Privacy Policy
Last updated: August 5, 2026
TheoStack is a theological research service: an AI assistant that answers questions over a curated library of theological texts and over documents you upload to your own personal library. This policy explains what information we collect, why we collect it, who processes it on our behalf, how long we keep it, and the choices you have.
1. Who we are
TheoStack is operated by Lordhill Digital, LLC, a Wyoming limited liability company (“Lordhill Digital”, “we”, “us”, “our”). Lordhill Digital is the controller of the personal information described in this policy. You can reach us at legal@theostack.com.
This policy covers the TheoStack website and application (the “Service”). It does not cover third-party sites we link to, which have their own privacy policies.
2. Information we collect
Account information
When you create an account we collect your email address and your name. If you sign up with an email and password, we store a one-way cryptographic hash of your password — never the password itself. If you sign in with Google or Apple, we receive your name, email address, and a provider account identifier from that provider; we never receive your Google or Apple password. We also store account state such as email-verification status, your plan, and any referral or redemption code associated with your account.
Content you provide
We store the content you create or upload in the Service, including your chat messages and conversations, documents you upload, personal-library files and the text extracted from them, project instructions, and any titles, notes, or metadata you add. Text extracted from your uploads is also converted into numeric embeddings so the assistant can retrieve relevant passages when you ask a question.
If you dictate a message using the microphone, your voice is streamed to our transcription provider and turned into text as you speak. We do not store the recording — it is not saved on our servers, and nothing is kept once the transcript comes back. Only the text that ends up in the message box, and only if you choose to send it, is stored as a message like any other.
Payment information
Payments are handled by Stripe. We never receive or store your card number, CVC, or full bank details. We store the identifiers and status Stripe gives us — customer and subscription IDs, plan, trial and renewal dates, invoice history, and the outcome of payments — so we can manage your subscription and show your billing history.
Technical information
Our servers automatically record technical data when you use the Service: your IP address, browser and device information, request paths and timestamps, and other server log data. We use this for security, abuse prevention, rate limiting, and debugging. When something breaks, an error report is sent to our error monitoring provider; those reports are scrubbed of personal information before they leave your browser or our servers, and error monitoring sets no cookies.
Analytics information
If — and only if — you accept analytics in our cookie banner, we collect product analytics: pages viewed, features used, and a small number of product events (for example, when a subscription activates or a payment fails). Analytics never loads before you consent. See our Cookie Policy for the full list of cookies.
3. How we use your information
- To provide the Service — authenticate you, keep you signed in, run chat conversations, and perform retrieval over the curated library and your personal library so answers cite relevant passages.
- To process your uploads — extract text from files, run optical character recognition (OCR) on scanned documents, generate document metadata such as title and summary, and index the text for search.
- To manage your account — send transactional email such as email verification, password resets, referral invitations, and billing notices.
- To handle billing — start and manage trials and subscriptions, apply redemption codes, meter usage against your plan allowance, and process payments through Stripe.
- To keep the Service secure and reliable — detect and prevent abuse, fraud, and unauthorized access; enforce usage limits; diagnose and fix errors.
- To understand and improve the product — consent-gated analytics only.
- To comply with law — meet tax, accounting, and other legal obligations, and respond to lawful requests.
We do not sell your personal information, and we do not use your chat messages or uploaded documents to train AI models.
4. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service you signed up for, and billing); legitimate interests (security, abuse prevention, service reliability, and defending legal claims); consent (product analytics, which you may withdraw at any time); and legal obligation (tax and accounting records).
5. AI processing of your content
To answer a question, we send the relevant parts of your conversation — and the passages retrieved from the curated library or your personal library — to Anthropic, which runs the model that generates the response. Scanned documents are sent to Google Document AI for OCR. These providers process that content as our service providers, under contract, solely to return a result to us. Content sent through Anthropic’s commercial API is not used to train Anthropic’s models.
