Privacy
Privacy policy
This policy explains the information threads-ai needs to connect a Threads account to an approved MCP client. It applies to this website, the Threads OAuth connection, and the remote MCP service.
1. Controller and contact
For the processing described in this policy, threads-ai is the service operator. For privacy questions or requests, contact support@lessontwo.co. We may ask for enough information to verify that a request concerns the account in question.
2. Information we process
- Threads connection data. Your Threads user ID, username, approved scopes, token expiry, and an encrypted Threads access token.
- Service and authorization data. An internal account ID, authorization version, browser-session and OAuth state records, CSRF data, and the metadata needed to authorize an MCP client.
- Published-object records. The Threads object ID, object type, reply target where applicable, permalink, and deletion status for content created through threads-ai. These records let us enforce the rule that only content created through this service can be deleted through it.
- Idempotency and operational records. A one-way request digest and safe result or error data for a short-lived mutation retry record. The application database does not store the text of a post or reply.
3. Why we use it
We use this information to sign you in through Threads, maintain your connection, issue and validate separate MCP authorization, perform the actions you approve, prevent duplicate publishing, protect the service, and respond to support or deletion requests. Where applicable law requires a legal basis, these purposes are necessary to provide the service you ask us to provide or are based on your authorization of the connection.
4. How information is shared
We use Cloudflare to run the Worker, D1 database, and KV storage, and Meta to authenticate your Threads account and perform Threads API requests. An MCP client you approve receives its own threads-ai access token and the results of the tools it calls; it never receives your Threads access token. Content you choose to publish is sent to Meta and may be public on Threads. We may also disclose information when required by law or to protect the security, rights, or property of users and the service.
5. What we do not do
threads-ai does not sell personal information, run advertising or usage analytics in this MVP, or give an MCP client your Threads access token. We do not use the service to make automated decisions with legal or similarly significant effects about you.
6. Retention
- Account, connection, authorization, and published-object records are retained while needed to operate the connection, enforce the deletion boundary, or until a verified data-deletion request is completed.
- Disconnecting immediately removes the usable encrypted Threads credential, invalidates current MCP access, and ends the current browser session. It does not by itself erase all account and operational records.
- Browser sessions expire after up to seven days; Threads OAuth state expires after ten minutes. Idempotency records have a 24-hour expiry and are removed during subsequent mutation cleanup or full data deletion.
- A Meta data-deletion confirmation code is retained for up to 30 days solely to confirm that the request was received.
7. Your choices and rights
You can log out to end the current browser session, disconnect Threads to revoke the usable credential and MCP access, and use Meta's data-deletion controls to request deletion of the threads-ai application data associated with your Threads account. Depending on where you live, you may also have rights to request access, correction, deletion, restriction, objection, or portability. Contact support@lessontwo.co to make a request.
8. Security and international processing
Threads access tokens are encrypted at rest and are kept separate from MCP access tokens. No method of transmission or storage is completely secure, so we cannot promise absolute security. Cloudflare and Meta may process information in countries other than the one where you live as part of providing their services.
9. Changes to this policy
We may update this policy when the service or applicable requirements change. The effective date above identifies the current version. Material changes will be posted on this page before they take effect where required.