Privacy Policy
Last updated: July 11, 2026
ThreadOS ("we", "us", or "our") operates the ThreadOS platform. This policy explains what data we collect, how we use it, and your rights.
1. Information We Collect
- Account data — email address and name, provided at registration.
- Threads account data — Threads username, profile picture, and user ID, obtained via Meta OAuth with your explicit consent.
- Content data — posts you generate, schedule, approve, or publish through our platform.
- Analytics data — post performance metrics (views, likes, replies, reposts) fetched from the Threads API on your behalf.
- Persona data — business description, audience details, content goals, and voice settings you provide to personalise AI generation.
- Usage data — pages visited, features used, and credit consumption, for product improvement.
2. How We Use Your Information
- To authenticate you and operate your account.
- To connect to your Threads account and publish or schedule content on your behalf.
- To personalise AI-generated content using your persona data.
- To display your Threads analytics inside the platform.
- To track credit usage and enforce plan limits.
- To improve the product using aggregated, anonymised usage data.
We do not sell your personal data to any third party.
3. Threads / Meta Data
When you connect your Threads account, we request these Meta permissions:
- threads_basic — read your profile and existing posts.
- threads_content_publish — create and publish posts on your behalf.
- threads_manage_insights — retrieve post and account performance metrics.
Your Threads access token is stored securely and used only for actions you initiate in ThreadOS. You can disconnect at any time from your Profile page, which immediately removes your token from our systems.
4. Data Retention
We retain your data while your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law.
5. Third-Party Services
- Supabase — database and authentication storage.
- OpenAI — AI content generation. Persona data and prompts are sent to OpenAI. OpenAI does not use API data to train models by default.
- Apify — competitor profile lookups using publicly accessible Threads data only.
- PostHog — product analytics using anonymised usage events.
- Vercel — hosting and edge infrastructure.
6. Cookies
We use a single session cookie to keep you logged in. We do not use advertising or tracking cookies.
7. Your Rights
- Access — request a copy of the data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion — request deletion via our Data Deletion page.
- Portability — request a machine-readable export of your data.
- Disconnect Threads — revoke access any time from your Profile page or the Threads app settings.
8. Security
We use HTTPS, hashed credentials, and row-level database security. No internet transmission is 100% secure, but we take reasonable steps to protect your data.
9. Children
ThreadOS is not directed at children under 13. We do not knowingly collect data from anyone under 13.
10. Changes to This Policy
We may update this policy periodically. The "Last updated" date above reflects the most recent revision. Continued use after changes constitutes acceptance.
11. Contact
Privacy questions or data requests: privacy@viralthreados.com
← Back to home · Terms of Service · Data Deletion