Jump go di content

Privacy Policy wey we get

Privacy policy for di Threada platform, wey cover how dem dey handle data, security control, and di rights wey user get.

Last time wey we update am: 2025-01-01

Dis Privacy Policy dey explain how Threada ("we", "us", "our") dey collect, use, and protect information when you dey use our website, platform, API, and related service dem (wey we dey call di "Services" together).

1. Information wey we dey collect

1.1 Account and tenant data

Information wey you dey give when you dey create account abi tenant, like name, email address, organization and role wey dem assign.

1.2 Content from knowledge source

Website content and document wey you allow as knowledge source. We dey store di text wey we process, di metadata wey we pull comot (including schema.org), embedding, and indexing artifact. We dey only process content wey private abi wey get gate if you upload am abi integrate am yourself.

1.3 WorkItem and interaction data

Request from end-user, AI response, citation, approval event, usage event and analytical metric wey no carry person identity.

1.4 Technical and log data

IP address, user agent, timestamp, request ID, latency metric, response code and operational diagnostic — for security, reliability and to catch abuse.

1.5 Billing and subscription data

Plan wey you pick, usage counter, invoice status, entitlement state. Na Stripe dey handle all payment processing; we no dey store full card number.

2. How we dey use information

  • Provide and run di Services (sync, index, answer, automation, analytics)
  • Make retrieval quality, ranking, and stopping of hallucination better
  • Catch abuse, fraud, security wahala, and system misuse
  • Send administrative and service notification
  • Enforce plan limit, free tier usage, and subscription status
  • Make performance, scaling, and reliability better

3. Legal basis (EEA/UK)

We dey process based on: contract performance, legitimate interest (security, improvement), legal compliance, and consent where we ask for am clear-clear (e.g., marketing opt-in).

4. How long we dey keep data

Default retention: work history log and analytics na 90 days, configuration and audit na 365 days. Tenant fit ask for shorter retention abi (where dem enable am) longer one, reach di limit wey dem set.

5. Security

We dey use encryption while data dey move and while e dey rest, tenant isolation, role-based access control, secret management (GCP Secret Manager), audit logging, and regular threat modeling.

6. Data sharing and subprocessor

We dey use selected infrastructure and service provider (e.g., Google Cloud Platform, MongoDB Atlas, Stripe, Google Workspace). Each one dey under contract with correct data protection terms. We no dey sell personal data.

7. Transfer to other country

Dem fit process data for di United States. Where e dey necessary, we dey apply transfer mechanism (e.g., SCCs).

8. Your rights

Depending on your jurisdiction, your rights fit include: access, correction, deletion, restriction, portability and objection. Reach us make you use dis rights. We go verify di request and answer within di time wey law set.

9. Cookies and tracking

We dey use essential cookie and small analytics. No third-party advertising network. Cookie consent interface go show for future where law require am.

10. Pikin dem

Di Services no be for pikin wey neva reach 16 years. We no dey collect data from minor on purpose. If we find out, we go delete am.

11. Changes

We fit update dis policy for legal, technical abi operational reason. If big change happen, we go announce am through dashboard abi email notice.

12. Contact

For privacy question abi rights request: privacy@threada.ai