Security
Careful with your inbox, your tokens and your leads.
Threadline acts in your name, from your own Gmail. Here's how it protects that trust — and the plain list of what it will and won't do.
Protections
How your account and data are protected
Any reply stops everything
Positive, negative or neutral — a reply ends all automation for that lead, and the thread is re-checked right before every follow-up.
Tokens encrypted at rest
Gmail OAuth tokens are encrypted with AES-256-GCM. Your Google password is never requested or stored.
Server-enforced daily caps
Limits are enforced on the server, per campaign and per mailbox — not just in the browser.
Never sent twice
Sending is built so the same email can never go to a lead twice, even if the server crashes mid-send.
Shared suppression list
Hard bounces and addresses you suppress are excluded from every campaign, current and future.
Append-only audit log
Every generated message, send, reply and bounce is recorded — and records are only ever added, never rewritten.
Google access
What access is requested, and why
Signing in uses Google sign-in and asks only for your name and email address.
Connecting Gmail is a separate step that asks for permission to send email on your behalf and to read your messages. Read access is what lets Threadline notice a reply, an out-of-office response or a bounce, so it can stop or pause a sequence. It is used only for messages related to emails the app sent — replies on its threads and bounce notices.
Tokens are encrypted at rest with AES-256-GCM. You can revoke access at any time from your Google Account's security settings, and you can ask us to delete your data by emailing support@example.com.
What the app does and does not do
What Threadline does
- Sends the emails you've set up, from your Gmail, as plain text.
- Reads messages on threads it started, to detect replies, out-of-office responses and bounces, and to give follow-ups context.
- Researches each lead's company from public web sources, and lists every source it used.
- Sends lead details, the research, your company profile and your playbook to Anthropic's API to write drafts.
- Records every generated message, send, reply and bounce in an append-only audit log.
What it never does
- Ask for, see or store your Google password.
- Add tracking pixels or rewrite links for click tracking.
- Scrape LinkedIn.
- Reply to anyone on your behalf.
- Try to get around Gmail's sending limits or spam filters.
- Sell your data, use it for advertising, or use Google user data to train generalized AI models.
Honest limits
Things you should know before you start
- It is designed for low-volume, personal one-to-one outreach — about 15–20 new emails a day — not bulk email.
- You are responsible for complying with the anti-spam and privacy laws that apply to you, such as CAN-SPAM and GDPR. Live sending stays off until your postal address is set.
- Every email links to a one-click unsubscribe page; anyone who uses it is added to your suppression list automatically.
- Threadline is not affiliated with or endorsed by Google.
Full details are in our Privacy Policy and Terms of Service.
Questions about security?
Email support@example.com — or sign in and see exactly what's requested on Google's consent screen.