Privacy Policy
Effective Date: August 16, 2026
At Thesis ("Thesis", "we", "us", or "our"), we take your privacy seriously. Please read this Privacy Policy to learn how we treat your personal data. By using or accessing our Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and share your information as described in this Privacy Policy.
Remember that your use of Thesis's Services is at all times subject to our Terms of Service. Any terms we use in this Policy without defining them have the definitions given to them in the Terms of Service.
If you have a disability, you may access this Privacy Policy in an alternative format by contacting support@thesisapp.co.
- 1. What this Privacy Policy Covers
- 2. Personal Data
- 3. How We Share Your Personal Data
- 4. Tracking Tools and Opt-Out
- 5. Google Drive and Third-Party Integrations
- 6. Data Security and Retention
- 7. Personal Data of Children
- 8. Your Privacy Rights
- 9. European Union Data Subject Rights
- 10. Changes to this Privacy Policy
- 11. Contact Information
What this Privacy Policy Covers
This Privacy Policy covers how we treat Personal Data that we gather when you access or use our Services. "Personal Data" means any information that identifies or relates to a particular individual and also includes information referred to as "personally identifiable information" or "personal information" under applicable data privacy laws, rules or regulations. This Privacy Policy does not cover the practices of companies we don't own or control or people we don't manage.
Personal Data
Categories of Personal Data We Collect
This list describes categories of Personal Data we may collect when you use the Services:
- Profile or Contact Data: Examples include first and last name, email address, and account credentials such as passwords or authentication tokens.
- Payment Data: Limited billing details associated with your subscription (for example, billing email, last four digits of a payment method, and billing country or address where provided). We use a third-party payment processor (currently Paddle) and do not retain full payment card numbers ourselves.
- Device/IP Data: IP address, device ID, domain server, type of device/operating system/browser used to access the Services.
- Usage Data: Interactions with a webpage or application, referring webpage/source through which you accessed the Services, request identifiers, and related usage statistics needed to operate and improve the Services.
- Social Network Data: If you use Google, GitHub, or other social login providers, we collect authentication tokens, associated email addresses, and basic profile information authorized by you.
- Integration Data: If you connect Google Drive or other integrations, we collect OAuth tokens and only the file metadata and content you choose to access or attach inside Thesis (for example, file name, id, mime type, and link).
- Other Identifying Information that You Voluntarily Choose to Provide: Identifying information in emails or messages you send us, and content in documents, projects, issues, and other workspace materials you create or upload.
How We Share Your Personal Data
We may share your Personal Data with the following categories of third parties:
- Service Providers: Hosting, technology and communication providers, security and fraud prevention consultants, support and customer service vendors, payment processors. These parties only access your data to perform tasks on our behalf.
- Business Partners: Third parties you explicitly authorize to receive your Personal Data, such as integrations or applications connected to your workspace.
- Legal Obligations: We may share Personal Data when required to comply with law, respond to lawful requests, protect rights and safety, investigate fraud or security issues, or enforce our Terms of Service.
- Business Transfers: All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part).
- Data that is Not Personal Data: We may create aggregated, de-identified or anonymized data from the Personal Data we collect. We may use such aggregated or anonymized data and share it with third parties for our lawful business purposes.
Tracking Tools and Opt-Out
We use cookies and similar technologies such as local storage to keep you signed in, remember preferences, and operate the Services securely. You can control cookies through your browser settings. If you decline certain cookies, some features of our Services may not function properly. We do not currently use third-party advertising analytics such as Google Analytics on the Services. If that changes, we will update this Privacy Policy.
Google Drive and Third-Party Integrations
Thesis may offer optional integrations, including Google Drive, that you connect from Settings → Integrations. Connecting an integration is voluntary and can be disconnected at any time.
When you connect Google Drive, Thesis requests limited Google OAuth access (currently including drive.readonly) so you can browse and attach existing Drive files to issues and project resources inside Thesis. We use this access only to:
- List and search files you are allowed to see in Google Drive
- Read metadata and content for files you explicitly select to attach or open in Thesis
- Store OAuth tokens needed to keep the connection working on your behalf
We do not modify, delete, or share your Google Drive files. We do not sell Drive data. We do not use Google user data for advertising. Drive data is processed only to provide the integration features you enable, and Google's own privacy policy also applies to your use of Google services.
You can revoke Thesis's access at any time from Thesis Integrations settings and from your Google Account permissions page. If you revoke access, we will stop using your Google Drive connection and will delete or invalidate related tokens according to our retention practices.
Data Security and Retention
We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you with our Services. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes, or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation.
Personal Data of Children
As noted in the Terms of Service, we do not knowingly collect or solicit Personal Data from children under 16; if you are a child under 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at support@thesisapp.co.
Your Privacy Rights
Depending on where you live, applicable privacy laws may give you rights regarding your Personal Data. These can include the right to know what Personal Data we collect, request access or deletion, request correction of inaccurate data, and opt out of certain sharing. We do not sell your Personal Data. To exercise available rights, contact us at support@thesisapp.co. We will not discriminate against you for exercising privacy rights that apply to you. Additional rights for EEA, UK, and Swiss residents are described below.
European Union Data Subject Rights
If you are a resident of the European Economic Area (EEA), the UK, or Switzerland, you have certain rights under the General Data Protection Regulation (GDPR) or similar laws. These include the rights to access, rectify, or erase any personal data we have collected about you. You also have the right to data portability, the right to restrict processing, and the right to object to our processing of your personal data. We act as a Data Controller for your account information and a Data Processor for the workspace data you upload. You may lodge a complaint with your local supervisory authority if you believe your rights have been violated.
Changes to this Privacy Policy
We're constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time as well, but we will alert you to changes by placing a notice on the Thesis website, by sending you an email, and/or by some other means. Please note that if you've opted not to receive legal notice emails from us (or you haven't provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them.
Contact Information
If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:
Email: support@thesisapp.co