How we keep your household safe
Last updated: August 13, 2026
TheuBot is a family assistant. That only works if you can trust it with calendars, mail, and the details you ask it to remember. This page explains — in plain language — how we isolate your household, encrypt sensitive records, and keep one member’s private accounts from leaking into another’s.
For legal terms on collection and use, see our Privacy Policy and Terms of Service.
Your household, not a shared bucket
Each family gets its own vault and assistant runtime. We do not mix your people, memory, or connectors with another customer’s.
My accounts stay mine
Personal Gmail, Drive, calendar, Tesla, and similar logins belong only to that member. Household accounts are the ones everyone can use.
Sensitive facts are encrypted
Legal names, full SSNs (if you ever store one), phones, addresses, and similar PII are stored as encrypted vault fields — not as ordinary text the assistant can dump.
You confirm the serious stuff
Sending mail, spending, and similar high-impact actions require an explicit Yes. The bot does not silently act on those.
The household vault
The vault is TheuBot’s memory for your family: people, preferences, open loops, and notes you ask it to keep. Display names and everyday likes can be used to help you. Secrets are treated differently.
- Full Social Security numbers, card numbers, and similar secrets are never sent to the language model, Telegram, or a daily brief.
- When a last-4 is enough (for example a card on file), we prefer that over storing the full number.
- We do not collect kids’ government IDs by default, and kids are not household admins.
Encryption keys
Sensitive person fields are encrypted with AES-256-GCM before they are written to the database.
Each household member has their own data key. That key is itself wrapped by the household master key, which lives in the household’s server environment — not in the browser, not in git, and not in chat logs. Encrypted cells are tagged to that person so one member’s ciphertext cannot be read with another member’s key.
If a member’s wrapped key is removed, their encrypted PII becomes unreadable even if the ciphertext rows remain. That is how we can crypto-erase a person’s sensitive fields without pretending the rest of the household never existed.
Connector logins (Google, Microsoft, Tesla, and so on) are stored as encrypted secrets in the control plane and pulled only by your household’s assistant when you use those features. Raw OAuth tokens are not prompt-eligible.
Personal vs household accounts
Family calendar and a shared inbox are household connectors — anyone in the house can use them. “My accounts” are not. Cassie cannot browse Chris’s Drive or Tesla; Chris cannot open Cassie’s personal mail. When you ask in chat, a household miss may fall back to your personal account only, never someone else’s.
Daily briefs follow the same line: the household brief is the shared snapshot. My brief is yours. Combined stacks those two. We do not put another adult’s likes, personal mail digest, or personal calendar on your board.
What the AI is allowed to see
To answer you, TheuBot sends relevant context to the model — a question, a calendar window, a mail summary you asked about. That is how an assistant works. What it must not see:
- Full SSN or full payment card numbers
- OAuth refresh tokens, API keys, or database credentials
- Another member’s personal secrets or personal connector data
- Kids’ records beyond what an adult has chosen to keep for the family
We do not sell household content. We do not use your vault or chats to train public foundation models for unrelated third parties.
Where data lives
- Sign-in — handled by Clerk (your email and organization membership).
- Billing — Clerk Billing and Stripe. We see plan status, not your full card number.
- Vault and household memory — stored in your tenant’s isolated database, with application-level encryption on sensitive columns.
- The assistant itself — a dedicated runtime per household, talking to the vault and the connectors you enabled, over TLS.
Traffic to our apps, the database, Google, Microsoft, and Telegram uses encryption in transit.
What we want you to know, honestly
No hosted service is invulnerable. If you invite someone to the household, they can use shared family connectors. If you store a sensitive fact, treat TheuBot like any other trusted home tool: use a strong sign-in, invite people you trust, and disconnect accounts you no longer want linked.
We designed the vault, the per-person keys, and the personal-account gate so a curious spouse, a kid with a phone, or a bug in a shared widget is not enough to read someone else’s private life. That is the bar we hold ourselves to.