This Privacy Policy describes how Thyra ("we", "us", "our") collects, uses, stores, and protects your information when you use our AI-powered agent platform. It applies to all users, including those in the European Union, and is designed to align with the EU General Data Protection Regulation (GDPR) and the EU Artificial Intelligence Act (Regulation (EU) 2024/1689).
1. Overview
Thyra is an AI agent platform for managing intelligent agents,
2. EU AI Act & Data Protection
Under the EU AI Act, deployers of AI systems must ensure that personal data processed in connection with AI is handled in accordance with GDPR and applicable data protection law. We:
- Process personal data only for specified, explicit, and legitimate purposes
- Implement appropriate technical and organisational measures to protect data
- Respect your rights to access, rectification, erasure, restriction, portability, and objection
- Provide transparency about how AI systems use your data
For more on AI-specific obligations, see Section 14.
3. Data We Collect
3.1 Account & Profile Data
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Name, email, profile image | Account identification, communication | Contract performance |
| Password (securely hashed) | Authentication | Contract performance |
| Session tokens, IP, user agent | Security, session management | Legitimate interest |
| Credit balance, superuser status | Billing, access control | Contract performance |
3.2 Chat & Usage Data
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| User queries, model responses, flow logs | Service delivery, analytics | Contract performance |
| Token usage, credits consumed | Billing, capacity planning | Contract performance |
| Client-side chat history (browser storage) | Offline/UX continuity | Consent / Legitimate interest |
3.3 Agent & Configuration Data
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Agent names, prompts, instructions, guardrails | Agent configuration | Contract performance |
| Documents (PDF, TXT, DOCX, CSV) for RAG | Knowledge base, retrieval | Contract performance |
| MCP server configs (name, transport, tools) | Extension configuration | Contract performance |
| API tokens (hashed), scopes | Programmatic access | Contract performance |
3.4 Connection & OAuth Data
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| OAuth access/refresh tokens, expiration | Integration with Gmail, Outlook, etc. | Contract performance |
| Connection-specific settings | User preferences (e.g., calendar privacy) | Contract performance |
4. How We Use Your Data
We use your data to:
- Operate the platform and deliver AI responses
- Run integrations (email, calendar, search, etc.)
- Process voice calls and STT/TTS
- Execute code in sandboxes
- Index documents for RAG
- Enforce guardrails and security
- Improve our services (analytics, debugging)
- Comply with legal obligations
5. Third-Party Integrations
When you connect external services, we store OAuth tokens and may send your data to those providers. Each integration is described below.
5.1 Gmail
- Capabilities: Read, send, reply, forward emails
- Data accessed: Email content, metadata, attachments (as needed)
- Processing: Background polling when Gmail is connected
- Provider: Google OAuth; subject to Google's Privacy Policy
5.2 Outlook (Mail & Calendar)
- Outlook Mail: Read, send, reply
- Outlook Calendar: List, create, update, delete events
- Provider: Microsoft OAuth; subject to Microsoft's Privacy Policy
5.3 Calendars (Google, Apple, Cal.com, ICS)
- Google Calendar: Full CRUD on events
- Apple Calendar: Read-only
- Cal.com: List, create, cancel bookings
- ICS Feed: Read-only context
5.4 Other Integrations
- Linear: Issue tracking (read, create, update)
- Twilio: Voice calls, WhatsApp
- Mattermost: Webhook receive, reply
6. AI/LLM Providers
Your messages, chat history, system prompts,
7. Voice & Communications
Voice and messaging features use third-party communications providers; audio is streamed to and from those providers.
8. Web Search
When the Web Search tool is used, queries are sent to third-party search providers. Search results are incorporated into AI responses. We do not control third-party search result content.
9. Data Storage & Retention
| Storage | Purpose |
|---|---|
| Database | User data, sessions, chat history, agents, connections |
| Queue systems | Background jobs (indexing, prompt generation, voice, web search, code execution) |
| Object storage | Documents, uploads |
| Vector stores | RAG embeddings for knowledge retrieval |
Retention periods depend on data type and applicable law. You may request deletion of your data (see Section 12).
Execution traces: 60 days
Every agent run records a detailed execution trace: the prompts we assemble and send to the model provider, the model's raw responses, the knowledge-base passages retrieved, and the arguments passed to each tool. This is what powers the run detail view, so you can see exactly what your agent did.
Sixty days after a run, that content is permanently blanked. It is overwritten in place and cannot be recovered afterwards, by you or by us.
The run's usage record itself is kept indefinitely: identifiers, timestamps, token counts, credits charged, model and tool names, and success or failure outcomes. Those are billing records, and we keep them so your charges remain reconcilable against our own ledger and our providers' invoices for as long as either may be questioned.
Your conversation history is not covered by this 60-day rule. The chat messages you can see in the app are a product feature rather than telemetry, and are retained until you delete them or close your account.
10. Security & PII Protection
We implement
11. Support Access & Audit
Authorized support staff may access user resources (e.g., agents) to resolve issues. Such access is logged in an audit log (actor, action, resource type, resource ID, resource owner, timestamp) for accountability and compliance.
12. Your Rights
Under GDPR and applicable law, you may have the right to:
- Access: Obtain a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Restriction: Limit processing in certain circumstances
- Portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent
- Lodge a complaint: With a supervisory authority (e.g., in your EU Member State)
To exercise these rights, contact us at legal@
13. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including by
14. AI Systems and Personal Data (EU AI Act)
Under the EU AI Act, deployers of AI systems must ensure that personal data processed in connection with AI is handled in accordance with GDPR. We: inform you when you interact with AI (see Terms of Service); process data only for specified purposes; collect only data necessary for the Service; implement measures to ensure data quality where it affects AI outputs; support
15. Cookies & Similar Technologies
We use session cookies for authentication. These are essential for the Service. We may use analytics cookies where permitted; you can manage preferences via your browser or our cookie notice. For more on cookies, see our Cookie Policy.
16. Children
The Service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected such data, please contact us.
17. Changes
We may update this Privacy Policy from time to time. We will notify you of material changes (e.g., by email or in-app notice). Continued use after changes constitutes acceptance.
18. Contact
For privacy-related questions or to exercise your rights:
Email: legal@
Data controller: Thyra (Delaware, USA / Portugal)