Privacy, data use and controls

What Threadglance reads, stores and cannot do.

· Controlled pilot

Privacy summary

Microsoft permission

Mail.Read permits mailbox-wide reading. Threadglance normally queries Inbox, plus a bounded Sent Items sample only when you request a writing profile.

What it cannot do

It has no permission to send, delete, move or mark messages. Attachments are not opened or analysed.

Processed briefly

A bounded message preview and limited message details are processed to produce the inbox analysis. Raw preview text is not retained in the Threadglance database.

What is stored

Sender, subject, timestamps, summaries, reply status, your fixed-category corrections, caution signals, suggested drafts and limited operational records may be stored.

Permission boundary

Exactly what Microsoft permits

Microsoft grants the application delegated Mail.Read permission after you consent. That permission is broader than Threadglance's routine use: regular checks are restricted by the application to Inbox messages. Microsoft access tokens are kept in an encrypted server-side token cache and are not returned to the browser.

Processing and retention

What remains after analysis

Processed for analysis
Sender, recipients, subject, timestamps, attachment indicator and a bounded body preview.
Stored by Threadglance
Limited message details and derived results such as summaries, reply decisions, caution signals, missing-information prompts and suggested drafts. Message records and their derived results are kept for up to 30 days from the message date; scan history is kept for up to 30 days.
Category corrections
If you confirm or change an email category, Threadglance stores the fixed category, the original automated category, a one-way message-version fingerprint and limited analysis provenance. The change applies only to that email version: it does not alter Outlook or teach future classifications. It does not store your correction as free text or use it to train a shared model. The correction is deleted with its message record.
Not stored after analysis
The raw message body or bounded body preview. Attachments are not fetched or opened.
Redrafting
Your current draft, the stored summary and optional style guidance are processed to return a revised draft. Threadglance does not add the edited draft to its database through the redraft endpoint.
Optional writing profile

How “Write more like you” works

Only when you request a refresh, Threadglance reads up to 40 usable messages from Sent Items from the previous 90 days. The message text is used on the server to calculate aggregate signals such as typical length, formality and warmth. Sent bodies, subjects, recipients, message IDs and attachments are not stored in the profile.

Turning the feature off stops using the profile for new drafts but keeps the aggregate profile. Use “Delete and reset profile” to remove it.
Service providers

Where processing occurs

Microsoft

Provides the mailbox data after you approve delegated Mail.Read access.

Supabase

Provides sign-in, the database and scheduled-job services.

Vercel

Hosts the website and server-side worker.

OpenAI

May process bounded preview text, stored summaries and draft text when analysis or redrafting is used. Organization data sharing for model improvement is disabled and requests set store: false, so Responses application state is not deliberately stored. Zero Data Retention is not enabled; standard abuse-monitoring logs may retain customer content for up to 30 days.

Resend

When branded sign-in delivery is enabled, Resend receives the recipient email address, the one-time-code email content and delivery metadata. Ireland is the sending region only; Resend stores email and log data in the United States for 30 days. Open and click tracking must remain disabled.

Cloudflare Turnstile

When bot protection is enabled for sign-in, Turnstile processes browser and security signals such as IP address, TLS fingerprint, user agent, site key and origin. Threadglance passes the single-use challenge result to Supabase Auth for validation and does not send mailbox content or reply drafts to Turnstile.

Your controls

Pause, reset or disconnect

  • Pause automatic checksKeeps the mailbox connected while scheduled checks stop.
  • Turn off writing guidanceStops using the aggregate profile without deleting it.
  • Reset writing guidanceDeletes the aggregate writing profile for that mailbox.
  • Disconnect the mailboxDeletes Threadglance's token cache, mailbox identity fields, derived inbox results, saved category corrections, writing profile and scan history. An identity-free disconnected record remains for up to 90 days for account integrity and support.
  • Delete the pilot accountAsk the person who invited you. During the controlled pilot, removal is handled manually by disconnecting mailboxes, revoking sessions, removing access and deleting the sign-in account.

Disconnecting does not delete email or revoke the application entry in Microsoft. Microsoft-side consent can be revoked separately in your Microsoft account or by your administrator. Active database records are removed under the limits above; deleted records may remain in encrypted Supabase daily backups for the current seven-day backup window. A complete self-service deletion flow is still required before access expands beyond the controlled pilot.

Limits of the analysis

No automated analysis can prove that an email is genuine or safe. Threadglance shows evidence and a suggested next step; consequential requests should be checked through contact details you already trust.