Legal

Privacy Policy

Last updated: 2026-08-10. This policy explains what Threadline does with your data, what we ask Google for on your behalf, and how you can delete it.

1. Who we are

Threadline(“Threadline”, “we”, “us”) is the always-on AI email assistant described at the top of this site. If you have any question this page doesn’t answer, write to threadline-solutions@polsia.app.

2. What Threadline does and the data we need

Threadline connects to a Gmail inbox to power a small, focused set of features. We don’t read the whole mailbox for any other purpose. The features are:

  • Triage — pulling inbound mail, scoring it for importance, and surfacing the threads that need you.
  • Drafting replies— generating reply drafts in Threadline’s compose surface that match your voice, which you review and send yourself.
  • Snooze and schedule — letting you put a thread aside and return to it at a chosen time, plus scheduling a draft to go out at a chosen send time.
  • Inbox rules — plain-English rules that route and label threads for you.
  • Action items — pulling tasks and follow-ups out of threads if you ask.
  • Scheduling proposals — when a thread is about meeting at a time, drafting a Calendar event that you accept or decline.

3. Google account data we access and what we do with it

We use Google OAuth to authenticate you and to be granted specific, narrow permissions. We request onlythe seven scopes below — no Drive, Contacts, Photos, or any other Google Workspace surface. The OAuth client, redirect URIs, and grant flow are unchanged whether or not you sign in via Google or by email + password.

The scopes we request

openid
Standard sign-in identity from Google.
email
Your Gmail address, used as your Threadline identity.
profile
Your display name and basic profile fields, used in app UI.
gmail.readonly
Fetch and triage inbound mail; read thread and message metadata.
gmail.send
Send mail on your behalf only when you click Send in the app.
gmail.modify
Archive a thread (remove the INBOX label) when you archive; never permanently delete.
calendar.events
Create a matching Calendar event when you accept a scheduling proposal.

We request offline accessso that we can store a refresh token and keep your mailbox syncing in the background between sessions. That token lives on your Threadline Account row, encrypted at rest by the managed database provider. You can revoke this grant at any time from your Google Account → Security → Third-party apps; revocation is instant on Google’s side.

We do not receive, store, or request any Google Workspace scope beyond the seven above. If a future feature needs something else, we will explicitly request that scope and update this policy before we do.

4. AI processing

When you ask Threadline to draft a reply, snooze a thread, surface an action item, or propose a meeting time, we send the smallest relevant excerpt of the thread (and your voice profile, where it applies) to a third-party AI model provider accessed through our infrastructure. We never send an entire inbox to the model.

The model providers we use are contractually bound not to retain request content beyond the inference and not to train on it. We do not name the underlying model in this policy because providers may change over time; what we promise is unchanged: your content is used to produce the output you asked for, and nothing more.

No human reads your inbox as part of normal operation. In the rare case our support staff triages a bug you reported to us, they see only the anonymized diagnostic information you sent in the support request — never the inbox itself.

5. How we don’t use your data

We do not sell, share, rent, or surface your email content to third parties for marketing, advertising, training of any general-purpose AI model, or any purpose unrelated to providing Threadline’s features to you.

We do not use your email content to train any general-purpose AI model. The model that produces drafts sees your content only as input to that specific request.

6. Data we store

To do the things above, we store the following per-account:

  • Account row. Your email, display name, and the sign-in providers linked to your Threadline account.
  • OAuth tokens. Your Google access and refresh tokens, stored encrypted at rest on the same database as the rest of your data.
  • Cached Gmail messages.Subject, from/to participants, body text, snippet, labels, importance score, and a soft-delete flag for messages we’ve triaged. We do not cache attachments as files.
  • Drafts, rules, scheduled-send queue, and scheduling proposals. All per-user rows created for your features.
  • Voice / style profile. Aggregated statistics (typical sentence length, common greetings and sign-offs, formality level) only. We never store raw email body for voice-training purposes.
  • User feedback labels. The thumbs-up / thumbs-down labels you give on importance predictions, used to keep importance ranking tuned to you.
  • Billing entitlement. A row that identifies your current subscription tier (Free, Pro, Team) and cadence (monthly or annual). The actual payment record is held by our payment processor; we hold the entitlement, not your card.

7. Retention and deletion

We retain your data while your account is active and Gmail is connected. The two flows you can use to take data out of Threadline are:

Disconnecting Gmail

In Settings → Connections, you can disconnect Gmail. Doing so immediately revokes the OAuth grant on Google’s side and stops new sync. The cached Gmail rows we hold are marked deletedAt and excluded from all in-app views; we purge the soft-deleted rows on a routine maintenance cycle.

Deleting your Threadline account

To permanently delete your account and all associated Threadline data, contact us at threadline-solutions@polsia.app. We action verified deletion requests within a reasonable timeframe after confirming ownership through your registered email.

Revoking from Google

You can also revoke Threadline’s access to your Gmail at any time from your Google Account → Security → Third-party apps, without contacting us. Revocation is instant on Google’s side; on our side it triggers the same disconnect and soft-delete path as if you had used Settings → Connections.

Billing records

We keep the entitlement record for as long as required to honor refunds, chargebacks, and applicable finance / tax record-keeping. The payment processor retains the underlying payment record under their own retention policy.

8. Where data lives

Account, OAuth tokens, cached Gmail rows, drafts, rules, and entitlements are stored on a managed PostgreSQL database operated by our platform provider. We use that single primary store for everything except what the payment processor retains on their side. Backups are encrypted at rest and held by the platform provider.

9. Your rights

  • Access. Your Inbox view is your live data; cached rows are the same rows the app shows you.
  • Correction.Voice traits and your style profile are editable from Settings → Voice.
  • Deletion. See Section 7.
  • Portability. You can request an export of your Threadline data (account row, cached Gmail rows, drafts, rules) by writing to threadline-solutions@polsia.app.

10. Children’s privacy

Threadline is not directed at children under 13 and you may not use it if you are under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has created an account, write to threadline-solutions@polsia.app and we will delete the account.

11. Changes to this policy

If we materially change how we handle your data, we will update the “Last updated” date at the top of this page and surface a notice in-app before the change takes effect, so you have a chance to review, disconnect Gmail, or close your account before the new terms apply.

12. Contact

Questions, deletion requests, and data-export requests: threadline-solutions@polsia.app.

Looking for the terms that govern your use of Threadline? See the Terms of Service.