Telegram Messenger Inc. and its group companies, such as Telegram FZ-LLC) Chat identifier, @username, text of messages, captions and photos of receipts exchanged with the Theros bot (optional feature, once the bot is published) Delivery of messages and responses to your Telegram, at your request
Source service of a calendar by link (Microsoft, Apple, Google, Proton or other) Receives the address you provided when queried by our server; does not receive any data about you Download of the calendar you subscribed to
Webhook destination (URL you choose) Data of the events you chose (for example, entries or tasks) Integration with the tool you use (Make, n8n, Zapier, scripts, etc.)
Meta (WhatsApp Business Platform / WhatsApp Cloud API) Phone number and messages exchanged with Theros through the WhatsApp channel (optional feature) and, in the Closet, the outfit image (collage of the images of your items), only with your consent Delivery of messages and outfit images to your WhatsApp, at your request

7.1 Data in push notifications

Push notifications sent by Theros may contain summarized financial data for your convenience:

This information is visible on the device's notification screen. For greater privacy, you can disable specific notifications in your operating system settings.

In addition to the providers above, your data may be shared in the following circumstances:

7.2 Access by administrators and staff

As with any cloud service, the data stored in your account can technically be accessed by those who administer Theros. Currently, the database security rules allow authenticated administrators of the internal dashboard to read the documents in your user collections (for example, profile, subscription, tasks, health records and AI memories), except for server-only areas (API keys, webhooks and the integrations audit trail), which no app or dashboard reads. Anyone with access to the project's Google Cloud console can also technically access the storage. We use this access for support you requested, security and abuse investigation, compliance with legal obligations and operation of the service, and not to read the content of your records in normal use.

8. Your Rights (LGPD)

In accordance with the Lei Geral de Proteção de Dados (Law 13.709/2018), you have the following rights:

To exercise any right not available directly in the app, contact us at rafaelfurlan@lunanexgen.com. We will respond within 15 business days.

9. Data Retention

Type of data Retention
Financial data, tasks, notes, chat history, voice commands, agents and OCR While the account is active, or until manual deletion
AI memories (phrases you asked Theros to remember) and the preference for using memories While the account is active or until you delete the memory, delete all of them or delete your account. Deletion takes effect immediately; chat history is controlled separately
Appointments, medical tests, people you track and health attachments While the account is active or until you delete them. Never deleted automatically due to plan expiration
Food diary (meals, favorites, goals) While the account is active or until you delete it
Meal photo thumbnails Expire automatically: 90 days (Essential), 365 days (Pro) or 730 days (Premium); after a paid plan expires, 30 days (section 9, expiring plan). The numerical meal entry remains. You can delete them earlier
Meal photo sent for analysis Not stored or logged: processed only during the analysis
Ideas, notes, canvases and attachments While the account is active or until you delete them. Images and PDFs are also subject to the expired-plan storage rule (below); text is never deleted automatically
Calendar by link (encrypted address and imported events) Until you remove the subscription or delete your account; "Clear Data" keeps the subscription and deletes the imported events
Telegram link and conversation history with the bot Link: until you unlink, use "Clear Data" or delete your account. History: up to 30 days, or until you unlink. Photos of receipts sent through Telegram are not stored by us. On Telegram, retention follows its own policy, which we do not control
API keys (hash) and webhook endpoints Until you revoke or delete them, or delete your account
Webhook delivery log 14 days (deleted automatically)
Audit trail of keys and webhooks 180 days (deleted automatically)
Automation rules and technical execution record Rules: until you delete them or delete your account. Execution record: 14 days (deleted automatically)
WhatsApp channel messages 90 days (automatic daily cleanup)
Technical error logs (without the content of your messages, images or records) 90 days (deleted automatically)
Medications and dose log While the account is active, or until manual deletion of the medication
Prescription photo sent for reading Not stored: processed only during the reading
AI usage metrics (local) 90 days (automatic cleanup)
Voice chat sessions Only metadata (duration, date) while the account is active
Gmail data E-mails: not stored. Detected transactions: while the account is active
Device data and login method Overwritten at each session (only the most recent record is kept). Removed when the account is deleted
Digital Closet (cut-out images and thumbnails, tags, outfits, usage history, preferences and consents) While the account is active or until you delete the item, clear the closet (Closet settings) or delete your account. The original photo is not kept when automatic cutout works
Outfit images sent via WhatsApp (only with your consent) Not kept by us after sending. In your WhatsApp conversation and in Meta's systems, retention follows WhatsApp/Meta's terms and privacy policy, which we do not control. The Closet conversation state on WhatsApp and the daily counter are kept in your account and are deleted with the closet, with "Clear Data" and with account deletion
Workout (workout plans, completed and imported workouts, custom exercises, body weight, check-ins, preferences) While the account is active or until you delete the workout or the workout plan, or delete your account
Exported backups Local files on your device (under your control)

Account deletion: when you delete your account, we permanently remove from our servers: all subcollections of your user in Firestore (including those of the Closet, AI memories, health records and the food diary), the main documents in root collections linked to your ID (for example, salary history, custom categories, shares, feedback, referrals, support conversations, records of taps on in-app notices, survey responses, voice commands, Alexa interactions, invitations and shared public profiles), all files you uploaded to Firebase Storage (including Closet images) and your authentication account in Firebase Auth. We retain, for the period required by law or for audit purposes, records of subscription transactions and administrative support trails. Data held by third-party providers (for example, RevenueCat, app stores and analytics services) is subject to those providers' policies.

