Privacy Policy
This page says what actually happens to your data — including the parts that are stored readable rather than encrypted. Where something is not settled yet, it says that too.
Last updated: September 17, 2026
On this page
TL;DR
- Photos and video files never leave your device. From a video, only its audio track is extracted on your device and sent for transcription
- Your messages are stored as written, encrypted. Card and bank details, ID numbers and passwords are replaced by typed markers before an AI provider reads them, and put back in what you receive. Phone numbers and e-mail addresses travel with the text, because they are often what a message is about
- Your chat text is stored so the recap, its search and the follow-up chat keep working — delete it anytime
- Every voice message is sent for transcription, and is then kept with your recap so you can play it back — delete it anytime
- Deleting a recap or your account is immediate and cannot be undone, and it takes the transcripts we cached for that conversation's audio with it
Local Processing
Your chat files are parsed directly in your browser. The audio of every voice message is converted locally; for a video, your browser extracts only its audio track before transcription. Video files and visual content are never uploaded.
Minimal Storage
Chat text is stored so your recap stays readable, so its search works, and so the follow-up chat can answer. Photos and video files never leave your device. From a video, only the audio track your browser extracts is sent for transcription. The audio of every voice message, and that extracted track, is stored with your recap; you can delete that audio on its own, or delete the whole recap, at any time.
You Control Deletion
Delete any saved recap from your dashboard, or your entire account, after an explicit confirmation. Erasure starts immediately, cannot be undone, and takes the cached transcripts of that conversation's voice messages with it.
Information We Collect
ThreadRecap is designed to minimize data collection. Here is what we handle:
- Chat Files (Temporary): When you upload a WhatsApp export, the file is parsed in your browser. The whole conversation is sent to our servers so we can measure it, price it and analyze it. When you ask to buy the full analysis, we keep a private copy of the conversation so we can deliver it as soon as your payment clears; nobody but you can reach that copy, and it is erased if you do not buy. The text is held while the analysis is prepared, and if you save the analysis it is kept in two forms: the conversation itself, encrypted with our own key, and a searchable copy of each message held readable so you and the follow-up chat can find things in it. The searchable copy has card and bank details, ID numbers and passwords replaced by markers; the encrypted conversation keeps them as written. When a conversation holds such data, its page says so and offers three choices: delete it, remove that data everywhere we hold it, or keep it. We do our best to protect it, and no company can promise a leak never happens. You can delete both copies at any time from your dashboard.
- Audio & Video: Every voice message in your export is sent to our transcription provider, and so is the audio track your browser extracts from each video — the video file itself is never uploaded, only its audio track. There is no setting that turns this off. That audio is then stored with your recap so you can play it back alongside its transcript. You can permanently delete the audio on its own, or delete the recap, at any time.
- Account Information: If you create an account, we store your email address and basic profile information through our authentication provider (Clerk). We also store your balance and saved analysis results (encrypted at rest).
- Usage Data: We collect limited operational telemetry about how the app is used (such as pages visited and features used) to operate, secure and improve the service. When a recap is deleted we keep one de-identified sentence about why it was made, with labels describing it (its type and purpose, language and country, size, whether it was a group, the credits it used and its month), and no participants and no message text. When an account is deleted, those records lose every link to it: no name, email, account id or conversation id stays with them, and their date is kept only to the month.
- Integration Tokens: When you connect third-party services (Notion, Google Calendar, Trello), we store OAuth tokens encrypted at rest. These tokens are used solely to maintain your connections and are deleted immediately when you disconnect an integration or delete your account.
How We Use Your Information
Your data is used solely to provide the service:
- Processing chat content through AI to generate insights and summaries
- Transcribing voice messages and video audio using AI transcription
- Authenticating your account and managing your balance
- Saving analysis results to your dashboard (only when you choose to)
- Improving the service based on anonymous usage patterns
- Answering follow-up questions about your analysis results via AI Chat
- Exporting analysis results to connected third-party services at your request
- Building a searchable copy of your messages, and the numeric vectors that let the follow-up chat find the right ones
We do not sell or rent your personal information, and we do not share it for advertising. It is shared only with the providers listed below, and only with what each one needs to do its job.
