DOC-02 — PRIVACY POLICYREV 2026-08-08

Privacy Policy

What we collect

Account data — name, email, organization, and the password hash or the identity of the provider you signed in with.

Contact enquiries — the name, email, and description you submit through the contact form.

Connected content — whatever the tools you authorize return: meeting transcripts, tickets, merge requests and their diffs, documents, messages, and the metadata around them, including the names and email addresses of the people who appear in that content.

Operational data — audit records of actions taken in the Service, workflow run logs, the cost and token counts of model calls, and the usage counts described in “Cookies and counting” below.

How we use it

Connected content is processed to build and maintain your project's knowledge graph, to answer questions you and your team ask, and to generate proposals for follow-through actions. Account and operational data is used to run the Service, to secure it, to bill or quote for it, and to talk to you about it.

We do not use your content to train models, and we do not sell it or share it with third parties for their own purposes.

Where your content goes

Answering a question or drafting a proposal means sending the relevant excerpts of your content to a large language model provider. Those excerpts leave our infrastructure. This is inherent to how the Service works; it is not something a configuration setting turns off.

For generation we call Anthropic, OpenAI, DeepSeek, or Google, depending on the model your project selects; embeddings go to OpenAI, and search results are reranked by Cohere. A project may also be pointed at another provider by naming a custom model — if yours is, that provider receives the excerpts too, and we will tell you which on request. We use these providers' standard APIs under their published terms; we have not negotiated separate data processing agreements or zero-retention arrangements with them, and you should read their policies as they apply to you.

Where it is stored

The Service runs on servers rented from Hetzner in Germany. Your content is held in a PostgreSQL database, a Qdrant vector index, and an S3-compatible object store, all on that infrastructure. Traffic to the Service is encrypted in transit with TLS.

Credentials for connected tools are encrypted before they are stored, and are never returned to the browser or written to logs in plaintext.

Keeping projects apart

Every project's content is scoped by a project filter applied on both writes and reads, in the database and in the vector index alike. One project cannot retrieve or cite another project's content, including inside the same organization.

How long we keep it

Connected content and derived entities are kept while the project exists. Deleting a project removes it and its entities from the primary database; copies in the search index and in backups are removed as part of a deletion request (below) rather than automatically.

Audit records outlive the project they describe, on purpose — the trail of who approved what is the point of keeping them. A project can set a retention period after which they are deleted; without one they are kept indefinitely.

Contact enquiries expire automatically 90 days after they are submitted, unless they turn into an ongoing conversation with us.

Your rights

Depending on where you live — and under the GDPR if you are in the EU or UK — you may ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. The Service has no self-serve account deletion yet: write to us and we will do it by hand. We aim to answer within 30 days.

If your data reached us because it appears in content someone else connected — a colleague's meeting transcript, a ticket you commented on — that customer decides what happens to their project. We will pass such requests on to them and help them action it.

Cookies and counting

This site sets no advertising or analytics cookies and loads no third-party tracking scripts. The only cookies are the ones that make signing in work: your session and the organization you are currently working in.

We do count how the site and the app are used, ourselves. Opening a page, and a handful of steps inside the app — signing up, accepting an invitation, connecting a tool — each record one line: which page or step it was, the site you arrived from (its domain, not the page), any campaign parameters in the link, and a random identifier held in your browser for the length of that visit. The identifier lives in session storage rather than a cookie, is discarded when you close the tab, and is connected to no account; it exists so we can tell one visit that read two pages from two visits that read one each.

What those lines deliberately do not contain: your IP address, your browser's user agent, your name or e-mail, and the identifiers of your organization, project or installation. Page addresses are stored as their shape rather than literally, so an address carrying an invitation token or the id of a document is recorded as “/invite/…” and not as the token itself. This data stays in our own database, is sent to no analytics vendor, and is deleted after 180 days.

Changes and contact

We may update this policy; the revision marker at the top of the page changes when we do, and material changes are announced through the Service or by email. Privacy questions and data requests go through the contact page or to hello@threadory.ai.