THEMYS LEGAL
Privacy, clearly stated.
These policies apply to Themys at themys.ca, its web app, APIs, documentation, and monitoring email service. The planned browser extension is coming soon and is not currently available. Effective and last updated August 10, 2026.
These policies are a plain-language product disclosure, not legal advice. They must be reviewed by qualified counsel before launch and before being relied on for a particular jurisdiction or use case.
Privacy Policy
Themys ("Themys", "we", "us", or "our") operates the Service. We are currently using Themys as the operating name rather than stating that a corporation or other incorporated entity exists. Our privacy contact is admin@themys.ca. This policy describes personal information and document content processed when you use the Service.
Information we collect
- Account and profile data: name, email address, Clerk account and session identifiers, country or state, target-clause preferences, strict-mode preference, and sign-up attribution such as UTM campaign values.
- Document and product data: public URLs you submit, text retrieved from those URLs, text submitted through the API, scan results, quoted clauses, explanations, structured extraction, history, monitoring subscriptions, snapshots, alerts, and notification state. The web app currently accepts URL scans; the API can also accept text supplied by an authorized caller.
- Billing data: plan, subscription and entitlement state, credits, Stripe customer/subscription/invoice/payment references, amounts, currency, and billing status. Themys does not receive or store full payment-card numbers.
- Operational and support data: IP address and user-agent information used for rate limits and abuse prevention, request paths and timing, security events, documentation feedback, and support correspondence.
- Measurement data: first-party page-view and product-funnel events. Anonymous events use a one-way hash of the request IP and user-agent rather than storing that fingerprint in the usage-events table as plaintext. We do not currently use a third-party advertising or cross-site analytics SDK.
Cookies and similar storage
Clerk uses cookies or related browser storage to maintain authentication. The web app may set short first-party attribution cookies when a landing-page URL contains UTM parameters. These are used to connect a later sign-up with the referring campaign. You can block non-essential cookies in your browser, but blocking authentication storage can prevent sign-in and account features from working.
How we use information
- Authenticate accounts, maintain sessions, and provide scans, results, history, APIs, monitoring, and email alerts.
- Retrieve public documents, detect document identity, compare monitoring snapshots, and generate source-grounded explanations and review guidance.
- Process subscriptions and credit purchases, calculate plan limits, prevent abuse, and reconcile usage.
- Secure, debug, measure, maintain, and improve the Service, including reliability and conversion measurement.
- Comply with law, enforce our Terms, respond to requests, and protect Themys, users, and third parties.
Service providers and international processing
We use processors and infrastructure providers to deliver the Service. They receive only the information needed for their role, but their own terms and privacy policies also apply. Processing may occur in Canada, the United States, or other countries in which a provider operates.
| Provider | Role | Examples of data |
|---|---|---|
| Clerk | Authentication and account management | Account email, name, account/session identifiers, and authentication metadata |
| Cloudflare D1 | Relational database for user-owned application records | Profiles, scan findings, monitoring records, API-key metadata, usage events, and billing references |
| Cloudflare R2 | Private object storage for raw extracted scan text | Raw document text addressed by an opaque server-side object key; objects are not publicly addressable |
| Cloudflare Workers and KV | Application hosting, request processing, caching, network security, and the private monitoring-email Worker | Requests, cached public-document text and analysis, alert email contents, recipient and sender addresses |
| Stripe | Checkout, subscriptions, credits, invoices, and payment processing | Email, customer/subscription/payment references, amounts, currency, and billing status; card data is handled by Stripe |
| OpenRouter and selected model providers | Automated analysis and extraction, restricted by the application to endpoints that advertise zero data retention | The document text and analysis instructions needed to return structured results, plus routing and usage metadata |
| Jina Reader | Public-page text extraction when configured | The submitted public URL; Jina fetches the page and returns its content |
| ToS;DR | Optional public reference data used to supplement a scan | The service domain or ToS;DR identifier; no Themys account data or submitted document text |
| Google favicon service | Display service icons in the web app and planned extension | The public service domain, IP address, and ordinary browser request information such as user agent |
| Sentry | Error and performance monitoring | Scrubbed error, route, timing, and stack information; request bodies, auth headers, emails, and user identifiers are removed before sending |
AI and model-provider processing
Themys sends document text for automated analysis and extraction through OpenRouter and may use different models over time. The application requests zero-data-retention (ZDR) routing for every model request, which limits routing to model-provider endpoints that advertise that they will not retain request content. OpenRouter may still process account, routing, and usage metadata under its own policy, and its account-level logging settings are separate from downstream-provider routing. Provider terms, locations, and technical practices can change, so this is not a promise that every intermediary retains no metadata. Themys does not use your documents to train its own model. Do not submit confidential, sensitive, regulated, or third-party personal information unless you have authority and have assessed the provider terms and settings that apply to your request.
Retention, deletion, and caches
- Account scan metadata, clauses, explanations, and structured extraction remain in Cloudflare D1 until the scan or account is deleted. Raw extracted text is kept in a private Cloudflare R2 object linked from the scan row. A scan deletion removes it from the user-facing history using the current soft-delete workflow; the underlying record may remain for operational cleanup.
- Monitoring subscriptions, snapshots, and alerts remain while the subscription is active. Removing a subscription or deleting the account cascades through those user-owned monitoring records.