Data Security
Some of what we store is encrypted with our own key, and some is deliberately held readable so the product can search it. Both are listed here:
- All data transmission uses TLS/SSL encryption
- Encrypted with our key: the saved conversation, the recap, the generated documents and your integration tokens
- Readable, not encrypted: the searchable copy of each message (with the removals described above), your follow-up chat history, and the one-sentence reason a recap was made
- Voice-message audio is stored in private object storage in the form you sent it, and its transcript is not put through the removals above
- Authentication is handled by Clerk, a dedicated identity provider
- Private audio and export files are served only through authenticated application endpoints
- Nobody here reads your conversations; they are processed by software, and there is no browsing tool that could
- We regularly audit our systems for security vulnerabilities
Third-Party Services
These providers receive your data, and only what each one needs:
- Text analysis (Anthropic, OpenAI): Your conversation text is sent to Claude by Anthropic and to GPT by OpenAI, whichever is available for the step being run. Both receive the text with card and bank details, ID numbers and passwords replaced by markers, and the markers are put back in the answer before you see it.
- Transcription (OpenAI): Every voice message, and the audio track your browser extracts from each video, is transcribed by OpenAI. Only audio is sent; the video file and visual content stay on your device. A number or a password said aloud in a voice message reaches the transcription provider as sound; the marker applies to the written transcript afterwards.
- Message search (OpenAI): Each stored message is turned into a numeric vector by OpenAI so the follow-up chat can find the right ones. The text sent for this is the searchable copy, with the same markers.
- Authentication (Clerk): Account creation and login are handled by Clerk, which manages your credentials securely.
- Payments (Stripe): Purchases are processed by Stripe. We never see or store your full payment details. If you tick the box to save your card at checkout, Stripe keeps it for your next purchase, and you can remove it on that same checkout page. For a purchase of a full conversation we also keep an order record — the amount, the payment reference, your e-mail address and which conversation it covers — so the purchase can be delivered, returned to your balance or refunded if you ask, and accounted for, and we send Stripe a reference code for that conversation with the payment. Deleting your account removes your e-mail address and browsing session from that record.
- Payments in the Android app (Google Play): In-app purchases are processed by Google Play, which is the seller of record for them. We receive a purchase receipt and the amount charged, never your payment details.
- Hosting (Vercel): Our service is hosted on Vercel with data centers that comply with industry security standards.
- Private Object Storage (Cloudflare R2): Audio, exports, and job files are stored privately in Cloudflare R2. We do not publish a public bucket or permanent public URLs for these files.
- Database (Neon): Your account, recaps and messages are stored in a managed PostgreSQL database run by Neon.
- Running the service (Inngest, Sentry, Upstash): Inngest runs the analysis pipeline, Sentry records errors, and Upstash holds short-lived rate-limiting counters. Error reports carry identifiers and technical detail, never conversation content.
- Product measurement (Vercel Analytics, Umami): We measure page views and feature use to see what works. Neither tool receives conversation content.
- Advertising tags (Google, OpenAI): Google Tag Manager loads Google Analytics and Google Ads, and an OpenAI advertising pixel runs alongside them, so we can tell which ads bring people here. These run only with your cookie consent, and you can change that choice at any time from the footer.
- Integrations (Notion, Google Calendar, Trello): Data is exported to these services only when you initiate it. OAuth tokens are stored encrypted. Once exported, your data is governed by each service's own privacy policy.
- Email (Resend): Transactional emails (welcome, analysis complete, etc.) are sent via Resend. We do not send marketing emails without your explicit consent.
Your conversations are not used to train AI models. Anthropic and OpenAI are called through their paid APIs, which do not train on what is sent to them.
The Android App
The ThreadRecap app for Android handles some things differently from the website, because a phone can do work a browser cannot:
- Conversations you share into the app: When you share a WhatsApp export to ThreadRecap, the archive is opened and read on your phone, the same rule the website follows. Photos and video files are never uploaded. The text needed for the analysis, the voice-message audio and the audio track extracted from each video are sent to our servers for transcription and analysis; the video and its picture stay on your device.
- Your contacts (never collected): If you allow it, the app reads your address book to put names to phone numbers in a conversation. That comparison happens entirely on your phone. No contact name, phone number or any other address-book field is ever sent to our servers, to our AI providers, or to anyone else, and we keep no copy of it. Turn the permission off and the app keeps working; the participants simply stay as the export wrote them.
- Files kept on your phone: The app can keep its own copy of an export so a conversation can be re-opened after the sending app releases the file. Those copies live only on your phone, are listed in the app's storage screen, and are deleted when you delete them or uninstall the app.
