Privacy policy
How ThreadCue handles information
This policy describes the public website and the current development version of the ThreadCue desktop application. It distinguishes implemented behavior from planned functionality.
1. Who operates ThreadCue
ThreadCue is operated by GLOBALCARD NETWORKS LIMITED (UK company registration number 15534843), registered at 71-75, Shelton Street, Covent Garden, WC2H 9JQ, United Kingdom. Privacy questions can be sent to getthreadcue@gmail.com.
2. Controller and website data
GLOBALCARD NETWORKS LIMITED is the data controller for personal data collected through the ThreadCue website, waitlist, and hosted ThreadCue services because it determines why and how that data is processed. Workspace information that remains only in the local desktop application is not received by GLOBALCARD NETWORKS LIMITED.
When you join the waitlist, the website stores the email address you enter, a normalized copy used to prevent duplicate entries, the UTC submission time, the consent-policy version, and the page that submitted the request. The website does not intentionally store a raw IP address with the waitlist record.
IP addresses are processed transiently by in-memory rate limiting to reduce abuse. The website uses an invisible honeypot field and an HttpOnly, SameSite antiforgery cookie that is necessary to secure form submissions. No advertising or analytics SDK is installed, and the site does not set marketing cookies.
The production reverse proxy and server may keep ordinary security and access logs containing an IP address, user agent, requested path, response status, and request time. These logs are access-restricted and retained only as needed for security and operations, ordinarily for no more than 30 days.
3. Purposes and lawful bases
The waitlist email address is used only for ThreadCue development updates, early-access invitations, and necessary messages about the waitlist. It is not sold. This processing is based on the consent given with the waitlist form, which can be withdrawn at any time by contacting us.
Security, fraud prevention, rate limiting, and essential service operation are based on GLOBALCARD NETWORKS LIMITED's legitimate interests in protecting and operating ThreadCue. Where a person is invited into an early-access service, processing needed to provide that access may also be necessary to take steps at their request or perform the applicable agreement. Information may be processed where necessary to comply with a legal obligation.
No email-delivery or CRM provider is connected to the current waitlist. Introducing one requires this policy and the provider record to be updated before waitlist addresses are transferred.
4. Desktop workspace data
The current desktop application stores project profiles, onboarding conversations, monitoring configuration, tasks, drafts, schedules, connection metadata, and captured source snapshots in a local SQLite database on the user’s device. That database is not encrypted. Provider secrets are stored separately in files protected by ASP.NET Core Data Protection; the production direction is to add operating-system credential-vault adapters.
ThreadCue currently has no cloud sync, team workspace, or production user-account service. Password, Google, and Apple sign-in shown in the prototype are simulated.
5. Reddit account and public-content data
The approval-gated Reddit connector requests identity, mysubreddits, and read. These permissions are used to identify the connected account, read its subscribed communities, and retrieve matching public communities, posts, and comments. ThreadCue does not request permissions to submit, vote, save, subscribe, message, read account history, or moderate.
Reddit client credentials and Reddit access and refresh tokens remain on ThreadCue’s hosted gateway. The desktop stores an encrypted opaque gateway credential plus account/profile metadata. The gateway does not store Reddit post or comment bodies; selected source snapshots are stored in the local desktop database.
6. External AI providers
A user may configure an OpenAI API key in the prototype. Eligible demo-source drafting and revision inputs can then be sent to the OpenAI API, including during monitoring while the desktop app is open. Onboarding extraction and opportunity classification remain deterministic and local in the current implementation.
Live Reddit text is deliberately excluded from external AI-provider prompts. Switching to Demo AI does not yet delete a previously stored OpenAI configuration or credential; removal UX is a known pre-release gap.
Anthropic is not connected in the current product. If an Anthropic integration is introduced, it will process context only when a user explicitly enables and uses that provider, and this policy will be updated before the integration is made available.
7. Retention
Live Reddit source snapshots are automatically removed after 48 hours by default; the supported configuration range is 24 to 168 hours. Derived opportunity tasks and drafts can remain after the source snapshot is removed, with the source relationship cleared. Disconnecting Reddit removes the gateway grant, local gateway credential, and account metadata, but it does not immediately purge every prior source snapshot or delete derived tasks.
Waitlist records are retained for 12 months from submission unless consent is renewed, the person joins an early-access service governed by an updated notice, or the record is deleted sooner at the person's request. The production waitlist database is backed up weekly. Backups are retained for no more than 30 days and then expire through normal rotation. A deleted record may remain in a restricted backup until that backup expires; if a backup is restored, verified deletion requests are reapplied before the restored waitlist is used.
8. Rights, deletion, and choices
Depending on the circumstances, UK data protection law may give you rights to access, correct, erase, restrict, or receive your personal data, object to processing, and withdraw consent. Requests are handled without undue delay and ordinarily within 30 days. If a lawful extension or exemption applies, we will explain it.
You can disconnect Reddit from the desktop Connections screen. Full local workspace deletion currently requires stopping ThreadCue and removing its local data directory. Waitlist deletion requests can be sent from the subscribed email address using the contact method below. See the data deletion instructions for exact steps and important limits.
You may complain to the UK Information Commissioner's Office at ico.org.uk, although we encourage you to contact us first so we can try to resolve the issue.
9. Hosting, providers, and recipients
The public website runs on a self-managed Coolify deployment hosted on server infrastructure in Frankfurt, Germany. Coolify is deployment software; the application does not send waitlist addresses to Coolify as a separate hosted service. The current website does not send waitlist data to a CRM, analytics provider, advertising network, or email-delivery service.
OpenAI receives eligible prompt content only when a user configures and uses the OpenAI feature described above. Anthropic does not currently receive ThreadCue data. Reddit processes account and platform data under its own terms when an approved user connects Reddit. Service providers may act as processors for GLOBALCARD NETWORKS LIMITED or as independent controllers depending on the specific processing and their terms.
10. Security
The website uses TLS in production, security headers, antiforgery protection, request-size limits, rate limiting, a unique database constraint, and restricted persistent storage. No system is risk-free. The desktop and gateway remain prototypes and have not completed an external security assessment.
11. International transfers and age
The website is hosted in Germany. A user-enabled external platform or AI provider may process information in other countries. Where GLOBALCARD NETWORKS LIMITED appoints a provider to process personal data on its behalf outside the United Kingdom, it will use a lawful UK transfer mechanism and appropriate contractual and security safeguards where required.
ThreadCue is intended only for people aged 18 or over. It is not directed to children, and we do not knowingly collect waitlist information from anyone under 18. Contact us if you believe a person under 18 has provided personal data.
12. Changes and contact
This policy will change as ThreadCue adds production infrastructure or integrations. Material changes should receive a new effective date and, where required, direct notice.
Contact: getthreadcue@gmail.com.