Your customers' messages, handled properly.
What we encrypt, where it lives, who can reach it, and how to get rid of it. In plain terms, with the detail in the privacy policy.
Encryption
Data at rest in MongoDB Atlas is encrypted with AES-256. Everything in transit uses TLS. Channel access tokens are encrypted separately with AES-256-GCM before they are stored.
Where it lives
Our infrastructure is hosted in the United States. If you or your customers are in the UK or EEA, transfers rely on Standard Contractual Clauses approved by the European Commission.
Never used for training
Your customers’ messages are not used to train models — not ours, not our providers’. They exist to answer that customer and to show you what happened.
Who can see what
Roles are owner, admin and member. Billing, agent configuration and member management are each permission-gated, so a member cannot change what an agent says or what you pay.
Deletion
Delete a workspace from settings and it goes immediately. Email privacy@thredo.ai and we confirm within 2 business days and complete within 30 days. What we keep for legal and billing reasons is listed in the privacy policy.
Meta’s rules, enforced
Only people who opted in are messaged. The 24-hour window is tracked per conversation and templates take over outside it. STOP opts a contact out immediately and no one on your team can undo it by accident. Group messaging is not supported by the API and Thredo does not attempt it.
What we do not claim
We are not SOC 2 or ISO 27001 certified, and we do not publish an uptime percentage we cannot yet stand behind. When any of that changes we will say so here with the date it happened.
A data processing agreement is available on request — email privacy@thredo.ai.
Every third party that touches your data is listed by name, purpose and location.
Start with 50 messages free.
No card, no trial timer. Set it up this afternoon.