Privacy Policy
Effective date: September 23, 2026
Last updated: September 23, 2026
The short version
- We collect what we need to generate FAQs from your reviews, and not much else.
- We don't sell your data, and we don't use your content to train AI models.
- Review text and product details are sent to our AI provider to generate your output.
- Card details go straight to Stripe. We never see them.
- Thresh does not connect to your store or to your review app. We ask for no access tokens, hold no credentials for any third-party service, and read nothing from your storefront.
- Email threshsince2026@gmail.com to see, correct, export or delete your data.
The rest of this page is the detail.
1. Who we are
Thresh FAQ is operated by Vicky Yu, doing business as Thresh, 1401 21st St #4894, Sacramento, CA 95811, United States. Contact: threshsince2026@gmail.com.
For your own account information we're the controller. For personal data inside the reviews you upload or paste into Thresh — your customers' data — you're the controller and we're your processor, under the Data Processing Addendum in our Terms of Service.
2. What we collect
2.1 From you, directly
| What | Why |
|---|---|
| Name and email | Your account, signing in, service messages |
| Password | Held by our authentication provider as a hash — we never see or store the password itself |
| Product details you enter (name, type, description) | Generating your FAQs |
| Reviews you paste or upload | Theme extraction and generation |
Everything above is entered by you, in the app. Thresh has no connection to your store, your review app or any other service you use, so we receive nothing automatically from them.
Reviews can contain personal data about your customers. We store review text only. We do not store reviewer names — if your CSV contains a reviewer-name column we ignore it, and nothing in Thresh ever attributes generated text to a named reviewer. Whatever a reviewer chose to write about themselves inside the review text itself is stored as written, so consider what you upload.
2.2 From Stripe
Payment confirmations, the brand, last four digits and expiry month/year of a saved card (so you can recognise it in your account), and Stripe identifiers for you and your payment method. We never receive or store full card numbers or security codes — those go directly from your browser to Stripe.
2.3 Automatically
Standard server logs (IP address, browser type, timestamps, pages requested) kept for security and debugging, and records of what you did in the app so we can bill runs correctly and support you.
We don't use advertising cookies, analytics trackers or other third-party tracking on our marketing site or in the app. Our marketing site loads its typefaces from Google Fonts, so your browser sends your IP address to Google when that page loads. The app uses a login session stored in your browser so you stay signed in.
3. What we do with it
- Run the Service: extract themes, generate FAQs, keep your results retrievable.
- Bill you correctly and apply your free runs.
- Support you when you ask.
- Keep the Service secure and diagnose faults.
- Send service messages about your account, such as password resets and payment receipts. We don't send marketing email; if that ever changes, we'll ask first and every message will include an unsubscribe link.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We do not use your reviews, products or generated output to train AI models. Our AI provider, Anthropic, does not train its models on data sent through its commercial API by default.
4. Who we share it with
These are our sub-processors. Each gets only what it needs.
| Provider | What it receives | Why | Where |
|---|---|---|---|
| Supabase | Account data, products, reviews, generated output | Database, authentication, server-side functions | United States (California) |
| WeWeb | Serves the application front end | Application hosting | Global |
| Cloudflare | Serves the marketing site | Website hosting | Global |
| Anthropic | Review text, product name, type and description | Generating themes and FAQs | United States |
| Stripe | Your name and email, and card data you enter directly with them | Payment processing | Global |
Shopify and review apps are not on this list, and that is the point. Thresh makes no requests to your storefront or to any review platform on your behalf.
We may also disclose data where the law requires it, to protect our rights or someone's safety, or to a buyer in connection with a sale of the business — in which case this policy continues to apply until you're told otherwise.
5. How we protect it
- All traffic to and from Thresh is encrypted in transit (TLS).
- Data is encrypted at rest by our database provider.
- Access to your data is enforced at the database level, so one account cannot read another's.
- Card data never touches our systems.
- We hold no credentials for any service of yours. There is no access token, API key or password for your store or your review app anywhere in Thresh, because we never ask for one. A credential we don't hold can't be leaked.
- Administrative access to production data is limited to the one person who operates Thresh.
No system is perfectly secure, and we can't guarantee absolute security. If a breach affects your data, we'll notify you and any regulator we're required to notify, without undue delay and within 72 hours of becoming aware where that obligation applies.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account is open, then deleted or anonymised within 30 days of closure |
| Products, reviews, themes, generated FAQs | While your account is open — your results stay retrievable — then deleted with the account |
| Billing records | 7 years, as tax and accounting law requires |
| Server logs | 90 days |
7. Your rights
Wherever you are, you can ask us to access, correct, export or delete your data, and to stop processing it. Email threshsince2026@gmail.com — we'll respond within 30 days, and we won't charge you or treat you differently for asking.
If the GDPR or UK GDPR applies to you, you also have rights to restriction, objection and portability, and a right to complain to your local supervisory authority. Our lawful bases are: contract (running the Service and billing you), legitimate interests (security, fault diagnosis, improving the Service), and consent where we ask for it.
If you're in California, you have rights of access, deletion, correction, and to know what we collect and share. We do not sell personal information or share it for cross-context behavioural advertising. You can appoint an authorised agent to act for you.
If you're a merchant asking about your customers' data — a reviewer asking you to delete a review you uploaded, for example — you're the controller. Delete it in Thresh, or email us and we'll help. If a request comes to us directly, we'll pass it to you rather than act on it ourselves.
8. International transfers
We're based in the United States, and our providers operate globally, so your data may be processed outside your country. Where data leaves the EEA or UK we rely on an appropriate safeguard, including the Standard Contractual Clauses.
9. Children
Thresh is for businesses and isn't directed at anyone under 18. We don't knowingly collect children's data; if we learn we have, we delete it.
10. Changes
We'll update the date at the top when this changes, and tell you about material changes by email or in the app before they take effect.
11. Contact
Vicky Yu, d/b/a Thresh
1401 21st St #4894, Sacramento, CA 95811, United States
threshsince2026@gmail.com