- Public-page text cached in Cloudflare KV has a seven-day TTL, and cached scan analysis has a thirty-day TTL. The shared D1 explanation cache is reused only during its thirty-day validity period; an expired cache row can remain until operational cleanup. These content-addressed caches are not an account archive and may expire independently of account deletion.
- Usage, security, error, and payment records are retained for as long as reasonably necessary for accounting, fraud prevention, service security, dispute resolution, and legal obligations. Anonymous usage-event rows use a hashed actor value and are not a user-facing history.
- Deleting an account from Settings cancels an active Stripe subscription before removing the Clerk identity and user-owned application rows, including profiles, scans, monitoring data, API keys, usage logs, credits, and application invoice rows. Stripe and other independent providers may retain records under their own legal and operational retention policies.
Security and disclosures
We use access controls, server-side secrets, encrypted transport, server-side ownership predicates, request validation, rate limits, and redaction before error telemetry is sent. No online service is completely secure. We may disclose information to providers listed above, when required by law or legal process, to investigate abuse or protect rights and safety, in a business transfer, or at your direction. We do not sell personal information or share it for cross-context behavioural advertising.
Your choices and rights
You can review or delete scans, disable monitoring email notifications per document, cancel subscriptions, and delete your account from the available product settings. Subject to applicable law, you may ask us to access, correct, or delete personal information by emailing admin@themys.ca from your account email address. We may need to verify identity and may retain information required for legal, security, fraud-prevention, or accounting reasons. Canadian residents may have rights under PIPEDA and applicable provincial law; US residents may have additional state-law rights, including access, correction, deletion, and non-discrimination rights where applicable. We do not sell or share personal information as defined by California law. You may complain to the privacy regulator with jurisdiction over you.
Children and changes
The Service is not directed to children under 13, and we do not knowingly collect information from children under 13. We may update this policy when the Service, providers, or law changes. We will update the effective date and provide any notice required by law.
Terms of Service
These Terms govern your use of Themys, themys.ca, its APIs, documentation, monitoring email service, and any future browser extension. The extension is coming soon and is not currently available. By using the Service, you agree to these Terms and the Privacy Policy. If you do not agree, do not use the Service.
The Service is not legal advice
Themys uses automated rules and artificial-intelligence systems to produce summaries, attention levels, extractions, comparisons, and flagged clauses. The output is informational review guidance only. It is not legal advice, a legal opinion, a risk determination, or a substitute for reading the original document or consulting a qualified lawyer. Automated output can be incomplete, outdated, or wrong. You are responsible for checking quoted text against the source and making your own decisions.
Accounts and permitted use
Provide accurate account information, protect your credentials and API keys, and promptly report unauthorized access. Use the Service lawfully and only with URLs, text, and data you are authorized to submit. Do not submit confidential or sensitive information unless you have assessed the risks; the Service is designed primarily for public-facing legal documents. Do not bypass authentication, rate or plan limits, or security controls; interfere with the Service; abuse public-page retrieval; reverse engineer or copy it except as permitted by law; or resell or share access without written permission. We may suspend or terminate access to protect the Service, users, or third parties, or for a breach of these Terms.
Your content and AI processing
You retain rights you hold in submitted content. You grant Themys a limited, non-exclusive right to host, copy, transmit, retrieve, transform, and process it only to provide, secure, measure, and improve the Service and to send requested monitoring alerts. This includes sending document text and instructions to the third-party processors described in the Privacy Policy. You are responsible for having the rights and permissions needed for any URL or text you submit and for activity under your account or API key.
Monitoring and notifications
Monitoring checks public URLs on the frequency shown in the product. A change may create an in-app alert and, for eligible plans with notifications enabled, an email. Retrieval failures, source changes, model failures, provider outages, filtering, and delivery delays can prevent or delay an alert. Email notifications can be disabled per monitored document, and the alert email links back to the Monitoring page; the Service is not an emergency or legal-notice system.
Payments, cancellation, and credits
Prices, billing intervals, taxes, renewal, and applicable cancellation terms are shown before checkout. Stripe processes payments. Recurring subscriptions renew unless cancelled before the next billing period; cancellation in Settings normally takes effect at the end of the current paid period. Credit packs and expiry terms are shown at checkout and in the product. Refunds are governed by the checkout terms and applicable consumer law. Deleting an account does not replace cancellation, so cancel an active subscription before deletion; the account workflow will also attempt to stop billing before removing the account.
Ownership, availability, and liability
Themys and its licensors own the Service, software, design, documentation, and branding. Subject to these Terms, you receive a limited, revocable, non-transferable right to use the Service for its intended purpose. The Service is provided “as is” and “as available” to the fullest extent permitted by law. We do not guarantee uninterrupted, secure, error-free, accurate, complete, or continuously available Service or analysis. To the fullest extent permitted by law, Themys is not liable for indirect, incidental, special, consequential, punitive, or reliance losses arising from the Service. Nothing in these Terms excludes liability or consumer rights that cannot legally be excluded.
Changes, termination, and contact
We may change the Service or these Terms when reasonably necessary. We will post the updated effective date and provide additional notice for material changes where required. You may stop using the Service and request deletion at any time. Sections that by their nature should survive termination, including ownership, disclaimers, payment obligations, limitations, and dispute-related terms, survive. Questions about these Terms or the Privacy Policy: admin@themys.ca.