This page lists all third-party sub-processors that may process customer data on behalf of ThreadScope. We will notify customers by email at least 30 days before adding new sub-processors. Customers have 14 days from the date of notice to object with reasonable grounds.
Railway
Infrastructure
- Purpose:
- Application hosting, database hosting, and container orchestration
- Location:
- United States
- Data types:
- All customer data (account information, posts, chat history)
- Security:
- SOC 2 Type II, encryption at rest and in transit, private networking
OpenRouter
AI / LLM
- Purpose:
- LLM routing provider for AI chat and analysis features. Routes requests to the downstream model providers listed below.
- Location:
- United States
- Data types:
- AI chat messages (prompts and responses), post text for analysis and embeddings
- Security:
- TLS encryption, no training on customer data by default
OpenRouter is a routing layer. ThreadScope selects the model for you and uses a fixed set -- the downstream providers your data reaches through it are listed individually below.
AI / LLM (via OpenRouter)
- Purpose:
- Downstream model provider for Gemini 2.5 Flash and Gemini 2.5 Flash-Lite (AI chat, post analysis, and tag description generation)
- Location:
- United States
- Data types:
- AI chat messages (prompts and responses) and post text sent for analysis
- Security:
- SOC 2 Type II, ISO 27001, encryption at rest and in transit
OpenAI
AI / LLM (via OpenRouter)
- Purpose:
- Downstream provider for text embeddings (text-embedding-3-small) used for semantic tag matching
- Location:
- United States
- Data types:
- Tag descriptions and post text sent for embedding generation
- Security:
- SOC 2 Type II, encryption at rest and in transit, no training on API data by default
Polar
Payments
- Purpose:
- Merchant of record, subscription billing, and payment processing
- Location:
- Sweden
- Data types:
- Email address, name, billing address, payment method details
- Security:
- PCI DSS compliant, encryption at rest and in transit
Resend
Email Delivery
- Purpose:
- Transactional email delivery (verification, password reset, notification digests)
- Location:
- United States
- Data types:
- Email addresses, email content for notifications
- Security:
- SOC 2 Type II, TLS encryption, DKIM/SPF/DMARC
Arcjet
Security
- Purpose:
- Rate limiting, bot detection, and abuse prevention
- Location:
- United States
- Data types:
- Request metadata (IP addresses, HTTP headers). No message content.
- Security:
- TLS encryption
Sentry
Error Tracking
- Purpose:
- Application error monitoring and performance tracking
- Location:
- United States
- Data types:
- Error reports, stack traces, performance metrics. No message content.
- Security:
- SOC 2 Type II, encryption at rest and in transit
Notification of changes
We will notify all registered users by email at least 30 days before adding, replacing, or materially changing any sub-processor. The notification will include the sub-processor's name, purpose, location, and the categories of data it will process. Customers who object may terminate their account as described in our Data Processing Addendum.
Questions?
If you have questions about our sub-processors or wish to object to a new sub-processor, contact hello@threadscope.io.
Version history
- 13 August 2026 -- Removed the bring-your-own-key model menu. ThreadScope now selects the model for you, so data only reaches Google (Gemini 2.5 Flash / Flash-Lite) for chat and analysis and OpenAI (text embeddings) via OpenRouter. Removed Anthropic, Meta, Mistral AI, DeepSeek, and NVIDIA, which are no longer used, and dropped the reference to storing user API keys.
- 14 May 2026 -- Initial version.