Privacy Policy

Last updated: September 23, 2026

This Privacy Policy explains how ThreadlyOS, operating the ThreadlyOS platform (“ThreadlyOS”, “we”, “us”), collects, uses, shares, and protects information when you use our WhatsApp-based customer relationship management (CRM) service (the “Service”). By using the Service you agree to the practices described here.

1. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, password (stored hashed), and profile details you provide when you register.
  • Contact & conversation data — phone numbers, names, tags, notes, and the content of WhatsApp messages exchanged between you and your contacts through the Service.
  • WhatsApp Business credentials — the WhatsApp Business Account ID, phone number ID, and access tokens you connect. Access tokens are encrypted at rest (AES-256-GCM).
  • Usage & technical data — log data, device/browser information, and timestamps generated as you use the Service.

2. How we use your information

  • To provide, operate, and maintain the Service.
  • To send and receive WhatsApp messages on your behalf through the Meta WhatsApp Business Platform (Cloud API).
  • To authenticate you and secure your account.
  • To provide support and respond to your requests.
  • To improve and develop new features.
  • To comply with legal obligations.

3. WhatsApp & Meta Platform data

The Service integrates with the Meta WhatsApp Business Platform. When you connect a WhatsApp Business number, message content and metadata flow through Meta’s infrastructure in accordance with Meta’s own terms and privacy policies. We process this data solely to deliver the messaging features you request. We do not sell your WhatsApp data, and we do not use it for advertising.

4. How we share information

We do not sell your personal information. We share data only with:

  • Meta Platforms, Inc. — to deliver WhatsApp messages via the Cloud API.
  • Supabase — our database and authentication provider, which stores your data securely on our behalf.
  • Infrastructure providers — hosting (e.g. Railway) required to run the Service.
  • Legal authorities — when required by law or to protect our rights.

5. Data retention

We retain your information for as long as your account is active or as needed to provide the Service. You may request deletion of your data at any time (see “Your rights” and “Data deletion” below). We may retain certain information where required for legal or operational reasons.

6. Data security

We apply industry-standard safeguards including encryption of access tokens at rest, row-level security on all data tables, HMAC-verified webhooks, and encrypted transport (HTTPS). No method of transmission or storage is 100% secure, but we work to protect your information.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the email below.

8. Data deletion

To request deletion of your account and associated data, email naveends798@gmail.com with the subject “Data deletion request”. We will process verified requests within 30 days.

9. Children’s privacy

The Service is not directed to individuals under 18, and we do not knowingly collect their personal information.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above.

11. Contact us

ThreadlyOS
Email: naveends798@gmail.com