Trust, Security & Privacy

Last updated: 2026-09-03

What Threadly does

Threadly helps you draft, format, and enhance posts for X and LinkedIn using AI models. Your post content is sent to AI providers only to generate the response you requested, and is not used to train any model.

Data we process

  • Post content you submit: forwarded to OpenRouter to produce a response, then discarded server-side.
  • Preferences (tone, length, formatting): stored in your browser's local storage only — never on our servers.
  • Bring-your-own API keys (optional): kept in your browser and forwarded per-request to the matching provider. They are never logged or persisted on our servers.

Security practices

  • All traffic is served over HTTPS.
  • Server-side API keys are stored as encrypted environment secrets.
  • Admin actions require a password and are scoped to a small allowlist of content (sponsors, blog data).
  • All user-submitted input is validated server-side with strict schemas before being forwarded to any external provider.

Subprocessors

Threadly relies on the following providers to deliver the service: OpenRouter, GitHub (for blog and sponsor data storage), and the Lovable hosting platform.

Your choices

You can use the app without an account. To stop processing entirely, simply close the tab — no background workers run on your behalf. To remove locally stored preferences, clear site data in your browser.

Contact

Questions or security reports? Open an issue on our GitHub repository or reach out through the contact details on the homepage.

This page describes Threadly's own practices and is not a certification or third-party audit.