Privacy Policy for Thorin AI
Last Updated: June 25, 2026
Thorin AI ("Thorin AI," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
1. Information We Collect
a. Information You Provide:
When you register for an account, you provide us with information such as your name and email address for account administration.
b. Service Data:
To provide the Service, we process the content of emails and related communication data that you connect to your account ("Service Data").
c. Usage Data & Cookies:
We automatically collect certain information when you use the Service. This includes high-level telemetry data, such as feature usage, clickstream data, and performance metrics. We use cookies and similar tracking technologies to operate and administer the Service.
d. Optional Mobile Messaging Data:
If you opt in to optional mobile messaging notifications, we collect your mobile phone number, messaging preferences, opt-in and opt-out status, consent timestamp, consent source, inbound replies, and related message metadata such as delivery status and carrier/channel information. Mobile notifications are not enabled by default.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To Provide and Maintain the Service: To operate our platform and deliver the automation services you request.
- To Improve and Develop the Service: To analyze usage patterns, conduct research, and enhance functionality and user experience. We do not use the content of your emails or other Service Data to train AI models.
- To Communicate With You:To send you service-related announcements, administrative messages, and marketing communications. You may opt out of marketing emails at any time by clicking the "unsubscribe" link in the email.
- To Provide Optional Mobile Notifications: To send optional mobile messaging notifications, such as agent updates, workflow alerts, onboarding messages, and support-related notices, and to manage HELP, START, UNSTOP, STOP, ENABLE, DISABLE, opt-out, and other messaging preference requests.
We do not sell your data to third parties. We do not use your Service Data for advertising purposes.
3. Our Commitment to Data Confidentiality and Security
We understand the sensitivity of your Service Data. We are committed to the following principles:
a. Restricted Human Access:
Access to your Service Data (i.e., email messages) is strictly controlled. Our systems are designed to ensure that such data is not subject to human review. Our employees are prohibited from viewing the content of your Service Data.
b. Emergency and Support Access:
The only exceptions to the no-review policy are:
- "Break-Glass" Procedure: In a critical emergency (e.g., a major security incident), a limited number of authorized leaders may access specific data using a special access key. All such access is logged and audited.
- Authorized Support: If you request technical support, you may be asked to provide explicit, temporary authorization for a support engineer to access relevant data to resolve your issue.
c. Database-Level Actions:
All automated processing is performed at the database level without human intervention.
d. Security Measures:
We implement robust security measures to protect your data, including industry-standard encryption for all data at rest in our databases and industry-standard protocols for data in transit. Our infrastructure is hosted on Amazon Web Services (AWS), a secure and certified cloud provider.
4. Data Sharing and Third-Party Sub-Processors
We do not share your personal data with third parties for their own marketing purposes. We may share data with trusted third-party service providers who act as sub-processors to help us operate our Service. These include:
- Cloud Hosting: Amazon Web Services (AWS) for data storage and hosting.
- AI Processing: OpenAI for processing data to enable service functionality. We have a data processing agreement with OpenAI that restricts their use of the data.
- Telemetry & Monitoring: Datadog for system telemetry, monitoring, and observability.
- Authentication Services:WorkOS to securely connect with your organization's SSO provider and synchronize directory data.
- Messaging Providers: We currently use toll-free SMS providers, including Twilio or Linq, to deliver optional mobile messaging notifications for users who opt in. These service providers help us send and receive messages, track delivery status, honor provider and carrier opt-out handling, and process HELP, START, UNSTOP, STOP, and opt-out requests. You can also manage personal agent notifications in Personal Agent Settings or by replying DISABLE to pause them and ENABLE to resume them.
We do not sell, rent, buy, share, or transfer mobile phone numbers, text messaging opt-in data, or messaging consent to third parties or affiliates for their own purposes or for marketing or promotional use. We do not share mobile messaging opt-in data or consent with third parties or affiliates except as needed for service providers to deliver optional mobile messaging and manage messaging preferences on our behalf. Text messaging originator opt-in data and consent are excluded from the data sharing described in this Privacy Policy.
5. Data Retention
We retain your Service Data for up to one (1) year in order to operate, maintain, and provide the Service, which includes improving caching, performance, and reliability. After this period, the data is permanently deleted from our production systems. Account information is retained for as long as your account is active or as needed to comply with our legal obligations.
If you remove your mobile phone number from your settings, we delete it from your account settings and no longer use it for mobile messaging notifications, except where limited records must be retained for legal, security, fraud prevention, or compliance purposes.
6. Your Rights and Choices
You have certain rights regarding your personal information. You may request to access, correct, or delete your personal data by contacting us at the email below. We will respond to your request within a reasonable timeframe.
7. Children's Privacy
Our Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on our website. We encourage you to review this Privacy Policy periodically for any changes.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Thorin AI
Pier 5, Suite 101
San Francisco, CA
privacy@thorin.com