Skip to content
Data handling

How Threada uses your data with AI

Threada uses AI to turn your requests into grounded answers and governed actions. This page states plainly how your data is used in that process — and where the binding terms live.

What follows is the short, citable version of our AI data posture: what we do and do not do with Customer Content, where it is indexed, how long it is kept, which model providers are involved, and what third-party attestations we currently publish. Each point links to the canonical page or contract that owns the detail.

We do not train foundation models on your content

Threada does not train foundation models with Customer Content. This is a binding commitment in our Terms of Service (§4, Customer Content), not just a stance: you retain ownership of your content, and we process it under a limited license solely to provide and improve the Service for you.

Retrieval, not training

Your content is indexed for retrieval, not for training. When Threada answers, it retrieves relevant passages from the sources you have approved and grounds the response in them with citations. The index exists to find and cite your knowledge at answer time; it is not used to retrain a shared model.

Retention you control

Retention is configurable per workspace. Work history and analytics, configuration, and audit records each have their own retention windows, and on contract termination customer data is deleted within 90 days unless a longer period is required by law. The Data Processing Addendum and Privacy Policy state the specifics.

Model providers

Threada uses named model providers for inference and embeddings — currently OpenAI and Google (Gemini) — each engaged as a subprocessor under appropriate data-protection terms. The current list, with each provider's purpose and location, is published on the subprocessors page and updated with advance notice of material changes.

Certifications and attestations

Threada does not currently publish a third-party security attestation such as SOC 2 Type II or ISO 27001. What we do publish and keep current is the underlying control evidence — our security architecture, threat model, subprocessor list, and Data Processing Addendum — so the controls behind our claims are inspectable today. If your review requires attestation status, contact us for the latest documentation.

Frequently asked questions

Does Threada train AI models on our data?
No. Threada does not train foundation models with Customer Content. Your content is indexed for retrieval only and processed under a limited license solely to provide and improve the Service for you, as set out in the Terms of Service.
Is our content used to improve a shared model other customers benefit from?
No. Content is retrieved and cited at answer time within your workspace; it is not used to retrain a shared foundation model. Tenant boundaries keep one customer's content from informing another customer's results.
How long do you keep our data?
Retention is configurable per workspace, with separate windows for work history, configuration, and audit records. On contract termination, customer data is deleted within 90 days unless a longer period is required by law. The DPA and Privacy Policy state the specifics.
Which AI providers does Threada use?
Threada uses named model providers for inference and embeddings — currently OpenAI and Google (Gemini) — each engaged as a subprocessor under appropriate data-protection terms. The full, current list is on the subprocessors page.
Do you have SOC 2 or ISO 27001?
Threada does not currently publish a third-party attestation such as SOC 2 Type II or ISO 27001. We publish the underlying control evidence — security architecture, threat model, subprocessors, and the DPA — and can provide current documentation for enterprise reviews on request.

Need this in writing for a review?

We can provide current data-handling and security documentation for your assessment.