Legal

Privacy Policy

Plain language first, because a policy nobody reads protects nobody.

Last updated 5 August 2026. This is a template and has not been reviewed by a lawyer. Have counsel check it before you launch.

The short version

  • We read your mailbox to summarize it. We do not send mail as you.
  • We store summaries and extracted contact details, not a full copy of your mailbox.
  • We do not sell your data or use your mail to train models for other customers.
  • Disconnect an inbox and its derived data is deleted.

What we collect

Account information

Your name, email address and billing details when you subscribe. Payment card details are handled by our payment processor, not stored by us.

Mailbox data

With your explicit OAuth consent, we access message metadata and body content in order to generate summaries and detect leads. We retain the generated summary, the lead flag, extracted contact details and message metadata.

Usage data

Basic product analytics such as pages viewed and features used, so we know what to fix.

How we use it

To provide the service, to support you when you ask, to bill you, and to improve ThreadOptic in aggregate. Nothing else.

Who we share it with

Only the processors needed to run the service, such as hosting, our payment processor and the language model provider used for summarization. Each is bound by contract to process data on our instructions only. We do not sell personal data.

Retention and deletion

Derived data is deleted when you disconnect an inbox. Account and billing records are kept as long as required for tax and accounting obligations. You can request full deletion at privacy@threadoptic.com.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Email us and we will action it.

Contact

Questions go to privacy@threadoptic.com.