Legal
Privacy Policy
Effective September 29, 2026
This policy describes what data Throu collects, how it is used, and the choices you have. Throu is operated by Throu, Inc..
1. Information we collect
We collect four categories of information:
Account information. When you sign up, our authentication provider (Clerk) records your email address, name, and authentication metadata (e.g., login timestamps, session identifiers). We use this to identify your account and secure access.
Connected-account data. When you connect a third-party service (Gmail, Google Calendar, GitHub, Jira, Linear, Notion, YouTube), OAuth tokens and the data your agents read from those services pass through Throu so that your agents can act on your behalf. The scope of data is limited to what each agent needs and what you grant during OAuth.
Usage and content. Chats you send, agent runs you trigger, and outputs the agent produces are stored so you can review them later and so the system can resume long-running tasks across sessions.
Browsing on your behalf. When you ask Throu to look something up or to do something on a website, it searches the web, reads pages, and can run a cloud browser for you in the background. We store the task you gave, the sites it visited, a log of its steps, and small screenshots of the pages so you can follow and review the task. When a site asks you to sign in, you type your password or code into a secure form in Throu. It goes straight into the site and is never stored by us, written to our logs, or shown to the AI model. After you sign in, the site's session cookies stay in your own browser profile at our browser provider, encrypted at rest, so you stay signed in. The browser asks for your approval before it submits, sends, books, or deletes anything, unless you have told it to always allow that on a site, and it always asks before a purchase or an account change. One-time codes and sign-in links are removed from the email content the assistant reads.
2. How we use information
- To operate the agents you have explicitly connected and authorized.
- To send the chats and tool calls you make, and the app data they need, to large language model providers (currently Anthropic and OpenAI) and return their responses. We ask for your permission before your first chat.
- To search the web, read pages, and run a cloud browser for the tasks you ask for.
- To deliver notifications you have opted into via channels you have linked (e.g., Telegram).
- To debug, monitor, and improve the service.
- To comply with legal obligations.
We do not sell your personal information. We do not use your private content to train third-party models.
3. Service providers we share data with
Throu relies on the following sub-processors. Each receives only the data needed to perform its function.
- Clerk - authentication, session management.
- Composio - OAuth token storage and brokered tool calls to connected third-party services.
- Plaid - bank account connections. When you link a bank, Plaid shares your account, balance, and transaction data with Throu.
- Anthropic - large language model inference (Claude).
- OpenAI - large language model inference (GPT family).
- Voyage AI - text embeddings used to organize your conversations into threads.
- Railway - application hosting.
- Neon - managed PostgreSQL database.
- Vercel - frontend hosting, edge network, AI model gateway, and the sandboxed workspace your assistant works in.
- Browser Use - hosts the cloud browser that runs your browser tasks, including your browser profile (cookies for sites you signed in to), encrypted at rest.
- Parallel - web search. Receives the search queries your assistant makes.
- Firecrawl - fetches public web pages our own fetcher can't read. Never used for pages that carry sign-in links or tokens.
- Sentry - error monitoring.
- Stripe - payments for subscriptions bought on the web.
- Apple - App Store in-app purchases and push notifications to the iOS app.
- Telegram - delivery of optional message notifications, when you have linked Telegram.
Each sub-processor handles data under its own privacy practices. You can revoke access at any time by disconnecting the relevant integration in Connections or by deleting your account.
4. Data retention
Account information is retained while your account is active. Chat history and agent run logs are retained for as long as your account is active so that you can review past activity, unless you delete them earlier. You can delete your account at any time in Settings, on the web or in the iPhone app. When you delete your account, we delete or anonymize the associated data within 30 days, except where retention is required by law.
OAuth tokens for connected services are deleted when you disconnect a provider or delete your account.
Browser task records are kept with your chat history. Page screenshots are deleted after 7 days. You can sign out of any site, or of every site, in Settings > Browser. Signing out of every site deletes your browser profile at our browser provider. Deleting your account deletes it too.
5. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise any of these rights, email privacy@throu.ai. You can also delete your account yourself in Settings.
You can revoke a connected service's OAuth grant at the provider (e.g., your Google Account security page) at any time, independent of Throu.
6. Security
We use TLS in transit, encryption at rest, and the principle of least privilege for OAuth scopes. See our Security page for details.
7. Children
Throu is not directed at children under 13 (or the age of digital consent in your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact privacy@throu.ai and we will delete it.
8. International transfers
Your information may be processed and stored in countries other than where you live, including the United States. By using Throu, you consent to this transfer.
9. Changes to this policy
We may update this policy. Material changes will be reflected by an updated effective date and, where appropriate, additional notice (e.g., email or in-app banner).
10. Contact
Privacy questions: privacy@throu.ai. For other questions, see our Contact page.