Thredary Privacy Policy

1. Introduction

Thredary respects your privacy and is designed around the principle of data minimisation.

This Privacy Policy explains how personal data is handled when you:

* use the Thredary macOS application (“Thredary” or the “Application”); * visit thredary.com (the “Website”); * purchase or manage a Thredary licence or subscription; * activate Thredary on a device; or * contact us for support.

There is an important distinction between the Application and the Website.

The Thredary Application is primarily a local application. Your AI conversations, prompts, projects, folders and conversation archives are not uploaded to Thredary’s licensing website or stored in Thredary’s licensing systems.

The Website provides information about Thredary and services associated with purchasing, licensing, subscription management and activation.

This policy is intended to comply with applicable privacy and data protection laws, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the EU General Data Protection Regulation (“EU GDPR”), and applicable privacy laws in other jurisdictions in which Thredary is made available.

⸻

Part I — The Thredary Application

2. Privacy by Design

Thredary is designed as a local-first application.

Conversation archives, saved prompts, projects, folders and related organisational information are stored:

* locally on your Mac; or * where you enable the relevant functionality, within an iCloud container associated with your Apple Account.

Thredary does not operate a central cloud service for storing your AI conversation archive.

Your locally stored conversation content is not transmitted to the Thredary Website or Thredary licensing systems simply because you use the Application.

3. AI Conversation and Prompt Data

Thredary enables you to organise and retain conversations and prompts associated with supported artificial intelligence services.

This information may include:

* conversation titles; * conversation content; * prompts; * responses; * organisational metadata; * project and folder information; * provider information; and * other information required to organise your locally maintained conversation archive.

This information remains under your control and is stored locally or, if you choose to use iCloud functionality, within your configured iCloud storage.

Thredary does not use your archived conversations or prompts for advertising, profiling, data brokerage or the training of artificial intelligence models.

Thredary does not sell your conversation data.

4. iCloud Storage

If you enable iCloud functionality, information stored by Thredary may be stored or synchronised using Apple’s iCloud infrastructure.

Your use of iCloud is subject to the terms and privacy policies applicable to your Apple Account and Apple’s services.

Thredary does not receive your Apple Account password.

Data stored in your private iCloud environment remains subject to Apple’s infrastructure, security and data-processing arrangements.

You may choose not to use iCloud where the Application provides local-only storage functionality.

5. ChatGPT and Other AI Provider Authentication

Where Thredary provides integration with ChatGPT, authentication takes place through the ChatGPT web experience presented within the Application.

Thredary does not ask for, collect or store your ChatGPT password.

Authentication credentials, session information and access controls used by ChatGPT remain subject to the systems and policies of the relevant AI provider.

Thredary does not represent itself as ChatGPT and does not provide ChatGPT accounts.

The same principle applies where support for additional AI providers is introduced: authentication remains subject to the relevant provider’s systems and terms unless explicitly stated otherwise.

6. AI Provider Security and Access Controls

Thredary is an organisational and productivity application.

It is not designed or intended to circumvent, defeat or interfere with:

* authentication requirements; * account permissions; * security mechanisms; * access controls; * rate limits; * usage restrictions; * subscription restrictions; or * other technical protections imposed by ChatGPT or another AI provider.

Thredary operates within the access available to the user through the relevant provider.

Its conversation-management functionality is intended to allow users to organise, retain and, where supported, reuse or replay prompts and conversation material for their own legitimate use.

Use of any third-party AI service remains subject to that provider’s terms, policies, account requirements and technical restrictions.

7. No Sale or Monetisation of Conversation Data

Thredary does not:

* sell your conversation archives; * sell your prompts; * sell your AI responses; * use conversation content for targeted advertising; * create advertising profiles from your conversations; * provide conversation archives to data brokers; or * use your conversation archive to train Thredary-owned artificial intelligence models.

8. Deleting Application Data

Because Thredary’s conversation archive is primarily stored locally, you remain in control of that data through the Application and your device.

Deleting locally stored information removes that information from the relevant local Thredary data store, subject to normal operating-system backups and storage behaviour.

Where information is synchronised using iCloud, deletion and retention may additionally be affected by Apple’s iCloud synchronisation, backup and recovery mechanisms.

⸻

Part II — The Thredary Website, Licensing and Purchases

9. Information Processed by the Website

The Thredary Website does not receive or store your Thredary conversation archive or saved AI prompts.

The Website and associated licensing systems may, however, process limited personal data necessary to provide commercial and support services.

