1.Who we are
THOTH is operated by THOTH STRATEGY TECNOLOGIA LTDA (trading as Thoth Strategy), CNPJ 61.150.242/0001-56, Florianópolis, Santa Catarina, Brazil. This policy covers the THOTH website at thoths.space and the THOTH application.
This policy describes our current practices. It does not claim certification or full compliance with any particular law; an assessment under the EU/UK GDPR has not yet been carried out.
2.Our roles
- For accounts, website, security, billing and our own communications, we decide why and how data is processed (we act as controller).
- For content that customers put in their Workspaces — projects, tasks, time entries, messages, documents — the customer organization generally decides the purposes, and we process it on its behalf to provide the service (we act as operator/processor).
These are preliminary classifications. The actual role can differ for a particular processing operation.
In short: Thoth Strategy is the controller of account, website, inquiry and billing-related data, and processes the content customers place in their workspaces on the customer's behalf. We do not currently offer a separate Data Processing Agreement.
3.Information we process
Account and authentication
- Name, email address and optional profile photo, job title and profile details you enter
- Sign-in identifiers, your password (stored only in hashed form by our authentication service), session tokens and sign-in timestamps
- Your preferences, such as theme and notification settings
Workspace content
- Workspace memberships, roles, teams and invitations (including the invited email address)
- Programs, projects, milestones, features, sprints and tasks, including assignments and dates
- Time entries, labor rates and project budgets and expenses
- Chat messages, direct messages, task discussions and notifications
- Uploaded documents, images and file details such as name, size and type
- Gamification records such as points, levels and badges
Billing
- Plan, subscription status, billing dates and Paddle customer, subscription and transaction references
- Plan and Growth requests
Inquiries
- Beta access and contact requests: name, email, optional company and team size, topic and message
Technical and security
- Records of essential system events, such as email delivery records, data export jobs and operational health checks
- Technical logs kept by our infrastructure providers, which may include IP addresses and browser information
We do not use advertising trackers or third-party analytics in THOTH.
4.Why we use it
- Providing the service and its Workspace collaboration features
- Authenticating users and protecting accounts
- Administering accounts, Workspaces, invitations and permissions
- Managing subscriptions, trials and access stages
- Security, fraud and abuse prevention, and keeping the service reliable
- Answering beta, contact and support requests
- Sending essential service notices (for example security, billing and access changes)
- Sending optional activity notifications you can turn off per Workspace
- Meeting legal, tax and accounting obligations
5.Legal bases
Under the LGPD and, where applicable, other laws, we rely on different legal bases depending on the purpose:
- Performance of a contract — providing your account, Workspaces and subscription.
- Legal or regulatory obligations — tax, accounting and responding to lawful requests.
- Legitimate interests — security, service improvement and essential communications, balanced against your rights.
- Consent — only where the law requires it; you may withdraw consent at any time.
- Regular exercise of rights — in legal or administrative proceedings.
6.Service providers
- Lovable Cloud — application hosting, database, authentication and file storage.
- Lovable Emails — delivery of transactional and operational emails.
- Paddle — checkout, payments, invoicing, tax and refunds as Merchant of Record.
These providers process data only as needed for their services. Paddle also acts independently as a seller under its own privacy terms.
7.Payments
Paddle processes payments for THOTH subscriptions. Card details are entered in Paddle’s checkout; THOTH does not store full card numbers. We keep subscription and transaction references and status information so we can manage access and answer billing questions. See Paddle’s Buyer Terms for its role.
8.Sharing and international transfers
We do not sell personal data. We share it only with the providers above, with other members of a Workspace as the service is designed to do, when required by law, or in connection with a business reorganization subject to this policy.
The providers listed above may process personal data outside Brazil. We have not yet confirmed and documented the specific countries, hosting regions or transfer mechanisms that apply, so we do not list them here. We will update this section, including the information required under Brazilian rules on international data transfers, once it has been verified.
Our service providers may process data outside Brazil. When that happens, we rely on the international transfer mechanisms permitted by the LGPD and the rules of the ANPD.