6. Where your information lives (processors)
We use a small set of service providers (“processors”) to run TheoStack. Each is bound by contract to process data only on our instructions.
| Provider | What it does for us | Data involved |
|---|---|---|
| Google Cloud | Backend application hosting, database, file storage, and Document AI OCR for scanned uploads | Account data, chat content, uploaded documents, logs |
| Vercel | Web application hosting and content delivery | Requests, IP address, technical logs |
| Anthropic | The AI model that generates chat responses | Chat messages and retrieved passages sent with them |
| OpenAI | Turns text into the numeric embeddings that make search and retrieval work | Text extracted from your documents, and the questions you search with |
| Deepgram | Speech-to-text for the microphone in the message box | The audio you record while dictating, and the transcript made from it — sent only while the microphone is on. We opt out of Deepgram using it to train their models, so it is kept only for as long as it takes to transcribe. |
| Qdrant (managed hosting) | Vector search index used for retrieval | Text excerpts and embeddings from library and personal documents |
| Stripe | Payment processing and subscription management | Name, email, billing details, and card data you enter directly with Stripe (we never hold card numbers) |
| Sentry | Error reporting and diagnostics | Scrubbed error reports and technical context — no cookies |
| PostHog | Product analytics — only after you consent | Usage events, page views, an analytics identifier |
| Resend | Transactional email delivery | Email address, name, and message content of the email |
| Betterstack | Uptime monitoring and our public status page (status.theostack.com) | Service availability data — no user content |
| Cloudflare | Bot protection (Turnstile) on sign-up and account-recovery forms | Browser and device signals used to compute a bot-risk score — cookieless, no message or document content |
7. Sharing your information
We do not sell or rent your personal information, and we do not share it for cross-context behavioural advertising. We disclose information only:
- to the processors listed above, so they can perform their function;
- when you choose to share it — for example, creating a public share link for a conversation makes that conversation viewable by anyone who has the link, until you revoke it;
- when required by law, legal process, or a lawful government request, or to protect the rights, safety, and property of Lordhill Digital, our users, or the public;
- in connection with a merger, acquisition, or sale of assets — in which case we will notify you and this policy will continue to apply to the transferred information.
8. How long we keep it
- Account and content data — kept until you delete it or close your account. You can delete individual conversations and documents at any time in the app.
- Server logs and error reports — kept for a limited period, generally no more than 90 days, and then discarded.
- Billing records — kept for as long as required by tax and accounting law, even after account closure.
- Backups — deleted content may persist in encrypted backups for a short period before being overwritten on the normal backup rotation.
Deleting your account: you can delete your account yourself in Settings → Account. Deletion is scheduled immediately — your account is disabled right away, and erasure of your account data completes after a 30-day recovery window, except records we are legally required to keep. If you change your mind, simply sign in again before the window ends — that cancels the scheduled deletion and restores your account. If you cannot sign in, email legal@theostack.com before the window ends. Deleting your account also cancels any active subscription.
9. Your rights and choices
Depending on where you live, you have the right to:
- Access a copy of the personal information we hold about you;
- Correct information that is inaccurate — you can edit your name and email in Settings;
- Delete your content or your whole account;
- Take your data elsewhere — download a copy of your account data and content yourself at any time in Settings → Account, or email legal@theostack.com and we will assemble one for you;
- Withdraw consent to analytics at any time via the Cookie settings link in the footer and in Settings — this stops analytics immediately and clears the analytics cookies;
- Object to or restrict certain processing, and not be discriminated against for exercising any of these rights.
To exercise any of these rights, email legal@theostack.com. We may need to verify your identity — normally by confirming you control the account email. If you are in the EEA or UK and are unhappy with our response, you may complain to your local data protection authority.
10. International transfers
Lordhill Digital operates in the United States, and your information is processed and stored in the United States by us and by the processors listed above. If you use TheoStack from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. Where required for transfers from the EEA or UK, we and our processors rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) as the transfer mechanism.
11. Security
We protect your information with encryption in transit (HTTPS), strong one-way password hashing, scoped access controls, short-lived session tokens, and isolation of each user’s personal library so it is retrievable only by that user. Card data never touches our servers. No system is perfectly secure, but if a breach affects your personal information we will notify you and any relevant regulator as required by law.
12. Children
TheoStack is not directed to children. You must be at least 13 years old (16 in the EEA and UK) to create an account. We do not knowingly collect personal information from children under those ages; if we learn that we have, we will delete it. Contact legal@theostack.com if you believe a child has created an account.
13. Changes to this policy
We may update this policy as the Service changes. We will revise the “Last updated” date above, and for material changes we will notify you by email or in the app before the change takes effect. Continuing to use the Service after a change means you accept the updated policy.
14. Contact us
Lordhill Digital, LLC (TheoStack)
Email: legal@theostack.com
For copyright complaints, see our Copyright / DMCA policy. For the cookies we set, see our Cookie Policy.