Privacy Policy
Threadback is privacy-first: zero upload, no telemetry. This policy explains in full what the extension and website do and do not collect, how it is used, where it is stored, who it is shared with, how long it is kept, and your rights. Last updated: 25 June 2026.
Scope of this policy
This policy applies to the Threadback browser extension and the Threadback website (threadback.dev), together "Threadback", "we", or "us". The extension is local-first: your conversations, search queries and the search index stay in your browser and are never uploaded. The website and license service handle only the minimal data needed to sell and validate the optional Pro license. Below we set out exactly what we collect, how we process it, where it is stored, and with whom (if anyone) it is shared.
Data we collect, and what we never collect
On your device, the extension reads your own past conversations on the AI platforms you are logged into, using your own session, solely to build a local search index. This content is processed on your device only and is never collected by or transmitted to us. The only data we collect on our servers is the minimum required to operate the optional Pro license: (1) your License Key, (2) an anonymous device identifier (instanceId) generated locally on your device, and (3) the email address you used at checkout. We do NOT collect conversation content, search queries, usage or analytics data, browsing history, IP-based tracking, precise location, contacts, or any other personal information.
Server logs and technical data
Like any web service, our license server briefly processes standard technical request data (such as your IP address and a timestamp) at the moment you activate, re-validate, or deactivate Pro, solely to deliver the response, prevent abuse, and rate-limit requests. We do not use this technical data to track you, build a profile, or link it to your conversations, and it is not stored as part of your account data. We keep no server or HTTP logs containing conversation content or search queries, because that data never reaches our servers.
How we use your data
We use the License Key and anonymous instanceId only to activate Pro, validate it during use, enforce the per-license device limit, and let you deactivate or move devices. We use your purchase email only to deliver your License Key, send transactional messages about your purchase or refund, and help you recover a lost key — we do not send marketing email. Conversation content is processed exclusively on your device to provide local keyword and semantic search, folders, tags and export; we never see, profile, or analyze it.
Where your data is stored
On your device: conversations and the search index are stored in your browser's local IndexedDB, and your settings, sync state, folders, tags and recent searches in your browser's local storage. None of this leaves your device. On our servers: only the License Key, anonymous instanceId and purchase email are stored, in a secured database hosted by our infrastructure provider; license keys are stored encrypted. Payment data such as your card number and billing address is stored by our payment provider, not by us.
How your data is shared
We do not sell, rent, or trade your data, and we never share it for advertising. We share the minimum necessary with a small number of service providers acting on our behalf: Dodo Payments, our Merchant of Record, handles checkout, payment methods, invoices, tax and refunds and receives your payment details and email directly (we never see your card data); our hosting and infrastructure provider stores the license database; and, only if you enable semantic search, your browser downloads model files from Hugging Face (with our mirror as a fallback) — only model bytes are transferred, never any conversation, query, or personal data. We may disclose information if strictly required by law or valid legal process; because we hold so little, there is very little that could be disclosed.
Compliance with the Chrome Web Store Limited Use policy
Threadback's collection and use of all user data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: we use and transfer user data only to provide or improve the single, user-facing purpose described above (searching, organizing, and exporting your own AI chat history, and validating the optional Pro license); we never use it for personalized or retargeted advertising; we never sell it or transfer it to data brokers or other parties for unrelated purposes; and no human reads your data except with your consent, for security or legal reasons, or when it has been aggregated and anonymized for internal operations.
The extension's only outbound requests
Apart from reading your own history on the AI sites (which stays in your browser), the extension makes only two kinds of outbound request. First, an optional one-time semantic model download when you enable semantic search — it tries Hugging Face first and falls back to our mirror, transferring only model files, never conversations or queries; this never happens if you don't enable semantic search. Second, a license check, only when you actively activate, re-validate, or deactivate Pro — the request body contains only your License Key and the anonymous instanceId, never any conversation, query, or personal information.
Data retention
On-device data (conversations, index, settings) remains until you delete it: you can clear it at any time from the extension settings, and uninstalling the extension removes it. On our servers, the License Key, instanceId and purchase email are kept while your license is valid and for as long as needed to meet legal, tax and accounting obligations relating to your purchase; after that they are deleted or anonymized. You can request earlier deletion as described below, subject to those legal retention requirements.
Your rights and choices
You can clear all local data at any time from the extension settings, or remove it entirely by uninstalling the extension. You can deactivate Pro to unbind your devices, and disable semantic search to avoid the model download altogether. For the limited data on our servers, you may request access to, correction of, or deletion of your License Key, instanceId or purchase email — and, where applicable, exercise your rights under the GDPR, UK GDPR or CCPA/CPRA — by emailing support@threadback.dev. You can recover a lost License Key through the recovery flow on our website. We do not sell personal information.
Security
All communication with our servers uses HTTPS. License tokens are cryptographically signed (ECDSA P-256) and license keys are stored encrypted at rest. By design we collect as little as possible, which keeps the amount of data at risk to a minimum.
International data transfers
Our infrastructure and service providers may process the limited license data (License Key, anonymous instanceId, purchase email) in countries other than your own. Given the minimal, non-sensitive nature of this data, we rely on our providers’ standard safeguards for any such transfers.
Children's privacy
Threadback is not directed to children. We do not knowingly collect personal data from children under 13 (or under the minimum age in your jurisdiction). If you believe a child has provided us data, contact us and we will delete it.
No third-party tracking
Neither the website nor the extension includes any third-party analytics, advertising, or tracking scripts.
Changes and contact
We may update this policy from time to time; for material changes we will revise the "last updated" date on this page. For any privacy question or data request, contact us at support@threadback.dev.