← Back to Threadora
CLEAR BY DESIGN

Your inbox.
Your information.

Privacy should be easy to understand. Here is what Threadora handles, where it goes, and what you control.

Privacy policyEffective September 6, 2026

Your mail cache lives on your device. Optional AI sends selected email content to OpenAI. This website does not read your inbox.

1. Who we are

Threadora is a desktop email assistant operated by Bonline. This notice covers the Threadora desktop application and the websites threadora.bonlineco.com and license.bonlineco.com. It explains the current early-access service, including optional AI features.

For privacy questions or requests, contact info@bonlineco.com with “Threadora privacy” in the subject. Please do not send passwords, access tokens, or an entire mailbox with your request.

2. Information the app handles

When you connect a mailbox, Threadora accesses the account email address and available display name; message identifiers, senders, recipients, subjects, dates, message text, and attachment metadata; and calendar invitation data found in messages. It uses these to display your inbox, find possible meetings, create reminders, and help you prepare replies.

The app stores its cached messages, local drafts and sent-message records, meeting details, reminder preferences, provider configuration, and connection tokens on your device. A custom IMAP/SMTP connection also requires the server addresses, ports, usernames, and passwords you enter. Google and Microsoft sign-in use provider authorization pages; Threadora does not ask for their account passwords.

Ordinary attachment files are not automatically downloaded for viewing. Calendar invitation attachments may be processed to identify meeting details. Theme and language preferences are also saved locally.

3. Mail and calendar permissions

Google permissions currently cover reading Gmail messages (gmail.readonly), composing and sending mail (gmail.compose), and reading or changing calendar events (calendar.events). Microsoft connections are designed to use delegated profile, mail-reading, mail-sending, and calendar permissions, with offline access for continued synchronization.

Sending a message requires your review and confirmation in Threadora. Creating or updating an event in your provider’s calendar requires your action. The app may check for scheduling overlaps before creating an event. Proposed meetings are not automatically accepted, and personal calendar copies do not automatically invite attendees.

Google and Microsoft decide which permissions an account may grant. Connection availability during early access depends on provider setup, verification, and any organization administrator restrictions.

4. Optional AI and OpenAI

AI features use your own eligible ChatGPT account through the Codex runtime. When you request a summary, meeting or action-item analysis, a scam check, or a reply draft, selected message text and relevant context are sent from your device to OpenAI. A reply request can include up to eight cached messages from that conversation, along with your instructions. Analysis can include the sender address and display name, reply-to address, subject, message date, and your time zone. Suggested tasks, follow-ups, and scam-risk assessments are stored locally. Scam checks review available email text; they do not authenticate the sender, visit links, or scan attachments, and cannot guarantee safety.

Automatic analysis is off by default. If you enable it, Threadora can send up to ten newly imported messages per synchronization to OpenAI. You can turn it off in Settings and save your preferences. Mailbox passwords and connection tokens are not included in AI prompts. Bonline’s website is not an intermediary for this AI traffic.

OpenAI processes this information under its applicable terms, account settings, and privacy policy. Those controls affect provider-side retention and model-improvement use; an ephemeral application session does not mean that OpenAI retains nothing. Before using AI with Google mailbox data, use an account configuration that excludes that content from model training. Review your organization’s rules before sharing workplace messages.

Bonline does not use your mailbox content to train general-purpose AI models. AI output may be inaccurate; review recipients, wording, dates, and commitments before acting on it.

5. Sharing and Google Limited Use

Threadora uses mailbox data for the features you choose. Data is exchanged with your mail provider to synchronize messages, deliver approved mail, or manage calendar events. OpenAI receives the selected content described above when you use AI. Your operating system may display meeting information in notifications, including on a lock screen if your settings allow it.

Bonline does not sell mailbox data, use it for advertising, or give staff routine access to your local inbox. If you voluntarily send a message or screenshot to support, our support team will see the information you include. Providers and hosting operators process information needed to deliver their services; legal disclosures may be required by applicable law.

Threadora handles Google API data in accordance with the Google API Services User Data Policy and its Limited Use requirements. Google-derived data is limited to the disclosed, user-facing features. It is not used for advertising, credit decisions, surveillance, or general-purpose model training. This policy does not mean Google has verified or endorsed Threadora.

