Privacy Policy
Last updated: May 2026
What we collect
Account information: Your email address, display name, and password. Your password is hashed using bcrypt (cost factor 12) and is never stored in plaintext.
Comments: When you post a comment, we store the comment text, the URL of the page it appears on, and a timestamp.
Session data: When you log in, we set an HTTP-only session cookie. This cookie does not track you across sites and is deleted when you log out or after 7 days of inactivity.
IP addresses: We do not store IP addresses for commenters or in our analytics system. IP addresses are used transiently in memory for rate limiting (to prevent abuse) and are not written to persistent storage for this purpose. IP addresses are recorded in admin audit logs for security auditing of administrative actions only.
What we never do
- Sell individual user data — under any circumstances, at any price
- Use behavioral targeting for ads — contextual topics only
- Share data with advertising networks or data brokers
- Track users across different websites
- Set tracking cookies on visitors who are not logged in
- Store IP addresses of commenters or visitors in our analytics database
How we use your data
Email: Account authentication, password reset, and essential service notifications (e.g., email verification). We do not send marketing emails without your consent.
Comments: Displaying them on the publisher's site and in the moderation dashboard.
Display name: Attributing comments to you publicly.
Analytics: Aggregated, anonymized pageview counts for publishers. No individual visitor tracking.
Your rights (GDPR / CCPA)
You have the right to:
- Access: Request a copy of all data we hold about you
- Export: Download your full comment history and identity data as JSON
- Delete: Schedule account deletion (30-day recovery window) from account settings
- Correct: Update your display name, email, or other profile information
- Object: Opt out of any processing you disagree with
To exercise these rights: use the export and delete options in your account settings, or email privacy@threadline.io. We respond to all requests within 30 days.
Data retention
Your account data: Retained until you delete your account, with a 30-day recovery period before permanent deletion.
Comments: Stay visible on sites where the embed is installed when a publisher closes their account; new comments are disabled until the embed is removed from the site or the account is restored. After permanent account deletion, your comments are anonymized.
Anonymized analytics: Aggregated pageview counts are retained for up to 2 years.
Moderation logs: Retained for 6 years for legal compliance.
Audit logs: Retained for 1 year for security purposes.
Publishers (Data Controllers)
If you embed Threadline on your site, you are a data controller for your visitors' comment data. Threadline acts as your data processor. We process comment data only on your behalf and in accordance with your instructions.
Our standard Data Processing Agreement (DPA) is available to download from the GDPR page. Publisher plan customers can request a countersigned copy at privacy@threadline.io.
Security
Passwords are hashed with bcrypt (cost factor 12). Session cookies are HTTP-only and SameSite=Strict. All data in transit is encrypted via TLS. Database access is restricted to authorized personnel.
Cookies
On first visit to threadline.io we show a cookie notice. We use essential cookies only (sign-in and security). Your acknowledgment is stored in your browser so we do not show the banner again. Details are in our Cookie Policy.
Contact
Privacy questions: privacy@threadline.io
Data deletion requests: dsar@threadline.io