Privacy Policy
Threadmill ("we") handles your personal data with care and in accordance with applicable law. This policy explains what we collect, why, and how we protect it.
1. Information We Collect
Account: email, name, and profile image from Google sign-in, or your email address for email sign-in.
Threads connection: Threads user ID, username, profile picture URL, and API access tokens (stored encrypted). Tokens are used solely to publish content, send replies, and read performance data.
Content you provide: persona settings, uploaded knowledge materials (text and URLs), generated and published content with its performance metrics, and public comments on your posts.
Optional: your Telegram chat ID if you connect notifications. Payment details are collected and processed directly by Paddle; we never store card information.
Automatic: service usage records, access logs, and essential cookies for login sessions.
Visit statistics: to count visitors we combine your IP address and browser User-Agent with a value that rotates daily, hash the result irreversibly, and store only that hash and the visit date. We never store the raw IP or User-Agent, and because the hashing value rotates daily the same person cannot be tracked across days. No cookies are used for this purpose.
Attribution cookie: when you first arrive we store the link's source markers (ref and utm parameters), the external referrer, the first page you landed on, and the time in a 30-day cookie (tm_attr). It contains no personal identifier. If you sign up, we copy it once into your account record so we know which channel you came from, and delete it with your account. Your IP address and browser information at sign-up are kept as part of access logs.
Usage analytics (Microsoft Clarity): to improve the Service we use Microsoft Clarity, which collects page navigation, click and scroll positions, session replays (text you type is masked by default), and device and browser information, using cookies such as _clck and _clsk. Microsoft's privacy statement applies; you can opt out by blocking cookies in your browser.
Ad measurement (Meta Pixel): when you visit threadmill.ai, Meta Platforms' pixel sends cookies (such as _fbp), device and browser information, the page URL, and events such as sign-up completed, checkout started, and subscription completed to Meta. We do not send direct identifiers such as your email address through the pixel. Meta uses this information to measure and deliver ads; you can opt out by blocking cookies in your browser or through your Facebook/Instagram ad settings (activity information from ad partners).
2. How We Use It
To provide the Service (content generation, scheduling, publishing, reply automation, reports), authenticate you, process billing, improve the Service, and meet legal obligations.
We do not sell your personal information to third parties for advertising.
3. Sharing & Processors
Meta Platforms (Threads API): publishing content and reading comments and insights.
Microsoft (Clarity): usage analytics and session replay. Your information may be transferred to the United States or other countries.
Meta Platforms (Meta Pixel): measuring and delivering ads based on website visits and conversion events. Your information may be transferred to the United States or other countries.
Google (sign-in, Gemini API): authentication; for content generation, your persona, knowledge materials, drafts, and incoming comments are sent to the AI model. We use API settings under which this data is not used for model training.
Paddle: payment processing as Merchant of Record; Paddle's privacy policy applies to billing data.
Telegram (optional): notification delivery.
Cloud infrastructure (e.g., AWS): data storage and operations. Data may be stored on servers outside your country, with safeguards required by applicable law.
4. Retention & Deletion
Account data and service data are deleted without undue delay when you delete your account or request deletion. Threads access tokens are destroyed immediately upon disconnection.
Transaction records are retained for statutory periods where required by law, then destroyed.
See our Data Deletion page (/data-deletion) for the deletion process. Removing Threadmill from your Threads settings immediately stops collection and publishing; if you also choose "request data deletion" when removing, Meta's deletion callback triggers deletion of the related data.
5. Your Rights
You may request access, correction, deletion, or restriction of your personal data at any time. You can disconnect accounts and delete materials directly in the dashboard; for anything else, contact us and we will act without undue delay.
6. Security
We encrypt sensitive data such as access tokens at rest, use TLS in transit, minimize internal access, and keep access logs, in line with applicable legal requirements.
7. Changes & Contact
Changes to this policy will be announced in the Service at least 7 days before taking effect; material changes will also be emailed.
Privacy inquiries: support@threadmill.ai