Privacy Policy
Thread is local-first. This policy explains what stays on your device, what reaches our servers when you choose to sync, and what never leaves.
Last updated: 24 September 2026
Updated for the paid launch; pending legal review.
1. Who is responsible
The controller is Infinity Consciousness Europe SIA, Vēja iela 4 – 2, Ādaži, Ādažu novads, LV-2164, Latvia (registration no. 50203642241). Contact: hello@orbitcue.app.
2. Using Thread without an account
Without an account, everything you capture — notes, documents, files, search index and what Thread understood — is stored only in your browser’s storage on your device (IndexedDB and the origin-private file system). We do not receive it. Our servers deliver the app files; standard web server logs (IP address, time, requested file, user agent) are processed for security and kept for a short period.
3. Account and sync (optional)
If you create an account we process your email address and a hashed password (or one-time sign-in codes) to authenticate you, via our hosting provider Supabase. If you turn on sync, the content of your synced workspace — except anything marked “Keep on this device only” — is stored in our database and file storage so it can reach your other devices.
- Hosting region: European Union (Ireland).
- Access is restricted per workspace by database access rules; files are private and only served to workspace members.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- We keep synced data until you delete it or your account. Items you delete or mark “Keep on this device only” are removed from the cloud on the next sync.
4. AI features (optional, off by default)
- Local AI (LM Studio, Ollama): your browser talks directly to the model on your own computer. Nothing is sent to us.
- Your own API key: the key is stored encrypted on our server and never returned to your browser. When you use AI, the relevant excerpts are sent through our server to the provider you chose (e.g. Anthropic, OpenAI, Google), under your own agreement with that provider. We do not store the prompts or answers beyond what is needed to return them, and we log only usage metadata (time, provider, token counts).
- Items marked “Don’t use with AI” or “Keep on this device only” are never sent to any AI provider.
- We never use your content to train AI models.
5. Trial, subscription and payments
- For each account we store your trial start and end dates and your subscription state (plan, monthly/annual, status, current billing period, scheduled cancellation, seats) so we can grant the right access.
- Payments are handled by Paddle.com, our merchant of record, as an independent controller for payment processing, invoicing and tax. Paddle collects your payment details, billing address and tax information; we never receive or store card numbers. We receive and store Paddle identifiers (customer and subscription IDs), prices, status and billing periods via verified webhooks.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legal obligations for accounting records (Art. 6(1)(c)). Billing records are kept as long as statutory retention periods require (in Latvia generally up to 10 years for accounting documents); other subscription data is deleted with your account.
6. Emails
We send transactional emails only: confirming your address, sign-in links and codes, password resets, email-change confirmations, and — once billing emails are enabled — trial reminders (start, 7 days and 1 day before the end, end), subscription confirmations, cancellation confirmations and payment problems. Paddle sends receipts and invoices. No newsletters without your separate consent.
7. Cookies and local storage
Thread uses no advertising or third-party tracking cookies. It uses your browser’s storage to hold your workspace, your session when signed in, and a cached copy of your plan status (so Thread keeps working offline). The service worker caches the app so it works offline. When you open the checkout, Paddle’s checkout window may set cookies necessary for payment and fraud prevention.
8. Processors and recipients
- Supabase Inc. — authentication, database, file storage and transactional email (EU region).
- Our web hosting provider (Vercel) — delivery of the app and API.
- Paddle.com Market Ltd — merchant of record for purchases (independent controller for payments).
- If configured: our transactional email provider — trial and billing emails.
- Only if you add your own key: the AI provider you chose, as your processor under your agreement.
9. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and to lodge a complaint with a supervisory authority (in Latvia: Datu valsts inspekcija). You can export everything yourself at any time from Settings → Data (see Export & restore). To delete your account, contact us.