Privacy Policy
Effective: August 1, 2026
Threadmill ("we") handles your personal data with care and in accordance with applicable law. This policy explains what we collect, why, and how we protect it.
1. Information We Collect
Account: email, name, and profile image from Google sign-in, or your email address for email sign-in.
Threads connection: Threads user ID, username, profile picture URL, and API access tokens (stored encrypted). Tokens are used solely to publish content, send replies, and read performance data.
Content you provide: persona settings, uploaded knowledge materials (text and URLs), generated and published content with its performance metrics, and public comments on your posts.
Optional: your Telegram chat ID if you connect notifications. Payment details are collected and processed directly by Paddle; we never store card information.
Automatic: service usage records, access logs, and essential cookies for login sessions.
2. How We Use It
To provide the Service (content generation, scheduling, publishing, reply automation, reports), authenticate you, process billing, improve the Service, and meet legal obligations.
We do not sell your personal information to third parties for advertising.
3. Sharing & Processors
Meta Platforms (Threads API): publishing content and reading comments and insights.
Google (sign-in, Gemini API): authentication; for content generation, your persona, knowledge materials, drafts, and incoming comments are sent to the AI model. We use API settings under which this data is not used for model training.
Paddle: payment processing as Merchant of Record; Paddle's privacy policy applies to billing data.
Telegram (optional): notification delivery.
Cloud infrastructure (e.g., AWS): data storage and operations. Data may be stored on servers outside your country, with safeguards required by applicable law.
4. Retention & Deletion
Account data and service data are deleted without undue delay when you delete your account or request deletion. Threads access tokens are destroyed immediately upon disconnection.
Transaction records are retained for statutory periods where required by law, then destroyed.
See our Data Deletion page (/data-deletion) for the deletion process. Removing the app from your Threads settings also triggers deletion via Meta's callback.
5. Your Rights
You may request access, correction, deletion, or restriction of your personal data at any time. You can disconnect accounts and delete materials directly in the dashboard; for anything else, contact us and we will act without undue delay.
6. Security
We encrypt sensitive data such as access tokens at rest, use TLS in transit, minimize internal access, and keep access logs, in line with applicable legal requirements.
7. Changes & Contact
Changes to this policy will be announced in the Service at least 7 days before taking effect; material changes will also be emailed.
Privacy inquiries: [email protected]