1. Scope and roles
This Privacy Policy applies to the public website at www.threep.ai, the hosted workspace at app.threep.ai, our contact form, and related support and account interactions operated by threep LLC (“threep,” “we,” “us,” or “our”).
For information such as website inquiries, account administration, billing, security, and service operations, threep determines why and how the information is used. For documents and other content an organization puts in its workspace, threep generally processes that content on the organization’s behalf. A separate order form, data processing agreement, or other written agreement may add to or override this policy for that customer.
Plain-English boundary: your organization controls what it uploads and who may use its workspace. threep uses that content to provide the service—not to make business, legal, audit, or certification decisions for you.
2. Information we collect
Public website and inquiries
If you submit the contact form, we collect the name, work email, organization (if provided), type of inquiry, message, page and call-to-action source, consent choice and version, and submission timestamps. We also keep the inquiry’s delivery status so we can tell whether the notification reached our team.
Accounts, teams, and subscriptions
We collect account email, display name (if provided), a one-way password hash for password-based accounts, organization or workspace identifiers, team role and membership, invitation information, plan and usage limits, and account activity. If you use a paid plan, we store Stripe customer and subscription identifiers, plan status, and billing-event records. Stripe—not threep—collects and processes full payment-card details through its hosted checkout.
Customer content and service activity
Depending on how you use threep, we process:
- security and compliance policies, plans, procedures, questionnaires, and other files you upload;
- document names, types, sizes, extracted text, indexed excerpts, and generated embeddings;
- questions, prompts, retrieved evidence, generated answers, citations, flags, reviewer decisions, revisions, and approval history;
- assessments, scheduled runs, delivery configuration, results, exported artifacts, and usage counters; and
- audit events used to preserve service, security, billing, and review history.
Technical information
Our systems and hosting providers may record IP address, request time, route or page requested, response status, error details, and similar network and application information. We use this information for security, rate limiting, reliability, support, and incident investigation. We do not need the contents of a contact message in our access logs; the inquiry itself is stored in the inquiry system.
3. How we use information
We use information to:
- operate, secure, maintain, and improve the website and service;
- create accounts, enforce workspace roles, and support team collaboration;
- ingest customer documents, retrieve relevant evidence, generate responses, and preserve review history;
- process subscriptions, enforce plan limits, and respond to billing events;
- answer inquiries and support requests without adding contact-form submitters to an unrelated mailing list;
- detect misuse, troubleshoot failures, protect tenant boundaries, and maintain audit records; and
- comply with law, enforce agreements, and protect threep, our customers, and others.
4. AI model processing
threep uses third-party AI infrastructure to generate and review answers. For a typical hosted request, threep sends the user’s question and selected excerpts retrieved from the customer’s workspace—not the entire workspace by default—to a model provider so it can return a response.
As of this policy’s effective date:
- Primary answer path: Featherless AI processes the question and selected evidence using a Qwen model.
- Manual escalation or verifier path: when a user asks threep to review an insufficient-evidence result, OpenRouter may process the question and selected evidence and route it to an Anthropic Claude model.
Model names, routing, and providers may change as the service evolves. If we make a material change to the categories of information sent or the purpose of processing, we will update this policy. Providers process these inputs under their own service terms, privacy practices, and the settings or agreements applicable to threep.
AI outputs require human review. Generated content may be incomplete or wrong. threep is designed to show evidence and preserve reviewer decisions; it does not replace professional judgment.
6. Browser storage, cookies, and analytics
The public site does not currently use advertising cookies or third-party behavioral analytics. It does load Google Fonts as described above.
The hosted app uses browser local storage for necessary sign-in state in password-based deployments and for product preferences. Depending on the features you use, local storage on that device may also contain recent questions and rendered answers, personal follow-up tasks, theme and layout choices, or dismissed-status markers. Other authentication deployments may use necessary session cookies.
Clearing browser storage can sign you out and remove locally saved preferences or history. Because there is no uniform standard for browser “Do Not Track” signals, the site does not respond differently to them. We honor legally required opt-out preference signals where they apply; threep does not currently sell or share personal information for targeted advertising.
7. Retention and deletion
We keep information only as long as reasonably needed for the purposes described here, our agreements, security and audit integrity, dispute resolution, and legal obligations. Retention varies by record:
- Workspace content and account data: generally kept while the account or customer relationship is active and until deleted or no longer needed, subject to contractual, security, and legal requirements.
- Website inquiries: kept while we evaluate and respond to the request and for reasonable business follow-up, unless deletion is requested or a longer period is required for a dispute or legal obligation.
- Operational and audit records: kept as needed for security, reliability, billing, change history, and accountability. Log sources do not all use the same fixed retention period.
- Backups: the current hosted database maintains encrypted automated backups for up to 14 days. Deleted information may remain in a backup until that backup expires and is replaced.
Deleting a workspace may require coordinated deletion across database records, uploaded objects, generated artifacts, and audit evidence. Contact us if you need deletion or an export; we will verify authority and explain what can be deleted, what must be retained, and the expected process.
8. Security
We use administrative, technical, and organizational safeguards appropriate to an early-stage hosted service. Current controls include encrypted HTTPS connections, encryption at rest for primary databases and object storage, tenant-scoped access controls, password hashing, service logging, automated database backups, and restricted infrastructure access.
No system can guarantee absolute security. Do not send passwords, secret keys, full payment-card details, or other unnecessary secrets through the contact form. Unless a separate written agreement expressly allows it, do not upload regulated or highly sensitive data that requires special handling.
9. Your choices and rights
Subject to applicable law and our need to verify your identity and authority, you may ask us to access, correct, export, or delete personal information associated with you. You may also object to or request limits on certain processing where the law provides that right.
If your information belongs to an organization’s workspace, please start with that organization’s workspace owner. threep may need the customer’s instructions before acting on customer-controlled content. We may retain or deny access to information where permitted or required by law, including to protect security, prevent fraud, preserve audit integrity, or resolve disputes.
To make a request, email privacy@threep.ai. We will not discriminate against you for exercising a legally protected privacy right.
10. Transfers, children, and changes
United States processing
threep is based in Texas, and the hosted service is currently operated in the United States. If you access the service from another country, information may be transferred to and processed in the United States.
Children
The service is intended for business users and is not directed to children. You must be at least 18 to create an account or enter into a service agreement. If we learn that a child provided personal information without appropriate authorization, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy as the product, providers, or law changes. We will post the new effective date here. If a change materially affects how existing customer content is used, we will provide additional notice where reasonably practicable or required by law.
11. Contact us
threep LLC
5900 Balcones Dr #32680
Austin, TX 78731
United States
Email: privacy@threep.ai
General inquiries: hello@threep.ai
For security reports, use security@threep.ai.