YOUR INFORMATION

Privacy policy.

How we handle your account, website information and the connections you choose.

Who we are.

theoretic.si is operated by MYST AS, organisation number 933392465, Hanna Vinsnes veg 10, 2322 Ridabu, Norway. MYST AS is responsible for the personal information described in this policy. Contact us at hi@theoretic.si for privacy questions or requests.

Information we process.

Accounts. We process the name, email, website and optional company information you provide, account and workspace identifiers, verification records and security information. Passwords are stored as salted hashes. Verification and password-reset links contain temporary secrets; the application stores their hashes. Payments are disabled.

Optional sign-in. Google or Microsoft sign-in supplies identity information such as your provider account identifier, name, email and verification status. We keep the identity link needed to recognise your account. We do not receive your provider password. Signing in with a provider does not itself connect search data.

Website and search data. Scott reads your configured public website and records monitoring findings, page metadata, tasks and reports. Optional Google Search Console and Bing connections provide matching website properties and permissions, queries, page URLs, search performance, crawl/indexing information and sitemaps. Requested performance checks send the public URL or origin to Google PageSpeed Insights or Chrome UX Report.

Service security and support. We process session identifiers, security challenge results and technical connection information to operate the service and limit abuse. Our hosting and security providers receive network/browser information. If you contact us, we receive the information in your message.

Why we use it.

We use this information to provide accounts and requested workspace features, verify and recover access, maintain your chosen connections, secure the platform and respond to support requests. For personal information covered by the GDPR, our bases are performing the service agreement for requested account and workspace functions, legitimate interests in service security and support, and consent where required for optional processing.

Required account information, email verification and the security check are necessary to activate an account. Search-data and AI connections are optional. Without a connection, the corresponding feature has no connected data or access.

Google API data.

Google sign-in requests basic identity information. Connecting Search Console is a separate choice and requests read-only access. Google returns properties your account can access; we match them to the websites registered in your workspace. We use the matching data for search insights, Scott monitoring and the read tools you authorize. This access does not permit changes to Search Console and does not grant access to Gmail messages, Drive files or Contacts.

theoretic.si follows the Google API Services User Data Policy, including the Limited Use requirements, when using or transferring information received from Google APIs.

We do not sell Google API data, use it to target advertising or determine creditworthiness, or train AI models on it. Transfers are limited to providing or improving the prominent features you authorize, necessary security or legal purposes, or another use expressly permitted by those requirements. Human access is limited to your affirmative agreement for specific data, necessary security investigations, legal requirements, or other uses expressly allowed by Google’s policy.

Providers and AI access.

Railway hosts the service and persistent application data. Cloudflare Turnstile processes the browser security check. Resend receives the recipient address and email contents to deliver verification and password-reset links. Google and Microsoft/Bing process the identity and API requests for the features you enable. Authorized platform operators administer and secure the service and provide support, subject to the Google data restrictions above.

If you authorize an AI assistant through MCP or give it a personal workspace token, it can receive read responses for that workspace, including search queries, pages, performance and monitoring findings. Provider credentials are not included. We do not automatically send workspace data to an AI assistant. Review your chosen assistant’s policies and settings: revoking its connection prevents future access but cannot recall information it already received.

The public homepage embeds Instagram content. When it loads, your browser contacts Instagram/Meta, which can receive network/browser information and use its own cookies or storage. This embed does not receive private workspace or Google API data from the application.

Provider processing locations can differ from your country. Contact us about processing locations, provider arrangements and applicable international-transfer safeguards.

Cookies and security.

First-party cookies keep you signed in and protect temporary provider sign-in and connection flows. A session lasts up to 12 hours, with a two-hour inactivity limit; temporary authorization cookies last up to ten minutes. Production session/authorization cookies use Secure and HttpOnly protections. Blocking them can prevent sign-in or authorization.

The current first-party frontend has no general advertising or visitor-analytics tracker. Instagram and the external security/identity providers can use their own cookies or storage. We encrypt Google/Bing access and refresh tokens in the application credential store and keep provider credentials out of browser and AI data responses. This does not mean every account record or monitoring file is individually encrypted.

Retention and removal.

Account records, identity links and workspace monitoring history persist to provide the service. There is currently no automatic full account or workspace deletion schedule. Contact hi@theoretic.si to request access, correction, export or removal; we verify the request and review it under applicable law.

Verification links normally expire after 24 hours and password-reset links after 30 minutes. Expiry prevents use of a link; it does not erase every related record immediately. Pending registrations older than 30 days and recovery records older than one day become eligible for cleanup during account-registration activity. Some monitoring lists have size limits; snapshots and reports can remain in workspace history. Backup copies can remain until those backups are rotated.

Disconnecting Google or Bing removes the current OAuth connection credential from the application. Google disconnect also attempts provider-side revocation, which can affect other connections using the same Google account and Google project. Disconnect does not erase previously collected reports, caches or backups, or remove a separately configured service-account integration. AI connections can be revoked and normally expire after 30 days; information already received by an assistant remains subject to its provider’s policies.

Your choices and rights.

You can leave optional sources disconnected, revoke AI access and review/remove app permissions in your Google or Microsoft account settings. Removing provider permission does not itself delete your theoretic.si account or its history.

Under applicable data protection law, you may request access, correction, erasure, restriction or portability, object to processing, and withdraw consent for consent-based processing. Contact hi@theoretic.si. You may also complain to the Norwegian Data Protection Authority, Datatilsynet, or your applicable supervisory authority.

We will update this policy when our data practices change. If a new use of Google data requires additional disclosure or consent, we will provide it before that use.