Back to home

Last updated: September 4, 2026

Privacy Policy

AI Theresa (“we”, “us”, or “our”) operates this website (aitheresa.ai) and the Theresa AI service (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

By using our website or the Service, you agree to the practices described here.

1. Who We Are

Theresa AI is a service that helps companies become AI-native by observing approved work tools, identifying the highest-cost workflow leaks, and shipping production automation. We are operated by AI Theresa (the “Company”), a Delaware company.

2. Information We Collect

2.1 When You Visit This Website

When you visit aitheresa.ai we automatically receive standard server logs from our hosting provider (Cloudflare), including your IP address, browser type, referring URL, and the pages you access.

2.2 When You Submit the “Get a Demo” Form

When you fill out the demo request form, we collect:

We store this information solely to follow up with you about your demo request and, with your continued engagement, related sales communications.

2.3 When You Become a Theresa AI Customer

If your company contracts with us to deploy the Service, we collect information through the Theresa AI desktop client and backend integrations. This is governed by a separate Data Processing Addendum signed with each customer. At a high level, Theresa AI:

For details, see our customer Data Processing Addendum or contact [email protected].

3. How We Use Information

We use the information we collect to:

We do not sell personal information. We do not use customer data to train third-party or shared AI models. Workflow memory derived from customer observation is used solely to inform that customer’s own automations.

4. How We Share Information

We share information only with:

We do not share customer observation data across customers; each customer’s data remains in org-level isolation.

5. Data Security

We take commercially reasonable steps to protect information from unauthorized access, alteration, disclosure, or destruction. These include:

No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you within a reasonable timeframe in accordance with applicable law.

6. Data Retention

7. Your Choices and Rights

Depending on your jurisdiction, you may have rights to:

To exercise these rights, email [email protected]. We respond within 30 days.

EEA/UK residents (GDPR): the legal bases for our processing are (i) consent (demo requests), (ii) legitimate interests (operating and improving the Service), and (iii) contractual necessity (delivering the Service to customer companies). The Company is the data controller for the website and a data processor for customer observation data.

California residents (CCPA/CPRA): we do not sell or “share” personal information for cross-context behavioral advertising. You have the right to know, delete, correct, and limit certain uses, as described above.

8. Cookies and Tracking

This website uses two third-party analytics services. Google Analytics 4 tells us how visitors find and move through the site. Factors.ai performs B2B company identification: it looks up a visitor’s IP address against a business database to match otherwise anonymous traffic to a company. Between them they set three cookies in your browser:

Company identification means your IP address is sent to Factors.ai, which looks it up against its company database. We use the result only at the company level, to see which organizations reach the site.

We may also use a first-party preference cookie (e.g. language).

We do not currently offer a cookie banner or an on-site opt-out. You can block or delete cookies, including these, through your browser settings.

9. International Data Transfers

Our infrastructure is hosted in the United States by default. EU/UK customers may, on request, deploy under EU data residency in accordance with their DPA. For website visitors, processing occurs in the U.S. and visitors consent to such transfer by using this site.

10. Children’s Privacy

The Service and this website are not directed to anyone under the age of 16. We do not knowingly collect personal information from children. If we learn we have done so, we delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date. Material changes will be communicated by email to active customers and demo-request contacts.

12. Contact Us

Questions about this Privacy Policy or our data practices?

Email: [email protected]
Subject line: Privacy Inquiry