Privacy Policy
Last updated: August 7, 2026
This Privacy Policy explains what information Threadly ("Threadly," "we," "us," or "our") collects when you use our website and application (the "Service"), how we use it, and the choices you have. By using the Service you agree to the collection and use of information as described here.
1. Information we collect
1.1 Account information
When you register, we collect your name, email address, and a hashed (never plaintext) password. We automatically create a workspace tied to your account to organize your connected platforms and settings — you don't need to name or configure it yourself.
1.2 Connected platform data
When you connect an account (X/Twitter, LinkedIn, or Reddit) via OAuth, we receive and store an access token (and refresh token, where the platform provides one) that lets Threadly act on your behalf within the scopes you approved during that platform's own consent screen. These tokens are encrypted at rest. We never see or store your password for any connected platform — authentication happens entirely on that platform's own site.
Using that connection, Threadly reads public posts and conversations on the connected platform matching the keywords and criteria you configure, in order to identify conversations that may be relevant to you and draft a suggested reply.
1.3 Content you create in Threadly
We store the conversations Threadly finds, the replies it drafts, and your decisions (approve, reject, or edit) on each draft. Nothing is ever published to a connected platform without your explicit approval — see Section 3.
1.4 Payment information
Subscription payments are processed by Polar (acting as merchant of record), our payment processor. Threadly never receives or stores your full card number — Polar handles card collection, billing, and applicable tax compliance directly. We store only your subscription status (trial, active, past due, canceled) and billing period dates.
1.5 Usage and log data
We keep an audit log of security-relevant account actions (logins, connections made or removed, subscription changes, configuration changes) including timestamps and IP address, for security and support purposes.
1.6 Cookies
We use a session cookie to keep you signed in and a second cookie to protect state-changing requests from cross-site forgery. Both are essential to the Service functioning and are not used for advertising or cross-site tracking.
2. How we use your information
- To provide, maintain, and secure the Service, including keeping you signed in and processing your subscription.
- To operate the AI agents that find relevant conversations and draft replies on your behalf.
- To communicate with you about your account, billing, or changes to the Service.
- To detect, investigate, and prevent fraud, abuse, or security incidents.
- To comply with legal obligations.
3. Human approval — how content drafting and AI processing works
Threadly is built around one permanent rule: nothing is ever posted, messaged, or published to any connected platform without your explicit, per-item approval. This is not a limitation of an early version — it is a permanent design principle of the Service.
To draft a reply, the text of the conversation Threadly found is sent to Anthropic's Claude API for processing. Anthropic processes this content to generate the draft and does not use it to train models available to other customers, consistent with Anthropic's own commercial API terms. See Anthropic's Privacy Policy for how Anthropic itself handles data sent to its API.
4. Third-party service providers
We share information with the following categories of service providers, only as needed for them to perform their function:
- Polar — subscription billing and payment processing (merchant of record).
- Anthropic — AI processing to draft replies (Claude API).
- X (Twitter), LinkedIn, and Reddit — the platforms you explicitly connect via OAuth; we exchange data with them only within the scopes you grant.
- Railway and Vercel — infrastructure providers hosting our backend, database, and website.
We do not sell your personal information to anyone, ever.
5. Data retention
We retain account and connection data for as long as your account is active. If you disconnect a platform, its access token is deleted immediately. If you delete your account, we delete your personal data within 30 days, except where retention is required for legal, tax, or fraud-prevention purposes.
6. Data security
Passwords are hashed, never stored in plaintext. OAuth tokens for connected platforms are encrypted at rest. All traffic between your browser and Threadly is encrypted in transit (HTTPS). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Disconnect any connected platform at any time from your dashboard, immediately revoking Threadly's access.
- Export your data.
To exercise any of these rights, contact us using the details in Section 11.
8. Children's privacy
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18 years old.
9. International data transfers
Threadly is operated from India, and our infrastructure providers may process and store data in other countries. By using the Service, you consent to your information being transferred to and processed in countries other than your own.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or through the Service before the change takes effect.
11. Contact us
Questions about this Privacy Policy or your data can be sent to thumbflip.contact@gmail.com.