Privacy policy.
How we handle your account, website information and the connections you choose.
Who we are.
theoretic.si is operated by MYST AS, organisation number 933392465, Hanna Vinsnes veg 10, 2322 Ridabu, Norway. MYST AS is responsible for the personal information described in this policy. Contact us at hi@theoretic.si for privacy questions or requests.
Information we process.
Accounts. We process the name, email, website and optional company information you provide, account and workspace identifiers, verification records and security information. Passwords are stored as salted hashes. Verification and password-reset links contain temporary secrets; the application stores their hashes. Payments are disabled.
Optional sign-in. Google or Microsoft sign-in supplies identity information such as your provider account identifier, name, email and verification status. We keep the identity link needed to recognise your account. We do not receive your provider password. Signing in with a provider does not itself connect search data.
Website and search data. Scott reads your configured public website and records monitoring findings, page metadata, tasks and reports. Optional Google Search Console and Bing connections provide matching website properties and permissions, queries, page URLs, search performance, crawl/indexing information and sitemaps. Requested performance checks send the public URL or origin to Google PageSpeed Insights or Chrome UX Report.
Service security and support. We process session identifiers, security challenge results and technical connection information to operate the service and limit abuse. Our hosting and security providers receive network/browser information. If you contact us, we receive the information in your message.
Why we use it.
We use this information to provide accounts and requested workspace features, verify and recover access, maintain your chosen connections, secure the platform and respond to support requests. For personal information covered by the GDPR, our bases are performing the service agreement for requested account and workspace functions, legitimate interests in service security and support, and consent where required for optional processing.
Required account information, email verification and the security check are necessary to activate an account. Search-data and AI connections are optional. Without a connection, the corresponding feature has no connected data or access.
Google API data.
Google sign-in requests basic identity information. Connecting Search Console is a separate choice and requests read-only access. Google returns properties your account can access; we match them to the websites registered in your workspace. We use the matching data for search insights, Scott monitoring and the read tools you authorize. This access does not permit changes to Search Console and does not grant access to Gmail messages, Drive files or Contacts.
theoretic.si follows the Google API Services User Data Policy, including the Limited Use requirements, when using or transferring information received from Google APIs.
We do not sell Google API data, use it to target advertising or determine creditworthiness, or train AI models on it. Transfers are limited to providing or improving the prominent features you authorize, necessary security or legal purposes, or another use expressly permitted by those requirements. Human access is limited to your affirmative agreement for specific data, necessary security investigations, legal requirements, or other uses expressly allowed by Google’s policy.
Retention and removal.
Account records, identity links and workspace monitoring history persist to provide the service. There is currently no automatic full account or workspace deletion schedule. Contact hi@theoretic.si to request access, correction, export or removal; we verify the request and review it under applicable law.
Verification links normally expire after 24 hours and password-reset links after 30 minutes. Expiry prevents use of a link; it does not erase every related record immediately. Pending registrations older than 30 days and recovery records older than one day become eligible for cleanup during account-registration activity. Some monitoring lists have size limits; snapshots and reports can remain in workspace history. Backup copies can remain until those backups are rotated.
Disconnecting Google or Bing removes the current OAuth connection credential from the application. Google disconnect also attempts provider-side revocation, which can affect other connections using the same Google account and Google project. Disconnect does not erase previously collected reports, caches or backups, or remove a separately configured service-account integration. AI connections can be revoked and normally expire after 30 days; information already received by an assistant remains subject to its provider’s policies.
Your choices and rights.
You can leave optional sources disconnected, revoke AI access and review/remove app permissions in your Google or Microsoft account settings. Removing provider permission does not itself delete your theoretic.si account or its history.
Under applicable data protection law, you may request access, correction, erasure, restriction or portability, object to processing, and withdraw consent for consent-based processing. Contact hi@theoretic.si. You may also complain to the Norwegian Data Protection Authority, Datatilsynet, or your applicable supervisory authority.
We will update this policy when our data practices change. If a new use of Google data requires additional disclosure or consent, we will provide it before that use.