← ThreadsHub
Privacy Policy
Last updated: May 4, 2026
1. Who we are
ThreadsHub ("we", "our", "us") is a multi-account management dashboard for the Threads platform by Meta. We are an independent service and are not affiliated with Meta Platforms, Inc.
2. Data we collect
- Account credentials: your email address and a hashed (bcrypt) password to authenticate you on ThreadsHub.
- Threads access tokens: OAuth tokens issued by Meta, stored securely in our database to interact with the Threads API on your behalf.
- Content you create: posts, images, text presets, and routines you save inside the app.
- Usage data: basic server logs (IP address, timestamps) for security and debugging purposes.
3. How we use your data
- To publish, schedule, and manage Threads posts on your behalf.
- To display analytics and insights from the Threads API.
- To sync your content across devices.
- We do not sell, share, or rent your data to any third party.
4. Threads API & Meta permissions
ThreadsHub uses the Threads API. By connecting your Threads account you authorize us to act on your behalf using the following permissions: threads_basic, threads_content_publish, threads_manage_replies, threads_read_replies, threads_manage_insights, threads_delete. You can revoke this access at any time from your Threads settings.
5. Third-party services & sub-processors
ThreadsHub uses the following third-party services to operate. Each may process some of your data as described:
- Railway (USA) — application hosting and PostgreSQL database. All user data transits through Railway infrastructure.
- Cloudflare R2 (USA) — cloud storage for images uploaded by users.
- Anthropic (USA) — AI caption generation. Only used when you explicitly request AI-generated content using your own Anthropic API key. Post text and images may be sent to Anthropic's API.
- Resend (USA) — transactional email service used to send account emails (welcome and password reset).
- Bonzai (Estonia) — payment processing, subscription management and affiliate tracking. Your email address and payment details are processed by Bonzai when you subscribe to a paid plan.
- Google Fonts (USA) — font delivery. Google may collect limited technical data (IP address, browser type) as part of this service.
No advertising or tracking cookies are used by ThreadsHub. We do not sell your data to any third party.
Data may be transferred to and processed in the United States. Where required, such transfers are subject to appropriate safeguards in accordance with applicable data protection law (including GDPR standard contractual clauses where applicable).
6. Legal basis for processing (GDPR)
If you are located in the European Economic Area, we process your personal data on the following legal bases:
- Contract performance: processing necessary to provide the ThreadsHub service you signed up for.
- Legitimate interest: server logs for security and abuse prevention.
- Consent: connecting your Threads account via OAuth.
7. Your rights (GDPR)
- Access: request a copy of all personal data we hold about you.
- Rectification: request correction of inaccurate data.
- Erasure: request deletion of your account and all associated data.
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on legitimate interest.
To exercise any of these rights, you can delete your account directly from the app (Settings → Delete account) or visit our Data Deletion page for full instructions. We will respond to any written requests within 30 days.
8. Data retention
Your data is retained as long as your account is active. Deleted accounts and their associated data are permanently removed within 30 days. For step-by-step deletion instructions, visit threadshub.app/data-deletion.
9. Security
Passwords are hashed using bcrypt and never stored in plain text. Access tokens are encrypted using AES-256-CBC before being stored in our database. All communications are encrypted via HTTPS.
10. Contact
For any privacy-related questions or to exercise your rights: [email protected]