Privacy Policy
Who we are
Goldenthred Ltd is a company registered in England and Wales (Company Number: 17212595). We operate the Goldenthred platform, accessible at app.goldenthred.ai, and the Goldenthred Chrome extension.
Our registered address is on file with Companies House.
If you have any questions about this policy, contact us at: privacy@goldenthred.ai
What data we collect
We collect the following personal data when you use Goldenthred:
Account data
- Your name and email address when you register
- Your password (stored in encrypted form — we never see it in plain text)
Professional context data
- Information you enter about your client engagements, including client names, company names, role titles, and notes. This data is stored securely. Authorised personnel may access it only for the purposes of providing the service or resolving technical issues, and are bound by confidentiality obligations.
- AI-generated summaries and briefs created from content you provide
- Website URLs you add to workspaces
Usage data
- How you interact with the platform, including features used and actions taken
- Session information such as timestamps and duration
Technical data
- Your IP address
- Browser type and version
- Device type and operating system
Chrome extension data
- The extension captures context from AI tools (such as Claude and ChatGPT) that you have open in your browser, but only when you actively choose to save content. We do not monitor your browsing activity passively.
How we collect it
- Directly from you when you create an account, set up workspaces, or use the product
- Automatically through PostHog, our product analytics tool, which tracks how features are used to help us improve the product
- Through our Chrome extension, when you explicitly save content
Why we process your data
We process your data on the following legal bases under UK GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the Goldenthred service | Performance of a contract |
| Improving the product using analytics | Legitimate interests |
| Sending product updates and important notices | Legitimate interests |
| Complying with legal obligations | Legal obligation |
We do not use your data for advertising. We do not sell your data to third parties.
Third parties we share data with
We use a small number of trusted third-party services to operate Goldenthred:
- Supabase — our database provider. Your data is stored securely with row-level security enabled.
- OpenAI — we use OpenAI to generate briefs and intelligence summaries. Content you provide may be sent to OpenAI's API to generate these outputs. OpenAI's privacy policy applies to data processed through their API.
- PostHog — product analytics. PostHog collects usage data to help us understand how the product is used. You can review PostHog's privacy policy at posthog.com/privacy.
- Google — the Chrome extension is distributed via the Chrome Web Store.
We do not share your personal data with any other third parties without your consent, except where required by law.
Data storage and security
Your data is stored on Supabase infrastructure. We have implemented the following security measures:
- Row-level security on all database tables — you can only access your own data
- Authentication required on all API endpoints
- No client-side exposure of secret keys
- Rate limiting on all AI-powered endpoints
- CORS restricted to production domains
Despite these measures, no system is completely secure. If you believe your data has been compromised, contact us immediately at privacy@goldenthred.ai.
How long we keep your data
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (right to erasure)
- Restrict how we process your data
- Port your data to another service
- Object to processing based on legitimate interests
To exercise any of these rights, email us at privacy@goldenthred.ai. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data lawfully.
Cookies
The Goldenthred web application uses cookies for authentication and session management. We also use PostHog, which may set cookies to track usage. We do not use advertising cookies or third-party tracking cookies beyond PostHog.
Children
Goldenthred is intended for professional use by adults. We do not knowingly collect data from anyone under the age of 18.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or via a notice in the product. The date at the top of this page reflects when the policy was last updated.
Contact
Goldenthred Ltd
privacy@goldenthred.ai
Company Number: 17212595