Depending upon how you use Thredary, this may include:

* your email address; * licence type and licence status; * subscription status; * Stripe customer identifiers; * Stripe subscription identifiers; * purchase and transaction references; * activated-device identifiers; * activation dates and status; * basic Application and device metadata; * operating-system and Application version information; * IP addresses and security/server logs where generated as part of normal web hosting or security operations; and * information you voluntarily provide when requesting support.

This information is not used to build advertising profiles or to analyse the contents of your AI conversations.

10. Why We Process This Information

Licensing and account-related information is processed only where reasonably necessary to:

* process purchases; * provide and manage subscriptions; * issue and validate licences; * activate authorised devices; * manage subscription and licence status; * prevent fraudulent or unauthorised licence use; * maintain the security and integrity of the licensing service; * provide customer and technical support; * maintain appropriate transaction and accounting records; and * comply with applicable legal obligations.

We do not use licence activation information for behavioural advertising.

11. Lawful Bases Under UK and EU Data Protection Law

Where the UK GDPR or EU GDPR applies, our principal lawful bases are:

Performance of a Contract

We process information such as your email address, licence details, subscription information and activation information where necessary to provide the software, licence or subscription you have requested.

Legal Obligations

Certain transaction, accounting and business records may be retained where necessary to comply with tax, accounting, fraud-prevention or other legal requirements.

Legitimate Interests

Limited information may be processed where necessary for our legitimate interests in:

* securing the Website and licensing infrastructure; * preventing fraud and licence abuse; * diagnosing technical problems; * responding to support enquiries; and * protecting Thredary, its systems and its users.

Where legitimate interests are relied upon, those interests are considered against the rights and reasonable expectations of affected individuals.

Consent

Where applicable law requires consent for a particular form of processing, including certain non-essential cookies or electronic marketing, consent will be requested separately.

Consent may be withdrawn where applicable.

12. Payments and Stripe

Payments for Thredary may be processed by Stripe.

Thredary does not store your complete payment-card number, card security code or equivalent sensitive payment credentials on its own systems.

Payment-card information is submitted to and processed by Stripe and relevant payment networks or financial institutions.

Thredary may receive and retain information from Stripe necessary to manage your purchase or subscription, including:

* Stripe customer identifiers; * subscription identifiers; * transaction identifiers; * payment or subscription status; and * limited transaction information necessary for accounting, support and licence administration.

Stripe processes personal data according to its own legal obligations, contractual arrangements and privacy policies.

13. Sharing of Personal Data

Thredary does not sell or rent personal data.

We do not provide customer email addresses to unrelated organisations for their own advertising or marketing purposes.

Personal data may be disclosed only where reasonably necessary to organisations providing services required to operate Thredary, such as:

* Stripe for payment and subscription processing; * Apple where you choose to use Apple or iCloud services; * infrastructure or hosting providers necessary to operate the Website and licensing service; or * professional advisers, regulators, courts or public authorities where disclosure is required by law.

Service providers are expected to process information only for legitimate service purposes and subject to applicable data-protection requirements.

We may also disclose information where reasonably necessary to establish, exercise or defend legal claims or protect against fraud, abuse or security threats.

14. Cookies and Website Tracking

Thredary aims to minimise tracking.

The Website may use cookies or similar technologies that are strictly necessary for functions such as security, session management, purchases, subscription management or other services requested by the user.

Where non-essential analytics, advertising or similar tracking technologies are introduced, they will be subject to appropriate transparency and consent requirements where required by applicable law.

Thredary does not use your Application conversation archive for website tracking or advertising.

15. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected or where retention is required by law.

For example:

* licence information may be retained while a licence remains valid and for a reasonable period afterwards; * subscription information may be retained for the duration of the subscription and as necessary for subsequent accounting, support or legal requirements; * transaction records may be retained for periods required by applicable tax and accounting legislation; * security records may be retained for a limited period appropriate to investigating security incidents or fraud; and * support correspondence may be retained where necessary to resolve issues and maintain an appropriate history of customer support.

When personal data is no longer required, it will be deleted, anonymised or otherwise disposed of appropriately, subject to legal and technical requirements.

Conversation archives stored locally or in your iCloud environment are controlled separately from Thredary’s licensing systems.

16. International Data Transfers

Some service providers used to operate Thredary may process information in countries outside the United Kingdom or European Economic Area.

Where UK or EU data protection legislation applies and a restricted international transfer occurs, appropriate safeguards will be used as required by applicable law. These may include adequacy regulations or decisions, approved contractual safeguards or other legally recognised transfer mechanisms.

Third-party providers may also operate their own international infrastructure under their respective privacy and data-protection arrangements.

17. Your Privacy Rights

Depending on your jurisdiction, you may have rights concerning personal data that Thredary controls.

