Privacy Policy

Effective Date: April 7, 2026
Website: https://www.threadlift.io

1. Introduction

This Privacy Policy describes how Kristyna Zackova, doing business as ThreadLift ("we," "us," or "our"), collects, uses, and protects your personal information when you use the website https://www.threadlift.io and related services (the "Service").

By using the Service, you consent to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, and password when you create an account
  • Payment information: credit card details processed securely through Stripe (we do not store your full card number)
  • Campaign data: keywords, topics, guidance, and other configuration you provide when setting up campaigns
  • Draft edits: modifications you make to AI-generated draft replies

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, actions taken within the Service
  • Device information: browser type, operating system, IP address
  • Cookies: session cookies used to maintain your login state

2.3 Information from Third-Party Platforms

  • Public content: publicly available posts, comments, and threads from platforms such as Reddit and Quora, collected as part of the Service's discovery features
  • We do not collect private or non-public data from third-party platforms

ThreadLift is not affiliated with, endorsed by, or sponsored by any third-party platform from which content is sourced.

2.4 Your Responsibility for Data You Provide

You are responsible for ensuring that any data you provide to the Service, including campaign inputs and content, does not violate applicable laws or the rights of third parties.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process your subscription and payments
  • Discover relevant public conversations based on your campaign settings
  • Generate AI-powered draft replies for your review
  • Maintain an audit trail of actions within the Service
  • Communicate with you about your account or the Service
  • Improve and develop new features
  • Comply with legal obligations

Legal Bases for Processing

We process personal data on the following legal bases:

  • Performance of a contract: to provide the Service as agreed when you subscribe
  • Legitimate interests: to improve and operate the Service, including analytics and feature development
  • Legal obligations: where required by applicable law, regulation, or legal process
  • Consent: where explicitly obtained, such as for optional communications

4. How We Share Your Information

We do not sell your personal information. We may share information with:

  • Stripe: to process payments and manage subscriptions
  • Anthropic: to generate AI-powered draft replies (campaign guidance and public thread content may be sent to Anthropic's API). We do not control how third-party AI providers process data once it is transmitted to them, and their use of data is governed by their own privacy policies.
  • Hosting providers: Vercel (hosting) and Neon (database) to operate the Service
  • Legal authorities: if required by law, regulation, or legal process

We require all third-party providers to handle your data in accordance with applicable privacy laws.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data: retained until you delete your account
  • Campaign and opportunity data: retained for the duration of your subscription
  • Audit logs: retained for up to 12 months
  • Payment records: retained as required by tax and financial regulations

You may request deletion of your account by contacting us or through account settings. Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

6. Cookies

We use essential cookies to:

  • Maintain your authenticated session
  • Remember your login state

We do not use tracking cookies, advertising cookies, or third-party analytics cookies at this time.

7. Data Security

We implement reasonable security measures to protect your information, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Hashed passwords (bcrypt)
  • Secure, httpOnly session cookies
  • Access controls limiting data access to authorized personnel

No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but will notify affected users of a data breach where required by applicable law.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your personal data
  • Export your data in a portable format
  • Withdraw consent where processing is based on consent
  • Object to certain types of processing

To exercise any of these rights, contact us at customer-care@threadlift.io.

9. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it.

10. International Data Transfers

Your data may be processed and stored in the United States. We rely on appropriate safeguards for international data transfers, including standard contractual clauses where applicable.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the effective date. We may, but are not obligated to, notify you of significant changes via email or the Service. Continued use of the Service after changes constitutes acceptance.

12. Contact Information

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us:

Operator: Kristyna Zackova (doing business as ThreadLift)

Email: customer-care@threadlift.io