What We Collect
Discord account. When you sign in we receive your Discord ID, username, avatar, and the email address on your Discord account via OAuth, and we read the list of servers you manage so the dashboard knows which ones to show. Servers where Thea is not installed are not stored, OAuth tokens are encrypted at rest with AES-256-GCM, and we never see your Discord password.
Email. We ask you to confirm your email address with a mailed code before the dashboard opens. It is used for account security (confirming a deletion), official notices, and service status announcements — never marketing, and never shared. The content of a notice is never put in an email; the email only tells you one is waiting.
Server data. For servers you connect: the server name, ID, icon, and the channel configuration you set in the dashboard.
Conversations. Messages that are routed to Thea as questions — and the answers it gives — are stored as transcripts so you can review them in the dashboard and correct wrong answers. On plans with vision enabled, this includes images attached to a question. Casual chatter in your server is not collected; only messages the bot actually handles are stored.
AutoMod scans. If a server turns on AutoMod, messages there are scanned for abuse — but the message text is not kept. A scan stores only a hash of the content, the scores, and any action taken. Text being scored is sent to the OpenAI Moderation API (and, on paid tiers, to an LLM classifier), used for nothing but the scan, and not retained by us.
Reports. When content is reported to us — by a person or by an automated flag — we keep a snapshot of the reported content so a human can review it. The snapshot is deleted when the report is resolved, unless it must be kept as evidence for an enforcement decision (a legal hold).
Knowledge sources. The docs, sites, files, and articles you connect are fetched and indexed so the bot can answer from them. Credentials for integrations (for example a Notion token) are encrypted at rest with AES-256-GCM.
Billing. Payments are processed by Stripe. We store your subscription status and plan — never card numbers.
Security logs. Actions taken in the dashboard are written to an audit log together with the IP address and browser they came from. That log is how a compromised account gets investigated.
Diagnostics. Server logs and error reports (via Sentry) that may include message IDs and error context, used only to keep the service working.
How We Use It
To operate the service: answering questions, syncing sources, running the moderation you enable, showing you analytics about your own community, and billing. We do not sell personal data, and we do not use your content to train foundation models.
Who Processes It
We use a small set of subprocessors:
- LLM providers (OpenAI, Anthropic, Google, via Vercel's AI Gateway) — receive question text, the retrieved passages needed to answer it, and content being moderation-scored;
- Supabase — hosts the Postgres database, authentication, and uploaded files;
- Stripe — payment processing;
- Resend — delivers the emails described above;
- Upstash — rate limiting;
- Sentry — error reporting.
Several of these providers process data in the United States; where the GDPR applies, those transfers are covered by their standard contractual clauses or Data Privacy Framework participation. Each tenant's data is isolated with Postgres row-level security; one server's content is never retrievable from another server's context.
How Long We Keep It
- Conversation transcripts age out automatically: 30 days on Free, 180 days on Pro, 365 days on Business.
- Knowledge sources are kept until you delete them or remove the bot.
- Removed servers: kicking the bot starts a 14-day clock, after which the server and everything belonging to it is permanently deleted. Re-adding the bot within the window keeps your setup intact.
- Deleted accounts: confirming an account deletion (see Your Rights) starts a 7-day clock, after which the account is permanently erased.
- Dead-letter job records (sync failures kept for debugging) are pruned automatically.
- Enforcement records: if a user, server, or account is banned under the Acceptable Use Policy, we keep the minimum needed to enforce the ban — the Discord ID, the reason, and when it happened — for as long as the ban stands, even after the rest of the data is deleted. Without this, a ban could be undone by deletion.
Cookies
The dashboard uses session cookies for authentication — that is all. There are no advertising or cross-site tracking cookies, which is why there is no cookie banner. Public help centers set no cookies at all, and the helpful-vote on an article is stored without any identifier.
Your Rights
You can delete knowledge sources, conversations, or your whole server's data from the dashboard at any time. You can also delete your account from the dashboard settings: we confirm the request with a code sent to your email, then permanently erase the account after a 7-day window — long enough to catch a deletion you did not authorise, and cancellable until it runs out.
For data export or any other request, email support@thea.gg and we will respond within 30 days. If you are in the EU/EEA or UK, these rights include access, rectification, erasure, and portability under the GDPR.
Some enforcement decisions — for example suspending a user or server for abuse — may be made by automated systems. You can always contest one by emailing support@thea.gg; appeals are reviewed by a person, as described in the Acceptable Use Policy.
Children
The service is intended for users who meet Discord's minimum age requirement (13, or higher where local law requires).
Changes
If this policy changes materially we will give notice on the dashboard or by email before the change takes effect.