Under the UK GDPR and EU GDPR, these can include the right to:

* obtain information about how your personal data is processed; * request access to your personal data; * request correction of inaccurate personal data; * request deletion of personal data in appropriate circumstances; * request restriction of processing; * object to certain processing; * receive certain information in a portable format; * withdraw consent where processing is based on consent; and * complain to an appropriate data-protection supervisory authority.

These rights are subject to applicable legal conditions and exemptions.

Because Thredary does not centrally hold your local conversation archive, we may be unable to retrieve conversation information stored exclusively on your device or within your private iCloud environment. Such information should normally be managed directly through the Application, your Mac or your Apple/iCloud services.

18. California and Other US Privacy Rights

Where applicable US state privacy legislation provides additional rights, including rights to know, access, correct or delete personal information, Thredary will honour those rights to the extent required by applicable law.

Thredary does not sell personal information.

Thredary does not sell or share personal information for cross-context behavioural advertising.

Thredary does not use Application conversation archives for targeted advertising.

19. Users in Other Countries

Thredary is available internationally.

Where local privacy legislation applies to our processing of your personal data, we will process that information consistently with applicable legal requirements.

Nothing in this Privacy Policy is intended to limit statutory privacy rights that cannot lawfully be excluded.

20. Security

Reasonable technical and organisational measures are used to protect personal data processed through Thredary’s Website and licensing infrastructure against unauthorised access, alteration, disclosure or destruction.

No electronic storage or transmission system can be guaranteed to be completely secure.

Users are responsible for maintaining appropriate security for their Mac, Apple Account, AI-provider accounts and other credentials.

21. Children

Thredary is a general-purpose productivity application and is not specifically directed at children.

We do not knowingly use the Website or licensing system to collect personal data from children for advertising or profiling.

Users must comply with any minimum-age requirements imposed by the AI providers and other third-party services they choose to use through or alongside Thredary.

22. Third-Party Services

Thredary may interact with or provide access to third-party services.

Those services operate under their own terms, privacy policies and data-processing practices.

Thredary is not responsible for the privacy practices of independent third-party services.

Users should review the applicable terms and privacy policies before using those services.

23. Independence from AI Providers

Thredary is an independent product.

Thredary is not affiliated with, endorsed by, sponsored by or officially connected with OpenAI, ChatGPT, Anthropic, Claude, Google, Gemini, or any other artificial intelligence provider referenced by the Application or Website, unless expressly stated otherwise.

All third-party names, trademarks and service marks belong to their respective owners.

References to third-party AI products are made solely to describe compatibility, interoperability or functionality.

24. Automated Decision-Making

Thredary does not use personal data from its licensing systems to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.

Automated licence validation and fraud/security controls may be used to determine whether a licence or activation is technically valid. Where an activation is incorrectly refused, users may contact us for support.

25. Data Breaches

Where a personal-data breach affecting information controlled by Thredary occurs, we will investigate the incident and, where required by applicable data-protection law, notify the relevant supervisory authority and affected individuals.

26. Business Transfers

If the business or assets associated with Thredary are reorganised, acquired or transferred, limited personal data associated with licences, subscriptions and customers may form part of that transaction where legally permitted.

Any recipient would remain subject to applicable data-protection obligations.

Conversation archives stored solely on users’ devices or within their private iCloud environments are not part of Thredary’s central customer database.

27. Changes to this Privacy Policy

This Privacy Policy may be updated from time to time to reflect changes to Thredary, applicable law, service providers or our privacy practices.

The current version will be published on the Thredary Website together with its effective or last-updated date.

Material changes affecting how personal data is processed will be communicated where required by applicable law.

28. Contact and Data Protection Requests

Questions concerning this Privacy Policy or requests concerning personal data can be submitted using the contact details published on the Thredary Website.

Requests will be handled in accordance with applicable data-protection legislation.

Where required, we may need to verify your identity before fulfilling a data-protection request.

UK users also have the right to complain to the Information Commissioner’s Office (ICO).

Users in the European Economic Area may contact the competent supervisory authority in their country where applicable.

⸻

Privacy Summary

Thredary has been designed around a straightforward privacy model:

Your conversations belong to you.

Your Thredary conversation archive is stored locally on your Mac or, where you choose to enable it, using your configured iCloud storage.

Thredary does not require your ChatGPT password.

Thredary does not upload your conversation archive to its licensing Website.

Thredary does not sell your conversations, prompts or personal information.

The Thredary Website processes only the limited information reasonably required for purchasing, licensing, subscriptions, activation, security and support.

Payment-card information is handled by Stripe rather than being stored by Thredary.

Thredary is independent of OpenAI, ChatGPT and other AI providers.