Clear Data (without deleting the account): the "Clear Data" option deletes the data recorded in the app (Firestore documents, including those of the Closet), while keeping your account, plan, account preferences, connections to external services (such as Gmail and calendars; the Telegram link is undone and events imported from calendars by link are deleted), notification tokens and plan usage counters. Among the files in Firebase Storage, this option deletes only the Closet images; files from other features (such as images of receipts and attachments) remain until you delete them or delete your account.

Expiring paid plan: storage and files

If a paid plan expires or is canceled, nothing is deleted for 30 days (grace period), and, while your storage is above the Free plan quota, you receive in-app and push notifications on days 0, 7, 21 and 28, and a last notice on day 84, six days before any cleanup. After that:

Closet: in Closet settings you can clear the entire closet (records and images) without deleting your account, and delete items individually.

10. Offline Processing

Theros has offline functionality. When you are not connected to the internet:

11. Cookies and Tracking

Mobile app (iOS/Android): does not use browser cookies. We collect only technical device metadata (model, operating system, app version) for diagnostics and service improvement.

Corporate website (therosapp.com) and web version (app.therosapp.com): we use:

We do not display ads within the app.

12. International Data Transfer

Your data is stored primarily in the southamerica-east1 region (São Paulo, Brazil) of Google Cloud. However, some third-party services may process data on servers located outside Brazil:

Each transfer is carried out under a contract with the processor and on the basis of one of the grounds of art. 33 of the LGPD, with each provider's contractual and security safeguards. We do not claim that every provider has adopted the ANPD (Brazilian National Data Protection Authority) standard contractual clauses: for providers that do not yet have a specific instrument for Brazil, we limit transmissions to general text content, without direct identifiers and without sensitive data (section 5.9), and we are working to formalize these clauses.

13. Minors

Theros is not intended for persons under 18. We do not knowingly collect data from minors. If we become aware that we have collected data from a person under 18, we will delete that data immediately. If you believe a minor has provided data to Theros, contact us at rafaelfurlan@lunanexgen.com.

To use Closet AI tagging, you must state that you are 18 years of age or older; in addition, if the date of birth entered in your profile indicates that you are under 18, the feature is not enabled and tags must be filled in manually.

Health data of children and adolescents recorded by a parent or guardian (section 3.18) is the responsibility of the account holder, who represents that they have standing to record it.

14. Changes to this Policy

We may update this Privacy Policy periodically to reflect changes in our practices, features or legal requirements. Significant changes will be communicated 15 days in advance, by in-app notification and, where possible, also by e-mail. The date of the last update will always be indicated at the top of this document. Continued use of the app after the changes constitutes acceptance of the updated policy, without prejudice to your right to revoke consents and delete your data at any time.

Summary of the latest changes (October 10, 2026): details on AI providers, retention and processing by Google (sections 5.3 and 5.9), rating of AI responses (5.10), installation identifier against abuse (5.11) and a 15-day notice period for material changes (14); permission requested before first use of AI, with a separate option, off by default, for other AI providers, which you can change in Settings > Privacy > AI providers (sections 2, 5.0, 5.2, 5.3, 5.9, 8 and 12); an exact description of the notices (days 0, 7, 21, 28 and 84) and of the automatic removal of excess files when a paid plan expires (section 9) and of the channels used to announce changes (14). Previous changes (October 6, 2026): common rules for health data, with legal basis, purpose, user control and a prohibition on advertising use (sections 2, 3.17 and 8); appointments, medical tests and people you track, with the representation of standing for data of family members and dependents (3.18); food diary with AI photo analysis, thumbnails that expire by plan and the photo not being stored (3.19 and 9); ideas, canvases and attachments (3.20); explicit AI memory and assistant tone, without sensitive data or secrets (3.4, 5.1, 5.2, 8 and 9); calendar by link (4.4), Telegram (4.5), public API and webhooks (4.6) and automation rules (4.7), with their retention periods; who can access stored data (7.2); new retention periods for technical records (section 9); rule for expiring paid plans, with a 30-day grace period and without deleting text, app data or health documents (section 9); corrected description of voice chat, which no longer uses the Gemini Live API (3.5 and 5.1). No previous commitment was withdrawn. (October 5, 2026): update of the contact e-mail and of the Data Protection Officer to rafaelfurlan@lunanexgen.com (sections 1, 8, 13 and 15); addition of the medication log with reminders, an every-X-hours schedule and an adherence map, and of optional AI reading of prescriptions from a photo, with dedicated consent (sections 3.16, 5.1, 5.8 and 9). (October 4, 2026): addition of the Workout module, with optional import of workouts from Health/Health Connect, check-in and a notice on arriving at the gym (sections 3.7, 3.15, 8 and 9); optional sending of Closet outfit images via WhatsApp, with dedicated consent and Meta as processor (sections 3.14, 7, 8, 9 and 12). (October 3, 2026): addition of the digital Closet (sections 3.14 and 5.7); description of the use of approximate position for the weather forecast and of other uses of location (section 3.6); weather forecast, geocoding and AI providers, including Open-Meteo in earlier versions of the app (sections 7 and 12); and details on data deletion, including files in storage (section 9).

15. Contact and Exercise of Rights

For questions, requests, complaints or to exercise your rights under the LGPD, contact us:

E-mail: rafaelfurlan@lunanexgen.com
Data Protection Officer (DPO): rafaelfurlan@lunanexgen.com
Response time: within 15 business days

You also have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) if you believe your rights have not been properly addressed.