Last updated 11 September 2026

Privacy policy

Theode reads the meetings, emails and documents an architecture project already produces, and keeps one current record of what the client wants. This page says what that means for a mailbox you connect: what Theode reads, what it stores, who can see it, and how to stop it.

Who we are

Theode is a project-record tool for architecture practices. Write to hello@theode.ai with any question about this policy, or to ask for your data to be deleted.

Theode is operated by [legal entity name], [registered address].

What Theode asks for, and nothing beyond it

When you connect a Google mailbox, Theode asks Google for one permission: read-only access to your mail (gmail.readonly). Google words it on its own consent screen as “View your email messages and settings”.

Read-only is the whole of it. Through a connected mailbox Theode never sends a message, never deletes one, never replies, never changes a label and never alters a setting. It cannot: the separate permissions Google requires for any of that are not requested, so Google itself would refuse the attempt.

You can instead forward mail to a private Theode address and connect nothing at all. That route exists so that granting a mail permission is a choice rather than a condition of using Theode.

If you choose forwarding, there is one thing Theode does on your behalf: Gmail will not forward to a new address until the address confirms it wants the mail, and it asks by emailing a one-time link there. Theode answers that link, because Theode owns the address being asked. It checks first that the request came from the mailbox you told us about, so nobody who merely learns your Theode address can point their own mailbox at it. Nothing else in your Gmail settings is touched.

What Theode stores

A message Theode files against one of your projects is stored as a source on that project, with its permitted attachments. Sources are what the project record cites, so they are kept for as long as the project is in Theode.

An attachment of a type Theode has no reader for is not stored: its contents are never written anywhere. Theode's own operators can see which kinds of file were skipped, so that the list of readable types can be widened; that record is the file's declared type and nothing from inside it.

Everything runs in one Amazon Web Services account in the us-east-1 region, on AWS-managed services. There is no server we operate that holds your mail, and no other company holds it on our behalf.

No one at Theode reads your mail

Nobody at Theode reads the body of a message in a connected mailbox, with three exceptions: to investigate a security problem or abuse, to comply with a legal obligation, or because you have asked us to and said so explicitly.

This is built in rather than promised. No log entry, metric or alert Theode writes may carry a subject, a body, a snippet or a participant’s address — identifiers and counts only. That rule is checked against every logging line in the mail code on every build, rather than only against the paths a test happens to run, because one debug line added later is exactly how a rule like this breaks quietly.

How the AI part works

Theode uses AI models to read a message and work out which project it belongs to and what it says about the brief. Those models run on Amazon Bedrock inside Theode’s own AWS account.

Your mail is not sent to a third-party AI service, and it is not used to train anyone’s model — not ours, not a model provider’s.

Theode does not sell your data, does not share it for advertising, and does not transfer it to anyone for their own purposes.

The key to your mailbox

Connecting a mailbox gives Theode a token from Google that lets it keep reading. That token is held in AWS Secrets Manager, under a name specific to your practice and to that one connection. The record of your connection holds the name of the secret and never the token itself, so the token is not in any backup, export or log of that record.

Disconnecting deletes the token and the connection record together. There is no dormant key left behind.

Stopping it, and deleting what was read

Two separate things, and the difference matters.

To stop Theode reading your mail, disconnect the mailbox in Theode, or revoke Theode’s access directly at myaccount.google.com/permissions. Either works on its own and stops the reading straight away. Theode then marks that connection as no longer working, and says so where you set it up. Nothing else about the project breaks: the record keeps the sources it already has and stays readable.

Messages already filed against a project stay after you disconnect. They are the evidence the project record cites, and removing them would leave the record asserting things with nothing behind them. To have them deleted as well, write to hello@theode.ai and say so, and we will delete them and tell you when it is done.

Google’s own rules about this

Theode’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Changes to this policy

The date at the top of this page changes when this policy does. If a change affects what Theode reads or who can see it, we will tell connected users rather than relying on you to re-read the page.

Back to Theode