Privacy
Privacy policy
Last updated 23 August 2026
Theazo runs AI agents on behalf of the companies that integrate it. That means we hold two quite different kinds of data: information about our customers, and the content their agents process on behalf of their own end users. This policy covers both, and names every third party either one reaches.
What we collect
Account data. When you create an account we store your email address, the organisations and projects you belong to, and your role in them. Authentication is handled by Supabase; we never see or store your password.
Usage and billing data. We record what ran, when, how long it took, which model and compute provider it used, and what it cost. This is what makes per-end-user cost attribution possible, and it is the basis on which we bill. Payment details are handled by our merchant of record and never reach our systems.
Agent content. Running an agent means processing whatever you send it: the task, any files, tool results, and the output. Where you have configured knowledge bases, that content is stored and indexed so agents can retrieve from it.
Credentials you give us. API keys for your own model or compute providers are encrypted at rest with AES-256-GCM under a key derived per platform. Theazo API keys are stored only as SHA-256 hashes — we cannot recover a key you lose, only issue a new one.
Your end users
Most Theazo customers use it business-to-business-to-consumer: their users run agents, and Theazo stays invisible. For that data we act as a processor, not a controller. You decide what your users send, how long it is kept, and what they are told. We process it to run the service you asked for and for nothing else — we do not use customer content to train models, and we do not sell it.
Sessions are isolated per end user. A user identifier you supply is stored so usage can be attributed and limits enforced; we do not require it to be a real name or email, and we recommend it is not.
Who else sees it
Running an agent necessarily involves other providers. These are the categories of processing that happen, and what data reaches each. We will name the specific sub-processors, and notify you of changes to them, on request or under a data processing agreement:
Authentication and database
Managed cloud infrastructure holds accounts and the primary record of what ran
Account identifiers, organisation and project records, agent and run metadata
Operational state
Short-lived counters for rate limits, spend tracking, and event delivery
Identifiers and counters only; nothing whose loss would be a correctness problem
Sandbox compute
The isolated environments agents actually execute in
Task input, files, and any code the agent runs
Model providers
Inference, unless you bring your own provider
Prompts, task content, and tool results sent for completion
Payments
Our merchant of record handles subscriptions, invoices, and tax
Billing email; card details are handled entirely by the payment provider and never reach Theazo
File storage
Object storage, when it is configured for your account
Files uploaded to or produced by an agent
If you bring your own compute or model provider, agent content goes to your infrastructure instead of ours, and the corresponding row above no longer applies to you. That is one of the reasons the option exists.
How long we keep it
Account and organisation records are kept while your account is open. Usage and billing records are kept for as long as we are required to retain financial records. Run logs and agent output are kept so you can inspect what happened; short-lived operational state such as rate-limit counters expires automatically within 24 hours.
When you close an account we delete or anonymise account and content data, retaining only what is needed for legal and accounting obligations. You can request earlier deletion of specific content at any time.
Security
Data is encrypted in transit. Provider credentials are encrypted at rest under per-platform keys, and Theazo API keys are stored as one-way hashes. Every agent runs in an isolated sandbox rather than shared infrastructure, and every database query is scoped to the owning platform so one customer's data cannot be returned to another.
No system is perfectly secure. If you believe you have found a vulnerability, please write to support@theazo.com with “security” in the subject line, rather than disclosing it publicly, and we will respond.
Your rights
You can request a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. If you are a Theazo customer acting on behalf of your own users, we will help you fulfil the equivalent request from them. Write to support@theazo.com and we will respond within 30 days.
Changes
When this policy changes materially we will update the date at the top and notify account holders by email before the change takes effect. We will not reduce your rights retroactively.
Contact
Questions about this policy, or about how a specific piece of data is handled, go to support@theazo.com. Other ways to reach us are on the contact page.