Privacy Policy
Service: ThreadsLeads (Starks) · Last updated: 21 July 2026
ThreadsLeads ("the Service", "we", "us") is an AI business assistant, operated through a
Telegram bot and web cabinet, with three capabilities: (1) a
business assistant — drafting emails to your own business contacts, keeping a
lightweight CRM of them, scheduling meetings, and sending approval-gated email campaigns,
(2) lead intelligence — finding relevant public Threads conversations, and scoring
messages in Telegram groups/channels you add the bot to as an admin, then preparing reply
suggestions, and (3) niche autoposting — generating and publishing
content on a schedule to your Threads account or a Telegram channel you manage.
This policy explains what data we process, why, and your rights. By connecting your Threads
account, a Telegram channel or group, or a business integration (email/SMTP, Slack, Discord,
a webhook, SendGrid, or Google Calendar) you agree to this policy.
1. What we collect
- Telegram identity: your Telegram user ID and username, to operate the bot.
- Threads account connection: when you authorize via Meta/Threads OAuth, we store
your Threads user ID, username, and an access token protected with
authenticated Fernet encryption.
- Autoposting channel connection: if you connect a Telegram channel for autoposting,
we store its Telegram Bot API token, protected with the same authenticated Fernet
encryption, plus your chosen niche, tone, language and posting frequency.
- Telegram group/channel scanning: if you add the bot as an admin to a Telegram
group or channel for lead scanning, we process messages posted there from that point on to
score intent/urgency for you — we do not access message history from before the bot was
added, and we process nothing from groups/channels you have not added the bot to.
- Custom niche description: if you describe your business in free text instead of
picking a preset niche, that description is sent to our AI provider to generate a short
niche label and a pool of content topics; the description and the generated label/topics are
stored so they can keep producing on-topic posts.
- Business contacts: if you use the business assistant, we store the contact cards
you create or import for your own clients/partners/leads — name, email, phone, company,
messaging handles, notes, and consent/unsubscribe status. These are your own contacts, not
data scraped from Threads.
- Integration credentials: if you connect your own email/SMTP account or another
business integration (Slack, Discord, a generic webhook, SendGrid), we store the connection
settings and any password/API key/bot token/webhook URL, protected with the same
authenticated Fernet encryption used for Threads and channel tokens.
- Google Calendar connection: if you connect Google Calendar via OAuth, we store your
Google account's OAuth access and refresh tokens, protected with the same authenticated Fernet
encryption, and your email address to label the connection. We use this solely to
create a calendar event when you schedule a meeting through the assistant — we do not
read, list, or import your existing Google Calendar events, and rescheduling or cancelling a
meeting in the Service does not currently update or delete the corresponding Google Calendar
event. We request only the
calendar.events and userinfo.email
scopes.
- Communications: email drafts and sent messages, conversation threads, meeting
details (title, time, participants, location) and reminders, and campaign content/recipient
lists, all created through the business assistant.
- Content you act on: public Threads posts you choose to analyze, AI-generated
reply drafts, AI-generated autopost drafts, and leads you save. We do not collect private
Threads messages.
- Usage metadata: scans run, replies and posts published, emails/campaigns sent,
timestamps — for rate limiting and analytics.
2. How we use data
- To authenticate you and act on your behalf.
- To analyze public content and generate reply suggestions.
- To generate niche-relevant post drafts for your autoposting channels.
- To publish posts/replies from your connected account or channel — by default only after
your explicit confirmation; on Pro/Agency plans you may opt an autoposting channel into fully
automatic publishing, subject to fixed safety limits (see Terms of Service §3).
- To draft and, only after your explicit confirmation, send emails and campaigns to your own
business contacts, using your connected email integration or a built-in fallback provider, or
deliver approved messages through a connected Slack/Discord/webhook/SendGrid integration; to
schedule meetings and deliver reminders you request.
- To score messages in a Telegram group/channel you add the bot to, so relevant leads there
are surfaced to you the same way public Threads posts are.
- To enforce safety limits that protect your account from spam-like behavior, including
outbound-email daily caps, quiet hours, and honoring your contacts' unsubscribe/consent status.
3. Threads / Meta data
We access Threads data through the official Threads API using the permissions you grant
(threads_basic, threads_content_publish,
threads_keyword_search, threads_read_replies,
threads_manage_replies, threads_manage_insights,
threads_manage_mentions, threads_profile_discovery,
threads_delete), or, if you explicitly connect the Browser Agent, through
your own authenticated Threads browser session. The Browser Agent receives only the jobs
you start and returns the public posts or publication result needed for that job; it does
not receive or store your Threads password. We use this data solely to provide the Service: discovering
relevant public posts and public profiles, showing replies and mentions related to your own
content, publishing posts/replies/autopost content only as described above, showing account
insights, and deleting only posts you explicitly choose to delete.
We never sell this data. Our use complies with the Meta Platform Terms and Developer
Policies.
4. Storage & security
Data is stored in a PostgreSQL database on a private server. Access and bot tokens are
encrypted at rest. Access is restricted to the Service operator. We retain data only while
your account is active.
5. Sharing
We do not sell or rent your data. We share data only with infrastructure providers
strictly necessary to run the Service (hosting, the AI model provider for text/content
analysis and generation, Telegram's Bot API to operate your autoposting channel, Google
Calendar API — only if you connect it — to create meeting events, and — only if you connect
them — the SMTP provider you configure, or Slack/Discord/SendGrid/your configured webhook
endpoint, to deliver the messages you approve), and when required by law.
6. Your rights — data deletion
You can disconnect your Threads account, remove an autoposting channel, remove the bot from
a Telegram group/channel to stop scanning, or disconnect an email, Google Calendar, or other
business integration at any time from the bot or the web cabinet, or via your
Threads settings (Website permissions) or your Google Account's
third-party access settings. To delete
all your data, send a request through the bot or email the contact below; we will erase your
stored data, including access and bot tokens, autoposting channel settings and generated
content, saved leads, business contacts, email/message history, meetings and reminders,
campaigns, and integration connections.
7. Contact
Email: sturox.company@gmail.com
ThreadsLeads is an independent tool and is not affiliated with or
endorsed by Meta Platforms, Inc.