Privacy Policy
Who we are
Goldenthred Ltd is a company registered in England and Wales (Company Number: 17212595). We operate the Goldenthred platform, accessible at app.goldenthred.ai, and the Goldenthred Chrome extension.
Our registered address is on file with Companies House.
If you have any questions about this policy, contact us at: privacy@goldenthred.ai
What data we collect
We collect the following personal data when you use Goldenthred:
Account data
- Your name and email address when you register
- Your password (stored in encrypted form — we never see it in plain text)
Professional context data
- Information you enter about your client engagements, including client names, company names, role titles, and notes. This data is stored securely. Authorised personnel may access it only for the purposes of providing the service or resolving technical issues, and are bound by confidentiality obligations.
- AI-generated summaries, briefs, and outputs created from content you provide
- Website URLs you add to workspaces
- Commitments and actions you log manually or via screenshot extraction, including text, due dates, and associated contact names
Usage data
- How you interact with the platform, including features used and actions taken
- Session information such as timestamps and duration
Technical data
- Your IP address
- Browser type and version
- Device type and operating system
Chrome extension data
- The extension captures context from AI tools (such as Claude and ChatGPT) that you have open in your browser, but only when you actively choose to save content. We do not monitor your browsing activity passively.
- Screenshots you take using the extension capture feature are processed in memory to extract actions and commitments. Screenshots are never stored on our servers and are discarded immediately after processing.
How we collect it
- Directly from you when you create an account, set up workspaces, or use the product
- Automatically through PostHog, our product analytics tool, which tracks how features are used to help us improve the product
- Through our Chrome extension, when you explicitly save content or use the screenshot capture feature
Why we process your data
We process your data on the following legal bases under UK GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the Goldenthred service | Performance of a contract |
| Improving the product using analytics | Legitimate interests |
| Sending product updates and important notices | Legitimate interests |
| Complying with legal obligations | Legal obligation |
We do not use your data for advertising. We do not sell your data to third parties.
How AI features use your data
Several Goldenthred features send content from your workspaces to third-party AI services to generate outputs. Specifically:
Brief Me
When you generate a pre-session brief, content from your workspace including captures, commitments, outputs, and intelligence items is sent to OpenAI's API. The Brief Me agent may make multiple API calls to generate a single brief.
Intelligence analysis
When you run an intelligence analysis on a workspace, company and market data associated with that workspace may be sent to OpenAI's API.
Screenshot capture
When you use the screenshot capture feature in the extension, the captured image is sent to OpenAI's API for processing. The image is discarded immediately after the API call returns and is never stored on our servers.
People intelligence
When generating briefs, we may search publicly available web sources for information about individuals mentioned in your workspace content, to provide context relevant to your engagements. This uses OpenAI's web search capability and is subject to OpenAI's privacy policy.
We use OpenAI's API under a data processing agreement. OpenAI does not use API data to train its models by default. For more information, see OpenAI's privacy policy at openai.com/privacy.
Third parties we share data with
We use a small number of trusted third-party services to operate Goldenthred:
- Supabase — our database provider. Your data is stored securely with row-level security enabled. Supabase's privacy policy applies to infrastructure-level data handling.
- OpenAI — we use OpenAI to generate briefs, intelligence summaries, and to process screenshot captures. Content you provide may be sent to OpenAI's API to generate these outputs. OpenAI's privacy policy applies to data processed through their API.
- PostHog — product analytics. PostHog collects usage data to help us understand how the product is used. You can opt out of PostHog analytics by emailing privacy@goldenthred.ai. You can review PostHog's privacy policy at posthog.com/privacy.
- Google — the Chrome extension is distributed via the Chrome Web Store.
We do not share your personal data with any other third parties without your consent, except where required by law.
Data storage and security
Your data is stored on Supabase infrastructure. We have implemented the following security measures:
- Row-level security on all database tables — enforced at the database level, not just the application level. You can only access your own data even if there is an application-level error.
- Tenant isolation enforced regardless of schema state — the database rejects unauthorised queries independently of application code
- Authentication required on all API routes — unauthenticated requests are rejected at the API boundary
- Chrome extension auth restricted to the verified goldenthred.ai domain only — the extension cannot be reconfigured by third-party pages
- Screenshots processed in memory and discarded immediately — never written to disk or stored in the database
- No client-side exposure of secret keys or API credentials
- Rate limiting on all AI-powered endpoints — prevents abuse and controls costs
- CORS restricted to production domains
- Server-side fetch restricted to a verified allowlist of domains
Despite these measures, no system is completely secure. If you believe your data has been compromised, contact us immediately at privacy@goldenthred.ai.
How long we keep your data
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (right to erasure)
- Restrict how we process your data
- Port your data to another service
- Object to processing based on legitimate interests
- Opt out of analytics data collection
To exercise any of these rights, email us at privacy@goldenthred.ai. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data lawfully.
Cookies
The Goldenthred web application uses cookies for authentication and session management. We also use PostHog, which may set cookies to track usage. We do not use advertising cookies or third-party tracking cookies beyond PostHog.
Children
Goldenthred is intended for professional use by adults. We do not knowingly collect data from anyone under the age of 18.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or via a notice in the product. The date at the top of this page reflects when the policy was last updated.
Contact
Goldenthred Ltd
privacy@goldenthred.ai
Company Number: 17212595