Privacy Policy

HeyTheo, Inc.

Last Updated: August 24, 2026

This Policy explains what data HeyTheo collects, how we collect it, what we use it for, and who we share it with. It applies to the HeyTheo mobile app, the website at heytheo.io, and all related services (the “Service”).

1. Information We Collect

Account information: Your email address, and the display name and profile picture associated with your account. Collected directly from you at sign-up, or from Google or Apple if you choose to sign in with one of those accounts. If you sign in with Apple and choose to hide your email address, we receive a private relay address instead of your own, and we use it the same way.

Payment information: None. HeyTheo is free to use, with no purchases or subscriptions in the app, so we do not collect or store payment details of any kind. If we introduce paid features we will update this Policy before they launch.

Content you create in the Service: The stock symbols on your watchlist, the symbols you mark as owned, baskets and strategies you build, alerts you configure, the ideas you adopt or dismiss, the searches you run in the app, and the questions you type to Theo. Collected directly from you as you use the app. We do not ask for and you cannot enter share quantities, cost basis, or brokerage transactions.

Usage and device data: Server and application logs, device model and operating system, app version, IP address, push notification tokens, records of your interactions with the app, and technical measurements about those interactions — how long a request took, and whether it failed. Collected automatically as you use the Service. We do not embed a third-party crash-reporting or performance-monitoring service in the app.

Cookies and browser storage: A few small files your browser keeps for us. We use them to count visits, to remember which link brought you to us, and to remember whether you chose light or dark mode. When we record where you came from, we keep only the name of the website — never the full address — so whatever you searched for, or were reading at the time, stays private. We read that one once, when you create an account, to remember which channel introduced you to us. None of this is advertising. We do not sell or share it, and no other company's cookies run on our site. You can block or delete all of it in your browser settings; the Service will still work, our usage numbers just become less accurate.

Communications: Anything you send us when you contact support, including diagnostic information you choose to attach to a support request.

2. How We Use Information

  • To provide, maintain, secure, and improve the Service.
  • To generate market analysis, alerts, and answers in response to your requests.
  • To send notifications and alerts you have configured or opted into.
  • To prevent fraud and abuse.
  • To respond to support requests.
  • To understand how the Service is used, so we can fix what is broken and decide what to build next. This product analytics data is linked to your account through an internal account identifier. We do not put your name, email address, or profile picture into it.
  • To comply with legal obligations.

We do not sell your personal data, and we do not use it for third-party advertising.

3. AI Processing

Theo, our AI assistant, is powered by large language models operated by third-party providers. This section explains exactly what leaves our systems when you use it.

Where AI is used. In the Theo chat, and in the AI-written insights shown alongside market data in the app.

What we send. For a chat message: the question you typed, as written, together with the earlier messages in that conversation. For a written insight: the stock symbol and the market data already shown on that screen. In both cases we also send a short-lived credential that identifies your HeyTheo account.

Why a credential is sent. Theo can look things up in your HeyTheo account while it answers — your watchlist, the symbols you have marked as owned, your baskets and strategies, your alerts, and your ideas. To do this, the provider's systems call our servers on your behalf using that credential, and whatever Theo retrieves becomes part of the conversation the provider processes. The credential is short-lived and is used only to authorise those lookups.

What we do not send. We do not send your payment information, and we do not send your profile details for a provider to use. The credential described above is an access key rather than profile data — it exists only so Theo can read the information you have built in the app.

Who we send it to. We use the commercial APIs of xAI, Anthropic, OpenAI, and Google. We route requests among these providers based on availability, capability, and cost, so any individual request may be handled by any one of them. Each provider handles what it receives under its own terms, which may involve its own retrieval and search systems. We will update this Policy and ask for your consent again before adding a provider outside this list.

Your questions are sent as written. Because we transmit the text of your question without modification, please do not include personal, financial, or sensitive details in what you type. We cannot filter information you choose to enter.

Provider data handling. We access these services through their commercial API offerings. Each provider's own terms govern how it handles data submitted through its API, including whether that data may be used to improve its models and how long it is retained. We select and configure these services with the intent that your data is not used to train third-party models and is not retained longer than necessary to return a response, and where a provider offers a setting to disable retention of conversation content we enable it. We use these services under their commercial API terms, which are not the same as the consumer terms that apply when you use a provider's own chatbot — commercial API data is generally excluded from model training by default. Each provider's terms, not this Policy, govern what it does with what it receives, so we encourage you to review them directly.

Your choice. We ask for your permission in the app before sending anything to an AI provider for the first time, and we do not send any data unless you agree. You can withdraw permission at any time in Settings → AI processing. Withdrawing permission disables Theo but leaves the rest of the Service — watchlists, alerts, ideas, screening, and backtesting — fully available to you.

4. Sharing of Information

We do not sell or rent personal data. We share it only with:

AI providers: As described in Section 3.

Infrastructure and service providers: Cloud hosting and storage, authentication, push notification delivery, market data providers, analytics, and customer support tooling. These vendors process data on our behalf and are permitted to use it only to provide services to us.

Legal and safety: Where required by law, legal process, or a governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of HeyTheo, our users, or the public.

Business transfers: If HeyTheo is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy, and you will have the opportunity to delete your account first — if you do, your data is deleted rather than transferred.

5. Data Security

We maintain technical and organizational measures designed to protect your information against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit, role-based access controls, and logging of access to production systems. We review these measures periodically and update them as our services change.

You are responsible for maintaining the confidentiality of your account credentials and for any activity that occurs under your account. Please notify us at support@heytheo.io if you believe your account has been compromised.

No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect your information, we cannot guarantee its absolute security.

6. Data Retention and Deletion

We retain your data for as long as your account is active and thereafter only as needed for legal, compliance, fraud-prevention, or other legitimate business purposes.

You can delete your account at any time from Settings in the app. Submitting the request starts a seven-day grace period, during which you can reverse it and keep your account. Once the seven days pass, we delete your account and the data associated with it.

You can also request deletion by email. Write to support@heytheo.io with the subject line “Data Deletion Request,” including the email address on your account so we can verify your identity. We will delete all personal data associated with your account within 30 days of a valid request, except where retention is legally required.

Note that questions previously sent to an AI provider may persist in that provider's systems for the period stated in its own terms, outside our control. We cannot delete them from a provider's systems on your behalf.

7. Your Rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. Residents of the EEA and UK have these rights under GDPR; residents of California have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. Contact us at support@heytheo.io to exercise any of these rights.

8. Children's Privacy

The Service is not directed at, and may not be used by, anyone under 18. We do not knowingly collect data from children. If we learn we have collected data from a child, we will delete it.

To enforce this, the app asks your device's app store whether the account using it is an adult, through the age-range signals Apple and Google provide. We receive an age range at most — never a date of birth — we use it only to decide whether to allow access, and we do not store it. Where the signal indicates a minor, the app blocks access and switches analytics collection off for that session entirely, so no record is kept that the device belongs to a minor.

9. International Users

We operate in the United States, and your data will be transferred to, stored in, and processed in the United States and in other jurisdictions where our service providers operate. These jurisdictions may have data protection laws that differ from those in your country.

10. Changes to This Policy

We may update this Policy. If we make a material change — including adding a new category of data we send to AI providers, or adding a provider outside the list in Section 3 — we will update the “Last Updated” date and ask for your permission again inside the app before the change takes effect for you.

11. Contact

HeyTheo, Inc. — support@heytheo.io