Privacy Policy
Last updated July 16, 2026
Overview
This Privacy Policy explains how Them Labs, Inc. (“Them,” “we,” “us,” or “our”) collects, uses, and protects information when you use the Them AI service (the “Service”). Them is a company-brain product that connects your tools, distills their content into governed memory, and exposes approved memory to AI agents under strict permissions.
Privacy and data governance are central to how the Service is designed. Your memory belongs to your workspace and is never served into another one, only content your team has approved is exposed to agents, and every agent key is scoped to what it is allowed to read. This policy describes those practices in detail.
Information we collect
We collect the following categories of information:
- Account information, such as your name, work email, workspace name, and authentication details.
- Content from the sources you connect, such as Notion pages, Confluence pages, a web page you point us at, and files you upload.
- Usage and device data, such as log events, feature interactions, IP address, browser type, and diagnostic information used to operate and improve the Service.
How connectors work and source scoping
You connect a source by supplying an integration token for that tool, or by pointing the Service at a page or uploading a file. Tokens are stored on our servers, are never returned to the browser, and are removed when you delete the connector. You can disconnect any source at any time, and you can revoke the token from the provider as well.
Memory is scoped to your workspace. Members of your workspace read the same approved memory, and what each member may change is controlled by their seat and role: contributing, governing, managing connectors, and managing the team are separate permissions. Agent keys are scoped further. A key issued against a client-scoped feed can read only that client's memory plus your firm's own unassigned memory, and never another client's.
Model processing
To distill sources into memory and to answer questions over it, the Service sends the relevant content to our model provider, Google (Gemini). Content is sent as it appears in the source you connected; we do not currently perform automated redaction of personal information before that call, so please connect only the sources you are comfortable processing this way.
Your content is not used to train our models or the provider's models. Model processing happens only to serve your workspace: distilling a source you connected, answering a question asked inside your workspace, or drafting from memory your team approved.
How we use information
We use the information we collect to:
- Provide, operate, and maintain the Service, including distilling content into governed memory with owners and citations.
- Redact personal information before content is processed by a model.
- Enforce source scoping, permissions, and the audit log.
- Secure the Service, prevent abuse, and troubleshoot problems.
- Improve the Service and develop new features.
- Communicate with you about updates, security notices, and support.
Sharing and subprocessors
We do not sell your personal information. We share information only with service providers that help us operate the Service and that act under contract on our instructions. These subprocessors include cloud hosting providers that store and run the Service and model providers that process redacted content to generate outputs.
Our contracts require these providers to protect the information they handle, to use it only to provide services to us, and not to use it for their own purposes. We may also disclose information if required by law or to protect the rights, safety, and security of Them, our users, or the public.
AI agents and the MCP feed
The Service can expose approved memory to AI agents over an MCP server. Only memory that has been approved is made available through the feed, and each agent is granted per-agent permissions that limit what it can access.
Every access through the feed is recorded in a full audit log, so you can see which agent accessed which memory and when. Nothing acts autonomously: agents draft and surface information, but a human approves any action.
Data retention and deletion
We retain information for as long as your workspace is active or as needed to provide the Service. You can delete any source or your entire workspace at any time. When you do, we remove the associated memory and content from active systems, subject to standard backup cycles and any retention required by law.
Security
We protect information using encryption in transit and at rest, access controls, and monitoring. We design the Service so that personal information is redacted before it reaches a model and access to memory is scoped per member.
The Service is in beta, and our security posture continues to mature. While we work to protect your information, no method of transmission or storage is completely secure, and you should evaluate the Service accordingly before connecting sensitive data.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information. You can exercise many of these rights directly within the Service by managing your sources and workspace, or by contacting us at legal@usethem.ai.
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your sources, memory, or workspace.
- Export the content you have brought into the Service.
International data transfers
We may process and store information in the United States and in other countries where we or our subprocessors operate. When we transfer personal information across borders, we use appropriate safeguards required by applicable law to protect that information.
Cookies
We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and understand how the Service is used. You can control cookies through your browser settings, though some features may not work correctly if you disable them.
Children
The Service is not intended for individuals under 16 years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at legal@usethem.ai and we will take appropriate steps to delete it.
Changes
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Contact
If you have questions about this Privacy Policy or our data practices, contact us at legal@usethem.ai.
- Company: Them Labs, Inc.
- Email: legal@usethem.ai