Skip to content

Security

Careful with your inbox, your tokens and your leads.

Threadline acts in your name, from your own Gmail. Here's how it protects that trust — and the plain list of what it will and won't do.

Protections

How your account and data are protected

  • Any reply stops everything

    Positive, negative or neutral — a reply ends all automation for that lead, and the thread is re-checked right before every follow-up.

  • Tokens encrypted at rest

    Gmail OAuth tokens are encrypted with AES-256-GCM. Your Google password is never requested or stored.

  • Server-enforced daily caps

    Limits are enforced on the server, per campaign and per mailbox — not just in the browser.

  • Never sent twice

    Sending is built so the same email can never go to a lead twice, even if the server crashes mid-send.

  • Shared suppression list

    Hard bounces and addresses you suppress are excluded from every campaign, current and future.

  • Append-only audit log

    Every generated message, send, reply and bounce is recorded — and records are only ever added, never rewritten.

Google access

What access is requested, and why

Signing in uses Google sign-in and asks only for your name and email address.

Connecting Gmail is a separate step that asks for permission to send email on your behalf and to read your messages. Read access is what lets Threadline notice a reply, an out-of-office response or a bounce, so it can stop or pause a sequence. It is used only for messages related to emails the app sent — replies on its threads and bounce notices.

Tokens are encrypted at rest with AES-256-GCM. You can revoke access at any time from your Google Account's security settings, and you can ask us to delete your data by emailing support@example.com.

What the app does and does not do

What Threadline does

  • Sends the emails you've set up, from your Gmail, as plain text.
  • Reads messages on threads it started, to detect replies, out-of-office responses and bounces, and to give follow-ups context.
  • Researches each lead's company from public web sources, and lists every source it used.
  • Sends lead details, the research, your company profile and your playbook to Anthropic's API to write drafts.
  • Records every generated message, send, reply and bounce in an append-only audit log.

What it never does

  • Ask for, see or store your Google password.
  • Add tracking pixels or rewrite links for click tracking.
  • Scrape LinkedIn.
  • Reply to anyone on your behalf.
  • Try to get around Gmail's sending limits or spam filters.
  • Sell your data, use it for advertising, or use Google user data to train generalized AI models.

Honest limits

Things you should know before you start

  • It is designed for low-volume, personal one-to-one outreach — about 15–20 new emails a day — not bulk email.
  • You are responsible for complying with the anti-spam and privacy laws that apply to you, such as CAN-SPAM and GDPR. Live sending stays off until your postal address is set.
  • Every email links to a one-click unsubscribe page; anyone who uses it is added to your suppression list automatically.
  • Threadline is not affiliated with or endorsed by Google.

Full details are in our Privacy Policy and Terms of Service.

Questions about security?

Email support@example.com — or sign in and see exactly what's requested on Google's consent screen.