6. Storage, security, and retention

The desktop app keeps its mail cache, drafts, reminder data, settings, and mailbox credentials in a local encrypted vault using operating-system storage facilities. Custom mail connections default to TLS or STARTTLS with certificate validation. If you explicitly choose an unencrypted connection for a legacy server, the mailbox password and email traffic travel without TLS protection. SmarterMail API connections use HTTPS. Local vault encryption does not encrypt an unencrypted network connection. Remote tracking images and remote email HTML are not loaded in the message viewer.

ChatGPT sign-in is managed separately by the Codex runtime in its application data directory. It is not part of the encrypted email vault. Your operating-system account, disk protection, device backups, and OpenAI controls remain important.

Cached mailbox data remains on the device until you disconnect the account or remove the application’s data. Uninstalling the program alone may leave that data behind. The current app does not automatically expire cached messages on a fixed schedule. Support correspondence is retained as needed to handle the request and relevant business or legal obligations. Hosting logs are retained according to the hosting service’s operational and security requirements; contact us for information about a specific request. Provider-side messages and AI data follow those providers’ retention rules.

No security measure eliminates every risk. Bonline cannot remotely erase data from your device, your backups, or another provider’s systems.

7. Your choices and deletion requests

You can disconnect a mailbox in Threadora to remove that account’s local mail cache, drafts, and reminders. This does not delete mail or events at Google, Microsoft, or your mail server. Revoke provider authorization in your Google account connections or Microsoft account settings if you also want to invalidate continued provider access.

You can disconnect ChatGPT, disable automatic analysis, change notification settings, and remove Threadora’s local application data and backups. Use OpenAI’s account controls for data held by OpenAI. Bonline does not hold a server-side copy of your desktop inbox for us to retrieve or erase.

Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal information. Send requests concerning information held by Bonline to our privacy contact. We may need enough information to verify your identity and identify the relevant records. Some records may need to be retained where law permits or requires it.

8. This website and contacting Bonline

This marketing website does not connect to your mailbox, accept payments, or include advertising pixels or analytics scripts. Its fonts and illustrations are hosted on this domain. It stores a light/dark appearance preference in your browser’s local storage; clear site data to remove it. The language is selected through the page URL.

Our hosting service receives ordinary request information such as IP address, requested URL, time, response status, and browser information for delivery, security, and troubleshooting. Infrastructure providers may use essential security mechanisms. Clicking an email link opens your email application; Bonline receives your email address and whatever you choose to send. There is no hidden mailing-list subscription.

External services have their own privacy policies. Providers may process information in countries different from yours. Threadora is intended for adults managing their own or authorized work email and is not directed to children.

9. Changes to this notice

We will update this page when the service’s data practices change and revise the effective date. Material changes to mailbox-data use will be disclosed before the new use begins, with renewed consent where required. The license dashboard and payment processing are described below.

10. License dashboard and payments

The administrator dashboard and customer purchase pages are hosted at license.bonlineco.com. It stores administrator email addresses, password hashes and roles; customer email addresses linked to licenses; license and subscription records; activation-key hashes and encrypted keys; and administrative activity. Customers receive a license key after verified Stripe payment, or directly from an administrator, and activate the desktop app without registering a dashboard account. The purchase session links the confirmation page to the browser used for checkout; email alone cannot reveal a key. Administrator login and customer checkout use an essential, host-only session cookie. Language is stored in the session; appearance preferences may be stored in your browser.

Desktop activation sends the license key initially and then a device activation identifier and secret to Bonline over HTTPS. The service records a random device identifier, device label, operating-system platform, app version, and activation/validation times to enforce device limits and check access. The license service does not receive your mailbox password, message content, or ChatGPT credentials.

Stripe processes payments arranged by Bonline. Verified successful payment automatically issues or renews the license. The customer copies or downloads the key on the payment confirmation page and enters it in Threadora. Administrators can suspend or revoke access. Bonline sends the account email and product/order references to Stripe, and retains customer, price, invoice-related subscription status, and payment-event references needed to manage access. Card entry happens on Stripe; Threadora does not store full card numbers. See Stripe’s privacy policy.

License/account records remain while needed to provide access, resolve billing/support requests, prevent abuse, and meet applicable accounting obligations. There is no automatic account-data purge in the current release; contact Bonline to request account closure or deletion. Some transaction or audit records may need to be retained. Removing a device stops future license validation for that activation; an already issued offline access token can remain valid for up to 72 hours, within the license expiry.