Privacy Policy

What we collect, why, who we share it with, and how to delete it — across both the ThreadSnoop API and the ThreadSnoop lead-discovery app.

Last updated July 22, 2026. This page is a plain-language overview of our real data practices, written by us, not a law firm. It's accurate to what the product actually does, but it isn't attorney-reviewed or a complete legal document — if you need a GDPR/CCPA/compliance answer for your own purposes, verify it independently with counsel.

What we collect

Account information

To create an account we collect your email address and a password. The password is never stored in plain text — we hash it with scrypt (a salted, one-way hash) and keep only the hash. Signing in sets a single session cookie; see “Cookies” below.

Product and discovery data (the lead-discovery app)

If you use the ThreadSnoop app, you tell us about your product — its name, URL, description, target customer, and the problems it solves — so we know what to look for on Reddit. We store the matches we find for you and the ratings you give them (good/bad), which train a scoring model personal to your account. None of this is shared with other ThreadSnoop users.

Payments

If you buy API credits or a subscription, Stripe collects and processes your card details directly — we never see or store your raw card number. On our side we keep a Stripe customer ID, a ledger of credit grants and top-ups, and the dollar amounts charged, so we can answer billing questions and keep your balance accurate.

API usage

Every API call is logged for metering and support: the endpoint you called, the HTTP status, credits charged, and latency. We do not log or store the actual search terms, subreddit names, or other query parameters you send — usage records are aggregate, not a transcript of what you searched for.

IP addresses

We use IP addresses to slow down abuse — signup/login throttling and free-credit-farming detection. These checks run in memory on our application server and are not written to a database; we don't keep a persistent log of visitor IP addresses. The one exception is a small internal table that logs requests to our upstream Reddit data provider (status codes and rate-limit info, for our own reliability monitoring) — it records nothing about you or your IP address.

Communications

We send transactional email — verification, password reset, your digest of new matches (if enabled), and billing receipts — and you can reply to any of it. If you're not yet a customer, we sometimes reach out directly about ThreadSnoop using publicly available contact information, such as an address listed on your own company site; tell us to stop and we will, and we'll delete what we found.

What we don't do

  • We never post, comment, or message anyone on Reddit on your behalf.ThreadSnoop drafts replies for you to review and edit; you copy them and post from your own Reddit account, yourself. We don't ask for or store your Reddit login, and Reddit posting never happens from our servers.
  • We never sell your personal data to anyone, for any reason.
  • We don't run ad trackers or third-party analytics on threadsnoop.com — no Google Analytics, no Meta/Facebook Pixel, no ad-network scripts. The site's fonts are self-hosted at build time, so even loading a page doesn't call out to a third party.

Third parties we use

We keep this list short on purpose — these are the only outside services that touch your data:

  • Stripe — payment processing. Card details go to Stripe directly; we never handle them.
  • Resend — sends our transactional email (verification, password reset, digests, receipts, outreach).
  • Together AI— powers the lead-discovery app's AI features (match scoring, onboarding suggestions, reply drafts). Text you provide there (your product description, and the public Reddit content being scored) is sent to this provider to generate a result. It is not used by the read-only API product.
  • A third-party Reddit data provider— the API and the app both read publicly available Reddit content (posts, comments, subreddit metadata) through a data provider rather than scraping Reddit ourselves. This only ever returns content that's already public on Reddit.
  • Our infrastructure provider — hosts the application and database. Standard hosting access, no data-sharing beyond keeping the service running.

Data retention and deletion

We keep your account data for as long as your account is active. You can delete your account yourself, at any time, from Settings — it's a genuine hard delete, not a deactivation flag: your product profile, discovery alert, matches, ratings, customer memory, API keys, usage history, and credit ledger are all removed in one cascade, along with your login itself. It cannot be undone, and we don't keep a shadow copy afterward.

If you only joined our waitlist, we keep your email address until we invite you or you ask us to remove it.

Cookies

ThreadSnoop sets one cookie: ts_session, used to keep you signed in. It's httpOnly (invisible to page JavaScript), sameSite=lax, marked securein production, and holds nothing but a signed user ID and an expiry — no tracking payload. We don't set any third-party or advertising cookies.

Children's privacy

ThreadSnoop is a business tool and isn't directed at children. We don't knowingly collect personal information from anyone under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has given us information, contact us and we'll delete it.

International users

ThreadSnoop is a small, independently run product, hosted in the United States. If you use it from outside the US, your data is processed there. We aim to honor the spirit of GDPR/CCPA-style rights (access, deletion, correction) for anyone who asks, regardless of location — the self-serve delete above covers most of it, and you can email us for anything else.

Contact

Questions, deletion requests, or anything else about this policy: hello@threadsnoop.com.