What we ask for,
and what we never touch.
ThreadOptic reads your mailbox. That deserves a straight explanation rather than a badge wall.
The access we request
ThreadOptic connects through the official Google and Microsoft OAuth flows. You approve the connection in their consent screen, not ours, and you can revoke it from your Google or Microsoft account settings at any time without asking us.
We request read only mailbox scope. ThreadOptic cannot send mail, cannot reply, cannot delete and cannot modify your messages. Those permissions are not in the grant, so even a bug on our side cannot reach them.
What we store
- The generated summary and lead flag for each message.
- Contact details extracted from the message body.
- Message metadata such as sender, subject and timestamp.
We do not keep a mirror of your full mailbox. When you disconnect an inbox, the derived data for that inbox is deleted.
Your mail and model training
Your inbox contents are not used to train models for other customers, and we do not sell or broker inbox data. Summarization runs per message for your account only.
In transit and at rest
All traffic runs over TLS. Stored data is encrypted at rest. Access to production systems is limited to the engineers who need it, and is logged.
Honest gaps
We are early stage. We do not yet hold SOC 2 or ISO 27001, and we are not going to imply otherwise by putting logos in a footer. If your brokerage requires a formal certification before approving vendors, we are probably not there yet. Ask us and we will tell you plainly where we stand.
Reporting something
If you find a vulnerability, email security@threadoptic.com. We will confirm receipt within two business days and we will not pursue action against good faith research.