What data we collect
When you use Themis, we collect the following categories of data:
- Authentication data — your email address and, if you sign in with Google, your Google profile information (name, profile picture, Google account ID).
- Conversation content — the messages you send and receive, and any documents you upload during a session.
- IP-derived approximate location — we derive a general geographic region (e.g., state or city) from your IP address to comply with applicable law and improve relevance. We do not store your precise IP address beyond what is necessary for security logging.
- Device type and browser information — the type of device you are using (mobile, desktop, tablet), your operating system, and your browser version. This is collected automatically when you visit the platform.
How we use your data
- To provide and operate the Themis legal awareness service.
- To generate responses to your queries using our AI system.
- To improve response quality and platform reliability over time.
- To enforce usage limits and prevent misuse.
- To send you authentication emails (magic links, confirmations).
- To comply with applicable Indian law, including the DPDP Act, 2023.
We do not sell your data. We do not use your data for advertising.
Data processors
We share data with the following third-party processors to operate the service:
- OpenAI— your conversation content (the messages you send) is transmitted to OpenAI's API to generate responses. OpenAI processes this data as a data processor on our behalf. OpenAI's data handling is governed by their API usage policies. We do not use OpenAI's consumer products for this purpose; API data is subject to separate, more restrictive terms.
- Supabase— authentication and database services. Your account data and conversation history are stored in Supabase's managed cloud database, hosted in the Mumbai region (ap-south-1), India.
Data storage
All user data is stored in Supabase's cloud database in the Mumbai, India region (ap-south-1). Conversations are tied to your account and are not accessible to other users.
Data retention
Conversations are stored until you delete them. You can delete individual conversations at any time from the interface.
If you delete your account, all associated data — including your profile, conversation history, and uploaded documents — is permanently deleted within 30 days.
Your rights under the DPDP Act, 2023
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), you have the following rights as a data principal:
- Right to access — you have the right to obtain a summary of the personal data we hold about you and the purposes for which it is processed.
- Right to correction — you have the right to correct inaccurate or incomplete personal data we hold about you.
- Right to erasure — you have the right to request deletion of your personal data, subject to any legal obligations that require us to retain it.
- Right to grievance redressal — you have the right to a prompt and effective response to grievances about the processing of your personal data.
- Right to nominate — you have the right to nominate another individual who may exercise your rights in the event of your death or incapacity.
To exercise any of these rights, contact us at the address below. We will respond within the timeframes required by the DPDP Act.
If you are not satisfied with our response, you may approach the Data Protection Board of India once it is constituted under the DPDP Act, 2023.
Cookies
We use authentication cookies to keep you signed in across sessions. These cookies are strictly necessary for the service to function.
We do not use third-party tracking cookies. We do not use cookies for advertising or cross-site tracking.
Contact
For privacy concerns, data requests, or grievances, contact us at: [privacy contact email to be added]
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "Last updated" date. Continued use of the platform after changes are posted constitutes your acceptance of the updated policy.