- Purchases through Google Play: Purchases made inside the app are sold and charged by Google Play. We never see or store your payment details. Google gives the app a purchase receipt, and the app sends that receipt to us so the purchase can be added to your account. Along with it we receive the product bought, the price Google charged and its currency, which we store as the record of the sale.
- Diagnostics: The app reports errors and crashes so faults can be found and fixed, and the same limited usage telemetry the website collects. Neither carries conversation content or contact data.
- Deleting your account from the app: The app has a direct account-deletion entry in the profile screen, and it deletes the same things the website does. See the account deletion page for what is removed and what is retained.
Data Retention & Deletion
We retain minimal data for the shortest time necessary:
- Voice-message audio is stored with the recap it belongs to, and is deleted when you delete the audio, the recap, or your account
- Analysis results you do not save are not kept
- Saved analyses and chat text are stored in your account until you delete them
- Account data is retained until you request deletion
- After you explicitly confirm deletion of a recap or account, it is immediate and irreversible. We remove stored recap content, messages, audio, documents, exports, and job files. If object storage is temporarily unavailable, we retain an encrypted deletion request and retry until the storage service confirms deletion.
- We retain financial transaction records and limited operational telemetry only as necessary for accounting, fraud prevention, security, and service operations. These records are not used to restore your recap or chat content.
- Integration tokens are deleted immediately when you disconnect a service or delete your account
- When you delete a recap, the transcripts we cached for that conversation's voice messages are deleted with it; uploading the same audio again pays for transcription again
- Our database keeps seven days of point-in-time history for recovery, so a deleted row is gone from the live database at once and out of that history within seven days
- The conversation you upload is held on our servers while you decide, so a paid analysis can start the moment you pay without uploading it again. That copy includes every voice message in your export, the audio track extracted from each video, and the transcripts made from them. If you do not buy, it is kept for up to thirty days after the upload and then erased automatically in our daily clean-up. If a paid analysis fails, its copy stays until the order's deadline, at most thirty days, so it can run again at no charge, and uploading another conversation does not erase it. Otherwise, uploading a different conversation ends the earlier price and erases its copy at once, and deleting the recap or your account erases it immediately.
Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for data processing
- Export your data in a portable format
To exercise any of these rights, please contact us at support@threadrecap.com.
Who is responsible
ThreadRecap is run by André Daniel Souza Silva, an individual based in Portugal, who is responsible for this policy and for the personal data of your account: your e-mail address, your balance, your purchases and the usage records described above. When ThreadRecap is registered as a company, the company takes this role and this page will name it.
For any question about this policy, and for every request under “Your rights” above, write to support@threadrecap.com. The same address answers.
The conversations you upload are yours to bring. Before your first upload you confirm that you have the right to use and upload the exports you send, and the Terms ask you to upload only conversations you take part in or that every participant agreed to share. For the other people in a conversation, you decide what is uploaded and why. ThreadRecap processes it only to deliver what you ask for, in the ways this page describes. Only people who agree to the Terms and to this policy may use ThreadRecap. If you do not agree, delete your account, and its data is erased as described above.
Each provider listed above processes data under its standard business terms. Anthropic's commercial terms include a data processing agreement.
How long each provider keeps what it receives, as each one publishes it:
- Anthropic deletes the text it receives within 30 days. It keeps text longer only when it is flagged for breaking Anthropic's usage policy, for up to 2 years, or when the law requires it.
- OpenAI keeps the text sent for analysis, chat and message search for up to 30 days, for abuse monitoring.
- OpenAI keeps no abuse-monitoring record of the voice messages it transcribes.
- Neon, Cloudflare R2 and Vercel store what we store, for as long as the retention rules above keep it.
- Inngest, which runs each analysis step, keeps the history of each run for 24 hours on the plan we use.
- Resend sends our e-mails and receives your replies to support. An e-mail can carry a document's title and what you write to support, and Resend keeps e-mail records under its own published policy.
- Clerk, Stripe, Google Play, Sentry and Upstash receive no conversation content. They keep account, payment, error and rate-limit records under their own published policies.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any significant changes by posting a notice on our website or sending you an email (if you have an account).
Your continued use of ThreadRecap after changes are posted constitutes acceptance of the updated policy.
Questions?
If you have any questions about this privacy policy or how we handle your data, please reach out to us.