Fine print
Privacy policy
What Threadline collects, why, where it goes and what you can ask us to do with it. Written to be read, not scrolled past.
Last updated 26 September 2026
Questions and requests
Threadline is a founding-client programme and the operating company is being set up. Until then, questions and requests about your data go to the person who replies to your application, or through the application form. We treat every request as we would once the company exists.
What we collect, and why
- When you apply: your name, email address, company, website, revenue range and your answers to the application questions. We use these to assess fit, to reply to you either way, and, if we work together, to set up your workspace. Legal basis: steps taken at your request before a contract, and our legitimate interest in assessing applications.
- When you are a client: your sign-in email, a hashed password, the content and records you and we create in your workspace, and the technical logs needed to run and secure the service. Legal basis: performance of our contract with your firm.
- When you follow a tracked link (a Threadline address in a client's post): the time of the click, the referring site's host name, and a random first-party identifier so that repeat clicks from the same browser can be told apart. We do not fingerprint devices and we cannot identify you from this. Legal basis: our and our clients' legitimate interest in measuring whether published work is met.
- When you write to us: your message and your contact details, to reply.
What we do not do
- We do not sell or rent personal data.
- We do not run advertising or third-party analytics trackers on this site.
- We do not scrape login-walled platforms or build profiles of people who have not contacted us.
- We do not send marketing email to applicants who were not accepted.
Who else sees it
We use a small number of providers to run the service, each under a contract that limits them to acting on our instructions:
- Hosting and delivery: Vercel.
- Transactional email (application confirmations, invites, password resets and reports): Resend, when configured.
- File storage for client workspaces: our storage provider, when a workspace uses file storage.
- Where a client connects a publishing or CRM platform to their workspace, the data that platform returns is held in the client's workspace and governed by the client's own agreement with that platform.
How long we keep it
- Applications: for the time it takes to assess them and reply, and for a short period afterwards so that we can answer follow-up questions, after which they are deleted or anonymised.
- Client workspace data: for the life of the engagement and for a short period after it ends so that records can be handed over, unless the client asks for earlier deletion.
- Tracked-link records: for as long as the piece of work they measure is being read, and then anonymised.
- Security and access logs: for a short, fixed period, then deleted.
Where it is processed
Our providers may process data outside the United Kingdom. Where they do, transfers rely on adequacy regulations or the UK International Data Transfer Agreement and the providers' standard contractual terms.
Your rights
Under UK data protection law you can ask us to confirm what we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to give you a copy in a portable form. Write to the contact above; we reply within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk.
Changes
We will change this policy when the service changes. The date at the top is the date of the current version. This version: 26 September 2026.