1. Who operates ThreadQuery
ThreadQuery is a service name used by an individual operator. That operator controls the personal information described in this policy.
Privacy requests may be sent to [email protected].
2. Information we collect
Account information
We collect your email address, a salted password hash, account status, short-lived hashed email-verification records, authentication-session records, and security settings. ThreadQuery does not store your plaintext account password or email-verification code.
API and usage information
We store API-key prefixes and hashes, labels, scopes, budgets, expiration and revocation state, endpoint usage, response status, credits charged, latency, idempotency references, and timestamps. Full API-key secrets are shown only when created and are not stored in recoverable form.
Connected X accounts
If you connect an X account, we store the account handle, health state, encrypted browser-session credentials, encrypted proxy credentials, key version, connection timestamps, and action/audit history. The extension connection request is short-lived, one-time, and stored only as a hash.
Credits and usage
We store evaluation-credit balances, credit-ledger entries, and usage records. ThreadQuery does not currently process customer payments.
Technical and support information
We may collect IP address, user agent, request time, endpoint, request identifiers, rate-limit events, error category, worker diagnostics, and security logs. We also retain information you send to support, privacy, legal, or abuse addresses.
3. How we use information
- provide, authenticate, and meter the service;
- route public reads and perform customer-authorized account actions;
- maintain credit, usage, action, and audit records;
- secure accounts, investigate abuse, enforce limits, and diagnose failures;
- respond to support, privacy, legal, and abuse requests;
- improve reliability and understand aggregate service performance; and
- comply with law and protect customers, ThreadQuery, and third parties.
4. Encrypted connected-account sessions
Connected-account credentials persist so ThreadQuery can perform later actions you authorize without asking for your X password on each request. Session and proxy credentials are encrypted in separate authenticated envelopes and are not returned through customer API responses.
Encryption reduces exposure but does not make stored credentials risk-free. When you disconnect an X account, ThreadQuery destroys the active credential envelopes so they cannot be used again. Disconnected account metadata, action history, and audit records remain. Encrypted backup copies may remain until the applicable backup-retention cycle expires.
7. Retention and deletion
Account records are generally retained while your account is active. Credential envelopes remain until you disconnect the X account, account closure requires their destruction, or a security response requires earlier revocation. Usage, ledger, action, fraud-prevention, security, and audit records may be retained after account closure when needed for dispute resolution, abuse prevention, system integrity, or legal obligations.
Retention periods depend on the record and operational need. When information is no longer required, it is deleted, aggregated, or de-identified where practical. You may request account closure or deletion at [email protected]. We may need to verify that the request comes from the account owner.
8. Security
ThreadQuery uses password hashing, hashed API keys and login tokens, scoped access, encryption of connected-account credentials, rate limits, audit records, and operational access controls. No service can guarantee absolute security. Report a suspected vulnerability or compromise to [email protected].
9. International processing
ThreadQuery and its service providers may process information in countries other than the country where you live. Where applicable law requires it, appropriate safeguards will be used for international transfers of personal information.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, or to object to or restrict certain processing. ThreadQuery does not discriminate against users for exercising applicable privacy rights.
Send requests to [email protected]. Include the account email and the nature of the request, but do not send passwords, API keys, X cookies, or wallet secrets.
11. Children
ThreadQuery is intended for adults and is not directed to anyone under 18. If you believe a minor provided personal information, contact the privacy address so the account can be reviewed.
12. Third-party services
The service interacts with X and other infrastructure providers. Their privacy practices are governed by their own policies. ThreadQuery is not responsible for third-party sites or services you access independently.
13. Changes and contact
We may update this policy when data practices, providers, features, or legal requirements change. The effective date above will be revised when an updated policy is published.
Contact [email protected] for privacy questions and [email protected] for ordinary account support.
