ThreadScope.

Sub-Processors

Last updated: 13 August 2026

This page lists all third-party sub-processors that may process customer data on behalf of ThreadScope. We will notify customers by email at least 30 days before adding new sub-processors. Customers have 14 days from the date of notice to object with reasonable grounds.

Railway

Infrastructure

Purpose:
Application hosting, database hosting, and container orchestration
Location:
United States
Data types:
All customer data (account information, posts, chat history)
Security:
SOC 2 Type II, encryption at rest and in transit, private networking
Visit website

OpenRouter

AI / LLM

Purpose:
LLM routing provider for AI chat and analysis features. Routes requests to the downstream model providers listed below.
Location:
United States
Data types:
AI chat messages (prompts and responses), post text for analysis and embeddings
Security:
TLS encryption, no training on customer data by default
Visit website

OpenRouter is a routing layer. ThreadScope selects the model for you and uses a fixed set -- the downstream providers your data reaches through it are listed individually below.

Google

AI / LLM (via OpenRouter)

Purpose:
Downstream model provider for Gemini 2.5 Flash and Gemini 2.5 Flash-Lite (AI chat, post analysis, and tag description generation)
Location:
United States
Data types:
AI chat messages (prompts and responses) and post text sent for analysis
Security:
SOC 2 Type II, ISO 27001, encryption at rest and in transit
Visit website

OpenAI

AI / LLM (via OpenRouter)

Purpose:
Downstream provider for text embeddings (text-embedding-3-small) used for semantic tag matching
Location:
United States
Data types:
Tag descriptions and post text sent for embedding generation
Security:
SOC 2 Type II, encryption at rest and in transit, no training on API data by default
Visit website

Polar

Payments

Purpose:
Merchant of record, subscription billing, and payment processing
Location:
Sweden
Data types:
Email address, name, billing address, payment method details
Security:
PCI DSS compliant, encryption at rest and in transit
Visit website

Resend

Email Delivery

Purpose:
Transactional email delivery (verification, password reset, notification digests)
Location:
United States
Data types:
Email addresses, email content for notifications
Security:
SOC 2 Type II, TLS encryption, DKIM/SPF/DMARC
Visit website

Arcjet

Security

Purpose:
Rate limiting, bot detection, and abuse prevention
Location:
United States
Data types:
Request metadata (IP addresses, HTTP headers). No message content.
Security:
TLS encryption
Visit website

Sentry

Error Tracking

Purpose:
Application error monitoring and performance tracking
Location:
United States
Data types:
Error reports, stack traces, performance metrics. No message content.
Security:
SOC 2 Type II, encryption at rest and in transit
Visit website

Notification of changes

We will notify all registered users by email at least 30 days before adding, replacing, or materially changing any sub-processor. The notification will include the sub-processor's name, purpose, location, and the categories of data it will process. Customers who object may terminate their account as described in our Data Processing Addendum.

Questions?

If you have questions about our sub-processors or wish to object to a new sub-processor, contact hello@threadscope.io.

Version history

  • 13 August 2026 -- Removed the bring-your-own-key model menu. ThreadScope now selects the model for you, so data only reaches Google (Gemini 2.5 Flash / Flash-Lite) for chat and analysis and OpenAI (text embeddings) via OpenRouter. Removed Anthropic, Meta, Mistral AI, DeepSeek, and NVIDIA, which are no longer used, and dropped the reference to storing user API keys.
  • 14 May 2026 -- Initial version.