Skip to content
Thredo
How it works Channels Integrations Shopify Security
Ecommerce Service businesses Small business
Blog Comparisons About Book a demo
Pricing Log in Get started

On this page

  1. 1. Information We Collect
  2. 2. How We Use Information
  3. Google user data & Limited Use
  4. 3. Legal Basis (GDPR)
  5. 4. Sharing with Third Parties (Subprocessors)
  6. 5. Data Retention
  7. 6. Security
  8. 7. Your Rights
  9. 8. Children
  10. 9. International Data Transfers
  11. 10. Changes to this Policy
  12. 11. Contact Us

Legal

Privacy Policy

Effective August 12, 2026

This Privacy Policy describes how Arconetix LLC ("Arconetix", "we", "us") collects, uses, stores, and shares personal information when you use Thredo (the "Service") at thredo.ai. Thredo is an AI-powered customer-messaging platform that lets businesses connect a messaging channel — WhatsApp, Instagram, Messenger, Telegram, SMS, email or a chat widget on their own website — and have an AI agent reply to inbound customer messages on their behalf. It can also read a connected Shopify store to answer questions about an order.

Arconetix LLC is a Wyoming, USA limited liability company with its registered office at 30 N Gould St, STE R, Sheridan, WY 82801. We are the data controller for information you provide directly to Thredo, and a data processor for the customer messages your business receives on any connected channel.

By using Thredo, you agree to the practices described here. If you do not agree, do not use the Service.

1. Information We Collect

1.1 Information you give us directly

  • Account data: name, email, password (hashed), workspace name, business type, country, time zone.
  • Billing data: payment-method last 4 digits, billing address, invoice history. Full card numbers are handled exclusively by Stripe and never reach our servers.
  • Agent configuration: system prompts, welcome messages, tone settings, knowledge-base entries, integrations you connect.
  • Support communications: emails, chat transcripts, or other messages you send us.

1.2 Information we receive on your behalf

When you connect a messaging channel to Thredo, we receive the following for each conversation routed to your agent:

  • Sender identifier — a phone number on WhatsApp, SMS or Telegram, an account ID on Instagram or Messenger, an email address on email, or an anonymous session ID on web chat.
  • Display name, if the channel shares it.
  • Message content — text, and metadata like timestamps and message IDs.
  • Delivery status events (sent, delivered, read, failed) for messages we send, where the channel reports them.

If you connect a Shopify store, an agent can look up an order when a shopper gives both an order number and the email on that order. Thredo receives the order's status, fulfillment state and tracking details. It does not request the order total, the customer's email, or any address. Every lookup is written to an access log we keep for 90 days, which records the order asked about and the decision made — never the email a shopper typed.

We act as a data processor for this information on your behalf as the business operator. You — the customer of Thredo — are the data controller for the end-customer information that flows through your WhatsApp number.

1.3 Information collected automatically

  • Usage data: pages visited, features used, request timestamps.
  • Device & technical data: IP address, browser type, OS, device type, language.
  • Error logs: stack traces and request context when something fails, used for debugging.
  • Cookies & local storage: session tokens for authentication, preference state. We do not use third-party advertising cookies.

2. How We Use Information

We use the information we collect to:

  • Provide the Service — receive inbound WhatsApp messages, generate AI replies, deliver them back to your customer.
  • Maintain your account and workspace, authenticate sessions, prevent unauthorized access.
  • Bill your account — meter API usage, charge subscription fees, send invoices.
  • Operate and improve the Service — debug errors, monitor performance, develop new features.
  • Communicate with you — transactional emails (receipts, password resets, security alerts), occasional product updates, and replies to your support requests.
  • Comply with legal obligations and enforce our Terms of Service.

We do not use the content of your customers' messages to train AI models. We do not sell your data or your customers' data to anyone. We do not use the Service to send marketing on your behalf without your explicit instruction.

Google user data & Limited Use

When you connect Google Calendar, you grant Thredo access to the https://www.googleapis.com/auth/calendar.events scope so your AI agent can check availability and create, reschedule, and cancel appointments on your behalf.

  • What we access: calendar event data (times, titles, attendees) needed to read availability and manage bookings.
  • How we use it: solely to provide the calendar-booking features you enable — checking free/busy times and creating, updating, or cancelling events you or your customers request.
  • Storage: we store OAuth tokens to keep the connection active and only the minimal event references needed to manage bookings; we do not keep a copy of your full calendar.
  • No selling, no ads, no model training: we never sell Google user data, never use it for advertising, and never use it to train generalized AI/ML models.
  • Revoke anytime: disconnect Google Calendar inside Thredo, or revoke access at myaccount.google.com/permissions.

