Privacy Policy
This policy explains the data that Sociomile Threads ("we", "the service") processes when you and your team use the service to read and reply to comments and mentions on your business's Threads accounts. Sociomile Threads is not a Meta or Google product and is not affiliated with either of them. Threads is a trademark of Meta Platforms, Inc.
Data we process
| Type of data | Contents | Source |
|---|---|---|
| User account | Google account ID, name, email, profile photo, last sign-in time | Google, when you sign in |
| Workspace & team | Workspace name, members, roles, account access, invitations (recipient email) | Entered by the Owner and members |
| Connected Threads accounts | Threads user ID, username, name, profile photo, access token (encrypted), token expiry | Threads, after you approve the permissions |
| Comments & mentions | Text, attachments (media links), post link, time, and the sender's username, profile photo, and verified status; the text of the original post as context | Threads API and Meta webhooks (public content only) |
| Team work | Replies and uploaded attachments, statuses, categories, labels, tags, internal notes, tickets, ticket discussions, notifications | Created by team members |
| Billing | Billing name, email, mobile number, and address; invoices; payment status, method, and reference | The Owner and Sassly Pay |
| Technical data | IP addresses and records of important activity (audit log), webhook logs, error logs | Our servers |
We never ask for or store Google or Threads passwords, and we do not store your payment card or bank account details.
What data is used for
- Running the service: showing comments and mentions, sending the replies you write to Threads, and managing tickets, reports, and teams.
- Sign-in and account security, including preventing unauthorized access between workspaces.
- Pro plan billing: creating invoices, processing payments, and sending reminders.
- Sending service emails: invitations, task notifications, invoices, and important account notices.
- Fixing disruptions and keeping the service reliable.
Data is not sold, not used for advertising, and not used to train AI models.
AI features (Pro plan)
When a member presses Summarize or Draft reply, the relevant conversation content (up to about the last 30 messages), the text of the original post, and the workspace's writing style settings are sent to a language model provider (Sumopod, an OpenAI-compatible API) to generate a summary or draft. Access tokens, member emails, and other workspace data are never sent. Drafts are never sent to Threads automatically; members always edit and send them themselves.
Other parties that process data
- Google for sign-in (name, email, profile photo).
- Meta (Threads API) to fetch comments and mentions and to publish replies. Reply attachments are made available through a public URL on our servers so that Meta can fetch them when publishing.
- Sassly Pay (pay.sassly.ai, using Mayar/QRIS) for invoice payments.
- Sumopod for email delivery and AI features (Pro plan).
- Infrastructure providers (servers and networking, including Cloudflare), only to the extent needed to run the service.
Apart from this, data is only disclosed when required by applicable law.
Storage & security
- All access uses an encrypted connection (HTTPS).
- Threads access tokens are stored encrypted (AES-256-GCM).
- Each workspace is separate: members can only open data of the workspaces in which they are an active member, according to the role and account access they have been given.
- The only cookies used are a session cookie to keep you signed in and a display-language preference cookie (kept for 1 year); there are no advertising cookies or third-party trackers.
How long data is kept
- Conversations and tickets are kept while the workspace is active, until the Owner deletes them or a data deletion request is made.
- Raw webhook logs are deleted automatically after 30 days.
- When a Threads account is disconnected, its access token is deleted immediately; the conversation history remains stored for the workspace until it is deleted.
- Invoices, payment records, and audit logs are kept as financial and security records in accordance with legal requirements.
Your rights
Under Law Number 27 of 2022 on Personal Data Protection, you have the right to request access to, correction of, and deletion of your personal data, and to withdraw your consent. How to delete data is explained on the Data Deletion page. For other requests, contact us at [email protected].
Minors
This service is intended for businesses and teams aged 18 and over, and is not intended for children.
Changes to this policy
If this policy changes, the latest version, together with its effective date, is always available on this page. Important changes are also announced by email to workspace Owners.
Contact
Questions about privacy: [email protected].