ThreadLantern

ThreadLantern Privacy Policy

Effective August 3, 2026.

ThreadLantern (the “Service”) is operated by Alex Luy. This policy describes the information used to operate comment search, review, synchronization, deliberate moderation, billing access, support, security, and recovery.

Information handled

How we protect Google user data

ThreadLantern uses technical and operational safeguards to protect Google user data. Connections between users, ThreadLantern, Google and YouTube, and service providers use HTTPS/TLS encryption in transit. Google OAuth access and refresh tokens are stored only in server-side systems and are not returned to the browser.

Production databases and caches are not directly exposed to the public internet. Access is limited to application services and the authorized operator. Authenticated account-ownership checks isolate each Creator's records. ThreadLantern also uses secure session cookies, origin and CSRF validation for state-changing requests, separate secret storage, and logging controls designed to redact credentials and exclude comment and search text.

Although ThreadLantern uses safeguards designed to protect information, no method of electronic transmission or storage can be guaranteed completely secure.

Use, sharing, and retention

Information is used to authenticate Creators, provide requested comment operations, enforce access, secure and recover the Service, and respond to support. OpenAI processes bounded comment text as a service provider for advisory spam classification. Other service providers may process information only as necessary to operate the Service. Information may also be disclosed when legally required.

ThreadLantern's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing features described in this policy and is not sold or used for advertising.

Records are retained only for approved product, security, recovery, and legal needs. Durable billing ledger records currently follow the operator's 400-day policy; telemetry has a separate, shorter policy.

Revocation and deletion

Users may revoke ThreadLantern's access through their Google Account permissions. Revocation prevents future Google API access but does not automatically delete information already stored by ThreadLantern.

Users may request deletion of stored OAuth credentials and synchronized YouTube data by contacting support@threadlantern.com. After verifying the request, ThreadLantern will delete the requested information unless retention is required for security, legal, billing, fraud-prevention, or dispute-resolution purposes.

Contact

For questions or rights requests, contact Alex Luy through support@threadlantern.com.