Thredo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. Legal Basis (GDPR)

If you or your customers are in the European Economic Area, United Kingdom, or Switzerland, our legal bases for processing are:

  • Performance of a contract — to deliver the Service to you.
  • Legitimate interests — to keep the Service secure, prevent fraud, and improve quality.
  • Legal obligation — to comply with tax, accounting, and law-enforcement requirements.
  • Consent — where you opt in (e.g. marketing emails).

4. Sharing with Third Parties (Subprocessors)

Thredo runs on a set of subprocessors — the companies that host the database, deliver the messages, generate the AI replies and take the payments. Each has access only to the data needed for its role.

The complete, current list is on its own page: thredo.ai/subprocessors.html, with what each one does and where it is located. It lives there rather than here because a list kept in two places drifts, and a stale subprocessor list is the kind of inaccuracy that matters.

We will publish a new subprocessor on that page 30 days before it begins processing data. We do not sell personal information to advertisers, data brokers, or any other party.

5. Data Retention

  • Customer messages and conversation history: retained for as long as the workspace that owns them is active. On workspace deletion, retained for 30 days then permanently deleted.
  • Account data: retained while the account is active. Deleted within 30 days of account deletion, except where law requires longer retention.
  • Billing records: retained for 7 years after the last transaction, per US accounting law.
  • Server logs: rotated after 90 days.
  • Shopify order-lookup access log: 90 days, then deleted automatically by the database. Records which order was asked about and what was decided; never a shopper's email or address.

Note: under Meta's WhatsApp Cloud API policy, raw messages flowing through Meta's infrastructure are deleted from Meta's systems within 30 days of delivery. What we retain on our side is described above.

6. Security

  • Encryption in transit: all connections use TLS 1.2 or higher.
  • Encryption at rest: data stored in MongoDB Atlas is encrypted at rest with AES-256.
  • Passwords: hashed with bcrypt (12 rounds). Plain-text passwords are never stored.
  • Access control: only authorized engineers can access production systems; all access is logged.
  • Secret rotation: API keys and tokens are rotated periodically.
  • Backups: automated daily; encrypted; retained 30 days.

No system is 100% secure. If we become aware of a security breach that affects your personal data, we will notify you and any required regulators within 72 hours of discovery, as required by GDPR Article 33.

7. Your Rights

Regardless of where you live, you may:

  • Access — request a copy of the personal data we hold about you.
  • Correct — ask us to fix inaccurate information.
  • Delete — ask us to delete your account and personal data (subject to legal-retention exceptions noted above).
  • Export — request your data in a portable format (JSON).
  • Object or restrict — ask us to stop or limit specific kinds of processing.
  • Withdraw consent — where processing is based on consent, you can revoke it at any time.
  • Complain — to your local data-protection authority (e.g. ICO in the UK, CNIL in France, the FTC in the US).

California residents have specific rights under the CCPA/CPRA, including the right to know what personal information we collect and to opt out of any "sale" or "share". We do not sell personal information.

To exercise any of these rights, email admin@arconetix.com. We respond within 30 days.

8. Children

Thredo is a B2B service intended for businesses and their authorized representatives. We do not knowingly collect personal data from anyone under 16. If you believe a minor has signed up, contact us and we will delete the account.

9. International Data Transfers

Our infrastructure is hosted in the United States. If you access Thredo from outside the US, your information will be transferred to and processed in the US. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission and equivalent mechanisms required by other applicable laws.

10. Changes to this Policy

We may update this policy from time to time. Material changes will be communicated by email to the workspace owner at least 30 days before they take effect. The "Effective" date at the top of this page reflects the most recent revision.

11. Contact Us

Questions about this policy or your data?

Arconetix LLC
Attn: Privacy
30 N Gould St, STE R
Sheridan, WY 82801, USA
Email: admin@arconetix.com
Phone: +1 (307) 441-9833
Thredo

An AI agent that answers your customers.

Product

How it works What it does Integrations Pricing Security Shopify app

Channels

WhatsApp Instagram Messenger Telegram Web chat Email

Solutions

Ecommerce Service businesses Small business Enterprise

Resources

Blog Comparisons AI support tools Contact

Company

About Contact support@thredo.ai
© 2026 Thredo · a product of Arconetix LLC, Wyoming, USA
Privacy Terms Subprocessors