9.Retention
The application access stages for a Workspace are:
| Stage | What it means |
|---|---|
| Trial | Seven days from Workspace creation. Full access; up to 5 active members and 10 GB of storage. No payment card required. |
| Active paid subscription | Full access during the verified paid period, including after a cancellation is scheduled, until that period ends. |
| Payment grace | Where applicable, if a renewal payment fails, full access continues for a seven-day grace period while payment is retried or updated. |
| Read-only | For the first 90 days after paid access ends, members can sign in and view data but cannot create or change content. Ordinary Workspace exports and Executive Presentation Mode are unavailable. |
| Locked, recoverable | From day 91 through day 180 after paid access ends, the Workspace is locked. Its data is retained and access can be restored with a new subscription. |
| Deletion eligible | After day 180 the Workspace becomes eligible for a retention and deletion review. Automatic permanent deletion is not currently enabled; any future deletion process will be announced in this policy before it applies. |
A payment grace period of seven days may apply after a failed renewal. These stages control access; they are not a schedule for erasing data. Automatic deletion of Workspace data is currently not enabled, and we do not claim that every copy of data is erased after 180 days.
Separately: billing and tax records may be kept as long as the law requires; security and technical logs are kept for limited periods by our providers; database backups age out on our provider’s schedule; completed data-export files are deleted about 24 hours after they finish.
We keep personal data only for as long as needed for the purposes above or as required by law, and then delete or anonymise it.
10.Security
Safeguards currently in place include authenticated access, role-based permissions, separation of each Workspace’s data enforced in the database (row-level security), private file storage with short-lived download links, restricted administrative functions, operational health monitoring, and payment handling through Paddle. No system is perfectly secure, and THOTH does not currently hold security certifications or independent audit reports.
11.Documents and backups
Our infrastructure provider keeps database backups. Uploaded documents and images are stored privately but are not currently backed up independently, so a deleted or lost file may not be recoverable. We do not offer a guaranteed disaster-recovery service. Workspace export files are temporary downloads, deleted about 24 hours after they finish, and are not backups. Please keep your own copies of important documents.
12.Your rights
Subject to applicable law, you may ask us to:
- confirm whether we process your personal data and give you access to it
- correct incomplete, inaccurate or outdated data
- anonymize, block or delete unnecessary or unlawfully processed data
- provide your data in a portable form
- tell you with whom we have shared it
- delete data processed on the basis of consent, and inform you about the consequences of refusing consent
- review decisions taken solely by automated processing
- object to processing where the law allows
If your request concerns content in an organization’s Workspace, we may refer you to that organization, as it controls that content. The Workspace export in Settings is a product feature for Owners and Admins; it is separate from these legal rights. If you make a request to access or port your personal data, we handle it through the contact channel below, including while a Workspace is read-only or locked and ordinary exports are unavailable. You may also complain to Brazil’s data protection authority (ANPD) or your local authority.
13.Cookies and browser storage
THOTH does not set its own cookies. It uses your browser’s storage as follows:
- Local storage — holds your sign-in session so you stay signed in between visits, a pending invitation link while you sign in, and display choices such as list or board view.
- Session storage — holds short-lived values during workspace setup and password recovery; it clears when the browser tab closes.
This storage is necessary for the service to work. Signing out removes the sign-in session. THOTH does not use analytics, advertising or tracking tools. Paddle’s checkout, when you open it, may set its own cookies under Paddle’s policies. If we add analytics in the future, we will update this policy first and ask for consent where required.
14.Communications
THOTH has an email system, but general email sending is not yet switched on. Apart from emails sent by our authentication service (for example password reset links) and limited internal testing, THOTH does not currently send emails to customers.
Once sending is switched on:
- Essential notices about your account, security, billing and Workspace access will be sent when relevant; you cannot opt out of them while you have an account.
- Activity emails (such as assignments, reminders and digests) are optional and follow the choices you make in Settings → Notifications.
We do not send marketing emails.
15.Children
THOTH is a professional tool for businesses and teams. Accounts are only for people aged 18 or older, and the service is not directed to children or adolescents. If we learn that an account belongs to someone under 18, we may close it and delete or anonymize the related account data, subject to legal obligations. A Workspace may still contain information about minors entered by its organization; that organization is responsible for having a valid legal basis for it.
16.Changes
We will post updates here with a new version and effective date, and notify users of material changes.
17.Privacy contact
Send privacy requests using the Contact page and choose “Privacy / Data rights”. We may need to confirm your identity before acting on a request.
Send privacy requests through our Contact page and choose the topic “Privacy / Data rights”. We may ask you to confirm your identity before acting on a request.