Security

Security and Data Use

Last updated: May 1, 2026

Security baseline

  • TLS is required for all web traffic and provider API calls.
  • Provider access tokens are stored server-side and refreshed securely.
  • Authentication and billing are separated from add-in logic.
  • Operational logs are used for reliability and abuse prevention.

Google Workspace add-on scopes used

  • https://www.googleapis.com/auth/gmail.addons.execute
  • https://www.googleapis.com/auth/gmail.readonly
  • https://www.googleapis.com/auth/gmail.send
  • https://www.googleapis.com/auth/script.external_request

Web OAuth mailbox scopes used

When you connect a mailbox from the web app, Threadclip asks only for sign-in identity plus the mailbox permissions needed to read the message you choose and send the forward you approve.

  • Google sign-in identity: openid, email, profile
  • Google mailbox access: https://www.googleapis.com/auth/gmail.readonly
  • Google sending access: https://www.googleapis.com/auth/gmail.send
  • Microsoft sign-in identity: openid, email, profile
  • Microsoft refresh access: offline_access
  • Microsoft account profile: https://graph.microsoft.com/User.Read
  • Microsoft mailbox access: https://graph.microsoft.com/Mail.Read
  • Microsoft sending access: https://graph.microsoft.com/Mail.Send

Google user data usage commitments

  • Threadclip uses Google user data only to perform user-initiated clipping and forwarding actions.
  • Threadclip does not sell Google user data.
  • Threadclip does not use Google user data for advertising.
  • Threadclip does not transfer Google user data to third parties except as required to provide or secure the service, or to comply with law.

Retention and controls

  • Users can disconnect Google and Microsoft providers from settings at any time.
  • Users can schedule account deletion from settings; provider access is disconnected immediately.
  • Scheduled deletion cleanup removes user-linked Threadclip records after the deletion window, subject to limited legal, billing, security, and abuse-prevention retention.
  • Threadclip stores clip and activity metadata for account history and support operations.

Reporting security issues

Report security concerns to admin@threadclip.com with reproduction details and impacted endpoint URLs.

© 2026 Clever Iterations Pty Ltd (ABN 19 695 039 019). Threadclip™ is a Clever Iterations product. All rights reserved.

Analytics cookies, only if you opt in. Privacy