Threadline privacy
Threadline is designed around isolated accounts. One customer cannot use the application to read another customer's events, goals, preferences, receipts, billing state, or browser sign-ins.
What is stored
We store account identity, Google identity linkage, password hashes for legacy password accounts, session records, subscription status, usage counts, goals, preference weights, connector status, action receipts, and information you direct Threadline to ingest. Sensitive event text, Google credentials, agent output, and reusable browser state are encrypted before database storage. Uploaded originals are not retained after bounded text extraction.
Service providers
Cloudflare provides the control plane, database, Browser Run service, and managed AI inference. Vercel hosts the web application. Stripe processes subscription payments; Threadline stores Stripe identifiers and status, not full card details. Google processes identity, Gmail, and Calendar authorization when you connect it. Resend processes operational email delivery to your verified account address when notifications are enabled. Other connected websites process information under their own terms when you choose to use them.
Google data
Threadline requests read-only Gmail access and Google Calendar event access to surface obligations and deadlines and, only after your explicit action review, create private holds without attendees or invitation updates. Google credentials are encrypted and isolated to your tenant. Threadline does not sell Google user data, use it for advertising, or let another customer access it. Disconnecting Google deletes the local credential and requests upstream revocation.
Managed reasoning
Your subscription includes tenant-isolated managed reasoning. It does not share or consume another person's ChatGPT credentials. The operator's optional owner-only model route remains technically and financially separate from customer accounts.
Proactive notifications
Email notifications are enabled by default for approaching deadlines and completed scheduled goal reviews. Threadline derives the recipient from your verified account instead of accepting an arbitrary address. You can turn email notifications off from the account page; queued notifications are then suppressed. Provider receipt identifiers are encrypted before storage.
Control and retention
You can disconnect Google, remove an individual reusable browser session, turn proactive email off, cancel billing in the Stripe customer portal, sign out, and permanently delete your account and tenant data from the account screen. Account deletion deletes reusable credentials, browser state, events, goals, notification state, preferences, receipts, agent output, and active sessions. Minimal payment or security records may be retained by service providers where necessary for fraud prevention, billing disputes, and legal compliance.