Privacy Policy
Last updated August 24, 2026
This Privacy Policy explains how Thread.xyz Inc ("Thread", "we", "us") handles information when you connect a mailbox, grant or revoke permissions, or build on the Thread platform. Thread exists to make mailbox access scoped, transparent, and revocable — and our handling of your data follows the same principle: we touch the least we can, and you stay in control of the rest.
Who we are
Thread is operated by Thread.xyz Inc. We provide a permission layer that lets people grant third-party applications ("Skills") scoped, revocable access to their mailbox, instead of handing over a password or a blanket OAuth grant. References to "you" mean either an end user who connects a mailbox, or a developer who builds a Skill.
Information we collect
- Account data. Your email address and authentication details when you sign in to a Thread portal.
- Connection data. The mailbox you connect, the provider (Google, Microsoft, or IMAP), and the OAuth tokens needed to access it on your behalf.
- Grants. Which Skills you have authorized, the scopes you granted them, and your revocation history.
- Mailbox content. We process message metadata and, where a granted scope requires it, message bodies and attachments — only to fulfill the access you granted.
- Operational data. Logs, timestamps, and diagnostics needed to run the service securely.
How we use mailbox data
We access your mailbox solely to carry out the scopes you have granted to a Skill. A Skill can only ever see what its granted scopes allow — never your whole inbox by default. Content that falls outside a granted scope is masked before it ever crosses the Thread membrane to a Skill.
Thread uses large language models to classify and categorize messages so that scopes can be enforced and sensitive fields masked. We do not sell mailbox data, and we do not use your mailbox content to train models.
What developers (Skills) receive
When you grant a Skill access, that Skill's developer receives only the data permitted by the scopes you approved. The developer is an independent controller of the data you choose to share with their Skill, and their use of it is governed by their own privacy policy. You can review and revoke any grant at any time from the user portal.
Service providers we rely on
- Mailbox providers — Google and Microsoft, for OAuth-based access to the mailbox you connect.
- LLM provider — to classify and mask messages so scopes can be enforced.
- Infrastructure — hosting, database, and logging vendors that run the service under contractual data-protection terms.
Retention
We keep account, connection, and grant records for as long as your account is active. Mailbox content is processed transiently to serve a granted scope and is not retained beyond what is needed to deliver the service. When you revoke a grant or delete your account, we revoke the associated tokens and delete or anonymize related data, except where we must retain it to meet a legal obligation.
Security and data protection
Mailbox and calendar content is sensitive data, and we treat it as such. The mechanisms below are structural — they are how the product is built, not policies layered on top.
- Encryption in transit. All traffic to Thread and to mail and calendar providers travels over TLS. We do not accept plaintext connections.
- Encryption at rest. Provider OAuth tokens and refresh tokens are encrypted at rest with AES-256 before they are written to the database. Encryption keys are held outside the application database and are never committed to source control.
- Message bodies are never stored. Bodies and attachments are fetched from the provider, filtered, and passed to the authorized Skill in the same request. They are not written to our database, our caches, or our logs. Our audit log has no column capable of holding message content.
- Masking by default. Where a grant allows body access, the default grade delivers a redacted body with personal identifiers removed. Unredacted content requires the user to choose it explicitly.
- Server-side enforcement, failing closed. Every request from a Skill is evaluated against the user's grant by our permission engine before any provider call is made. If a grant is missing, expired, out of schedule, over its rate limit, or cannot be evaluated, the request is denied. Access is never granted by default.
- Skills never receive your credentials. Your provider OAuth token stays with Thread. Skills authenticate to our gateway with their own key and receive only the data your grant permits.
- Least-privilege internal access. Administrative access to production systems is restricted to named personnel who need it, and privileged actions are logged.
- Audit trail. Every access to your mailbox or calendar is recorded as metadata — which Skill, which action, which decision, when — and is visible to you in the portal.
- Revocation and deletion. Revoking a grant takes effect on the next request, with no cache to drain. Disconnecting a mailbox deletes the stored provider tokens. Deleting your account removes your account data, connections, and grants.
- Incident response. If we become aware of a breach affecting your data, we will notify affected users and any applicable regulator without undue delay and within the periods required by law.
No system is perfectly secure, and we do not claim otherwise. What we can say is that the amount of your data reachable at any moment is bounded by the grants you have made, and that bound is enforced in code.
Google user data and Limited Use
Thread's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features you have granted a Skill — reading the mail or calendar entries in scope, and performing the triage or scheduling actions you allowed.
- We transfer Google user data to a third party only at your explicit direction: to the specific Skill you authorized, limited to the scopes you granted, and only for as long as that grant is active. You can revoke it at any time.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to train generalized artificial-intelligence or machine-learning models.
- Humans do not read your Google user data, except where you have explicitly asked us to (for example, to debug a problem you reported), where it is necessary for security purposes, or where we are required to by law.
Your rights and choices
- Revoke any Skill's access, instantly, from the user portal.
- Disconnect a mailbox, which revokes the underlying provider tokens.
- Request access to, correction of, or deletion of your personal data.
- Object to or restrict certain processing, where applicable law provides the right.
To exercise any of these, contact us at the address below. We honor revocation in real time — it is the core promise of the product, not a support ticket.
Children
Thread is not directed to children under 16, and we do not knowingly collect their personal data.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by an updated date above and, where appropriate, a notice in the portal.
Contact
Questions or requests about privacy can be sent to privacy@thread.xyz. Thread.xyz Inc is the data controller responsible for your information.