Security and Data Use
Last updated: September 9, 2026
For deployment guidance, see Threadclip for IT admins. For the full data-use policy, read our privacy policy.
What access does Threadclip need?
Signing into Threadclip and connecting a mailbox are separate decisions. Mailbox permissions allow access beyond a single selected message. Threadclip uses them to show recent message details, run searches you request, prepare your selected conversation and find related attachments. Sending happens when you review the forward, choose recipients and attachments, and select Send forward.
- Gmail: gmail.readonly lets Threadclip read messages and attachment data; gmail.send lets it send the forward you approve. These are Google API permissions, not access technically restricted to one chosen message.
- Outlook: delegated Microsoft Graph Mail.Read lets Threadclip read messages and attachments in the connected mailbox; Mail.Send lets it send on your behalf. These are permissions for the signed-in user, not app-only access to every mailbox in an organisation.
- Microsoft User.Read identifies the connected account. offline_access allows the connection to be refreshed when you return; it is not permission to send without your action.
- Sign-in uses openid, email and profile to identify your Threadclip account. Google can also provide refresh access for the mailbox connection.
- Threadclip does not run a recurring server-side inbox scan. Attachment recovery may check a limited set of recent messages when needed for the conversation you select.
Permissions in Gmail and Outlook add-ins
- The Gmail add-on uses gmail.addons.execute to run inside Gmail, gmail.readonly to read messages and attachments, gmail.send to send your approved forward, and script.external_request to communicate with Threadclip. Google presents its own installation and permission screens.
- The Outlook add-in requests the Office ReadItem permission for the current item. A separate Microsoft mailbox connection uses the delegated Graph permissions described above for retrieval and sending. Installing the add-in does not by itself grant that Graph access.
- An organisation may require administrator approval or deployment. A return from its approval process does not establish that mailbox consent was granted.
Email content and the details we retain
Threadclip processes email bodies and attachment files to prepare and send your forward. Processing is not limited to your browser. Threadclip is not a mailbox archive; clip-history records do not contain the email body or attachment file contents.
- Clip history can include the subject, sender, original and forwarding recipients, message and thread identifiers, timestamps, attachment counts and recovery status. These details can identify people and messages; they are not anonymous.
- Attachment indexing and recovery records can include filenames, file types, sizes, mailbox and message identifiers, matching features, scores and feedback. These are metadata, separate from message bodies and attachment file contents.
- Temporary processing can include a Gmail add-on user cache of prepared content configured to expire after ten minutes. A forward may also involve a draft or sent item stored by your email provider. Disconnecting Threadclip does not delete those provider-held items.
- Account, billing and operational records are also retained to run and secure the service. See the privacy policy for data-use and retention details.
Attachment recovery and AI
Attachment recovery uses deterministic matching rules, not machine learning, to find and rank related attachments. Threadclip does not train AI models on your emails or other customer data. Recovery metadata and feedback are recorded separately from email bodies and attachment files; recording that metadata is not model training.
Disconnecting and deleting your account
- You can disconnect a mailbox in Settings. This removes the connection held by Threadclip; it does not delete mail in Google or Microsoft.
- Provider consent is a separate control. You can review or revoke Threadclip access in your Google or Microsoft account; an organisation may manage that control for you.
- Before scheduling deletion, resolve any shared-workspace or organisation ownership shown in Settings. Shared workspace owners must transfer or remove the workspace; owners of organisations with other members must transfer ownership.
- You can then schedule account deletion in Settings. Provider access held by Threadclip is disconnected immediately. Scheduled cleanup removes eligible user-linked records after the deletion window, subject to limited legal, billing, security and abuse-prevention retention.
- Disconnecting a mailbox alone does not delete your Threadclip clip history. Account deletion and provider-held drafts or sent mail are separate matters.
Security practices
- Web traffic and provider API calls use TLS. Stored mailbox connection tokens are encrypted on Threadclip’s servers; operational logs support reliability and abuse prevention.
- The application and database run on separate hosts with restricted private database access.
- We perform internal security testing and vulnerability scanning, including application testing, host scans and targeted authorisation and data-access checks. These internal tests are distinct from an independent penetration test.
Google user data commitments
- Threadclip uses Google user data to provide the user-requested clipping and forwarding workflow.
- Threadclip does not sell Google user data or use it for advertising.
- Threadclip does not transfer Google user data to third parties except as required to provide or secure the service, or to comply with law.
Reporting security issues
Report security concerns to admin@threadclip.com with reproduction details and impacted endpoint URLs. Do not include mailbox contents, passwords or access tokens.
Forward the useful part of the thread. Built for people who live in email.
© 2026 Clever Iterations Pty Ltd (ABN 19 695 039 019). Threadclip™ is a Clever Iterations product. All rights reserved.