ThreadLantern Privacy Policy
Effective August 3, 2026.
ThreadLantern (the “Service”) is operated by Alex Luy. This policy describes the information used to operate comment search, review, synchronization, deliberate moderation, billing access, support, security, and recovery.
Information handled
- Google account and authorized YouTube channel information used for sign-in and Creator-scoped operation.
- Channel, video, comment, commenter, classification, review, synchronization, and moderation-request records needed to provide the Service.
- AI-assisted classification: bounded public comment text from an authorized channel may be sent to OpenAI for spam classification. ThreadLantern excludes Creator, channel, video, external comment, and commenter identifiers from the classification request and does not give the AI provider moderation access.
- Server-side session and security state.
- Billing, trial, and search data: We store trial dates, successful-search usage, billable search intents, Entitlement state, Stripe Customer and Subscription references, billing status, webhook receipt/outbox state, and safe reconciliation outcomes. ThreadLantern does not receive or store card or bank details or billing addresses; payment entry is handled by Stripe-hosted Checkout and Customer Portal.
- Bounded operational telemetry designed to exclude comment/query text, email, payment data, secrets, hosted URLs, and provider identifiers.
How we protect Google user data
ThreadLantern uses technical and operational safeguards to protect Google user data. Connections between users, ThreadLantern, Google and YouTube, and service providers use HTTPS/TLS encryption in transit. Google OAuth access and refresh tokens are stored only in server-side systems and are not returned to the browser.
Production databases and caches are not directly exposed to the public internet. Access is limited to application services and the authorized operator. Authenticated account-ownership checks isolate each Creator's records. ThreadLantern also uses secure session cookies, origin and CSRF validation for state-changing requests, separate secret storage, and logging controls designed to redact credentials and exclude comment and search text.
Although ThreadLantern uses safeguards designed to protect information, no method of electronic transmission or storage can be guaranteed completely secure.
Use, sharing, and retention
Information is used to authenticate Creators, provide requested comment operations, enforce access, secure and recover the Service, and respond to support. OpenAI processes bounded comment text as a service provider for advisory spam classification. Other service providers may process information only as necessary to operate the Service. Information may also be disclosed when legally required.
ThreadLantern's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing features described in this policy and is not sold or used for advertising.
Records are retained only for approved product, security, recovery, and legal needs. Durable billing ledger records currently follow the operator's 400-day policy; telemetry has a separate, shorter policy.
Revocation and deletion
Users may revoke ThreadLantern's access through their Google Account permissions. Revocation prevents future Google API access but does not automatically delete information already stored by ThreadLantern.
Users may request deletion of stored OAuth credentials and synchronized YouTube data by contacting support@threadlantern.com. After verifying the request, ThreadLantern will delete the requested information unless retention is required for security, legal, billing, fraud-prevention, or dispute-resolution purposes.
Contact
For questions or rights requests, contact Alex Luy through support@threadlantern.com.