Encrypted in transit & at rest
All communication uses HTTPS. Provider keys are stored in Azure Key Vault with hardware-backed encryption.
Trust & Safety
Theodore& is built to help people trust the system that does real work in their files. Here’s how we protect your data, your workspace, and your team.
Key takeaways
Our commitment
Users should always be able to understand where work is happening, which AI provider is being used, and what data is required to get the job done. No hidden processes. No ambiguity.
Security measures
All communication uses HTTPS. Provider keys are stored in Azure Key Vault with hardware-backed encryption.
Workspace files are accessed through Microsoft Graph API or Google Drive API with scoped OAuth tokens. Theodore only accesses what you authorize.
All services run on Azure Container Apps with managed identity, role-based access controls, and audit logging.
Theodore& does not use your workspace files for model training. Your data is processed solely to deliver the requested workflow.
When Theodore sends a request to OpenAI or Anthropic, you know which provider is being used. Provider API calls are governed by the provider's own terms.
Admin controls, permission-based workspace access, and audit trails ensure your team maintains control over who can do what.
Privacy policy
Theodore& processes project files, messages, and workspace metadata only to deliver the requested workflow. Theodore& does not use customer workspace files for unrelated model training, and access to files remains tied to the product flows and permissions required to perform the task.
When you connect Google Drive, Theodore& uses Google Drive access only to let you choose project folders, read project files you ask Theodore to work on, create or update requested output files, keep project folders synchronized, and show file status in the product. Google Drive data is not sold, used for advertising, or used for unrelated model training.
Theodore& stores the project information needed to operate the service: account details, connected providers, workspace and file metadata, job history, event logs, and output artifacts. That information helps with reliability, support, auditability, and product operations.
We use information to provide the service, maintain security, debug issues, improve the product, communicate with users, and comply with legal obligations. When users connect a provider such as OpenAI or Anthropic, Theodore& may send the relevant request payload to that selected provider in order to complete the task.
Theodore& does not sell customer data to third parties. Theodore& may share information with infrastructure partners, AI providers users have connected, and legal authorities where required. Google Drive files and metadata are shared only as needed to provide user-requested Theodore workflows, such as sending relevant file content to the AI provider the user selected. Provider API calls are governed by the provider's own terms.
Job history and output artifacts are retained for the duration of the user's active account. Cached Google Drive and Microsoft 365 file metadata are retained only as needed to operate connected projects and sync state. Users may disconnect a drive account, delete projects, or request account data export or deletion by contacting support. Provider-side retention is governed by each provider's data handling policies.
Last updated: March 7, 2026.