Privacy Policy
Last updated: 16 June 2026
This policy explains what data Threadwork collects, why, and the choices you have. We aim to collect only what's needed to run the service, and we never sell your data.
Who this applies to
This policy describes how Threadwork handles personal data when your team uses the service. The organisation (your employer or whoever invited you) is the controller of the work content; Threadwork processes it on their behalf to provide the service.
What we collect
Account data: your name, email address, optional avatar, role and notification preferences.
Work content you and your team create: organisations, workspaces, projects, threads, posts and blocks, comments, reactions, tags, time logs, budgets, rooms and messages, and the flexible "contexts" you define.
Operational data needed to run the service: authentication sessions, audit-style timestamps (created/updated), and basic technical logs (such as request errors) used to keep the service reliable and secure.
How we use it
To provide the core service — sign-in, showing your team's work, sending the notifications you've opted into, and producing the reports you ask for.
To keep the service secure and working — preventing abuse, diagnosing errors and protecting accounts.
We do not sell your personal data, and we do not use your work content to advertise to you.
Authentication & security
Sign-in uses secure, single-use magic links and optional passwords or passkeys. Passwords, when used, are stored only as salted hashes — never in plain text.
Access to your organisation's data is confined to members of that organisation, enforced on every request. Private workspaces are further limited to their members.
Cookies & sessions
Threadwork sets a small number of strictly-necessary cookies to keep you signed in and to remember light preferences (such as light/dark mode). It does not use advertising or cross-site tracking cookies.
Sharing & sub-processors
We share personal data only with infrastructure providers needed to run the service — for example a managed database host and a transactional email provider that delivers your sign-in links and notifications — and only to the extent needed to provide Threadwork. The operator of this instance should maintain the current list of these sub-processors.
We may disclose data if required by law, or to protect the rights, safety and security of users and the service.
Retention & deletion
We keep your data for as long as your account and organisation are active. You can ask to export or delete your data; on a verified deletion request we remove it within a reasonable period, except where we must retain limited records to meet legal obligations.
Disappearing posts are removed from view once their timer expires, and can be permanently purged by an organisation owner or admin.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise them, contact your organisation's owner or the administrator of this instance, who can action most requests directly within Threadwork.
Children
Threadwork is a workplace tool intended for business use and is not directed at children.
Changes & contact
We may update this policy as the service evolves; we'll revise the "last updated" date above when we do.
For privacy questions, contact your workspace owner or the administrator of this Threadwork instance.