Privacy Policy
Last updated 15 September 2026
This policy explains what Therm (“we”, operated by Fouressco) collects when you connect a thermostat to our service, why we collect it, who can see it, and how to get rid of it.
It is written to be read rather than skimmed past. If anything here is unclear, ask us at privacy@fouressco.com before you connect a device.
The short version
- We read your thermostat’s temperature, humidity and running state about once a minute, and we store that history.
- We can change your setpoint — but only if you turn that on yourself, and you can turn it off at any time.
- We do not sell your data, show you ads, or use your data to train machine-learning models.
- Deleting your account deletes your thermostat history.
What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Email address and a password hash. We never store your password itself. | To sign you in and to contact you about your service. |
| Home | A name you choose, and a ZIP or postal code. From the ZIP we derive your city, state, approximate latitude and longitude, timezone and elevation. We do not ask for your street address. | Outdoor weather drives the control maths, and elevation sets atmospheric pressure, which every humidity calculation depends on. Timezone makes daily reports line up with your calendar rather than ours. |
| Thermostat connection | An access credential issued by your thermostat provider (for Google Nest, an OAuth refresh token), plus the device identifiers and display names of the thermostats you choose to share. | To read your thermostat and, if you allow it, to change its setpoint. |
| Thermostat readings | Roughly once a minute: indoor temperature, relative humidity, derived dew point, current setpoint, heating/cooling mode, whether the system is actively heating, cooling or idle, whether Eco mode is on, and fan state. Alongside each reading we store outdoor temperature, humidity and dew point for your ZIP code. | This series is the input to the building model that decides when to run your equipment. Without history there is no model. |
| Control decisions | Every decision our system makes, whether or not it was sent: the setpoint before and after, and a plain-language reason. Also every setpoint change made by a person, labelled as from the wall unit, from our app, or from us. | So that you and we can always answer “why did my thermostat do that?” This is an audit trail, and it is deliberately complete. |
| Consent changes | Each time remote control is switched on or off: when, and from which session. | So there is a record of what you agreed to and when. |
| Payment | A customer identifier from our payment processor, and your subscription status. | To know whether your subscription is active. We never see or store your card number — card details go directly to Stripe. |
| Technical logs | IP address, timestamps and error diagnostics for requests to our service. | Security, abuse prevention, and debugging. Retained for a short period. |
Google user data, specifically
If you connect a Google Nest thermostat, you grant us the
https://www.googleapis.com/auth/sdm.service scope through Google’s own
consent screen. That scope lets us read the thermostat traits listed above and write
setpoint and fan commands. We request it because our control loop needs both: it cannot
hold a humidity band without reading temperature and humidity, and it cannot act without
writing a setpoint. Google offers no narrower scope for this.
Limited Use commitment. Therm’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means we do not:
- sell, rent or trade your Google data;
- use it for advertising, ad targeting, remarketing or profiling;
- use it to train generalised machine-learning or AI models;
- transfer it to data brokers, information resellers or any third party, except as described under Who else sees your data below;
- allow humans to read it, except with your explicit consent for a support request you have raised, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymised.
You can revoke our access at any time from your Google Account permissions page, or by disconnecting the thermostat in our app. Revoking access stops all reading and all control immediately.
Changing your thermostat
Connecting a thermostat starts data flowing. It does not give us permission to change anything.
Remote control is a separate switch, off by default, labelled Allow Control in the app. While it is off, our system still analyses your home and records what it would have done, but sends nothing to your equipment. While it is on, we may adjust your cooling setpoint within limits you can see and change.
Turning it off takes effect on our next control cycle, within fifteen minutes, and leaves your thermostat holding an ordinary temperature that you can change by hand at any time. Adjusting the thermostat at the wall always takes precedence over us.
Who else sees your data
We do not sell your data. We share it only with the service providers needed to run the product, and only to the extent needed:
- Your thermostat provider (e.g. Google) — we call their API to read and command your device.
- Stripe — payment processing. They receive your email and payment details; we do not receive your card number.
- Our hosting — our servers and database, which we operate ourselves.
We may also disclose data where we are legally required to, or where it is necessary to investigate a security incident. If we are ever compelled to disclose your data, we will tell you unless legally prohibited from doing so.
Our own staff do not routinely read your data. Access is limited to support requests you raise, security investigations, and operating the service, and administrative access is logged.
How long we keep it
- Thermostat readings and control decisions — for as long as your account is open. The building model gets better with more history, so we keep it rather than trimming it, and you can export it at any time.
- After you delete your account — readings, decisions and your thermostat credential are deleted within 30 days. Backups age out within a further 30 days.
- Technical logs — 30 days.
- Billing records — retained as long as tax and accounting law requires, typically several years. These contain no thermostat data.
Disconnecting a thermostat without closing your account deletes the stored credential immediately and stops collection. Your existing history is kept so that reconnecting later does not start the model from nothing — tell us if you would rather it were erased.
Your choices
- See it — your full reading history is visible in the app and exportable as CSV.
- Correct it — account and home details are editable in the app.
- Delete it — delete your account in the app, or email us.
- Stop control without disconnecting — switch off Allow Control.
- Revoke entirely — disconnect in the app, or revoke at your thermostat provider.
Depending on where you live you may have additional rights — access, portability, correction, erasure, restriction, objection, and the right to complain to a supervisory authority. Email us and we will honour them. We do not discriminate against anyone for exercising a privacy right.
Security
Thermostat credentials are encrypted at rest with a key held outside the database. All traffic to our service uses HTTPS. Sign-in sessions use rotating tokens with reuse detection, so a stolen session token is detectable and revocable. Access to production systems is restricted and logged.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the relevant authorities as required by law.
Children
Therm is not directed at children under 13 (or under 16 where local law sets that bar), and we do not knowingly collect their data. If you believe a child has given us data, email us and we will delete it.
International transfers
Our servers are located in the United States. If you use Therm from elsewhere, your data will be transferred to and processed in the United States, which may have different data protection laws from your own country.
Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will notify you in the app or by email before the change takes effect, and update the date at the top. Continuing to use Therm after that constitutes acceptance.
Contact
Fouressco
4067 Miramar St
La Jolla, CA 92037
United States
privacy@fouressco.com