Privacy policy
Last updated
Version 1.1 · Effective
Who this policy is about
Tendthread is a tool for sending follow-up email. That means this policy covers two different groups of people, and they are owed different things.
- Customers — people who create a Tendthread account and connect a mailbox. You gave us your data directly and you can see and delete all of it.
- The people our customers contact, who we call leads. If you received an email sent through Tendthread, we hold your name, your email address, and the full text of any reply you sent — and you never signed up for anything. The sections on why we are allowed to do this and how to make it stop are written for you.
Who we are
Tendthread is the controller of the personal data described here. The company behind it is being incorporated in England and Wales; its registered name, company number and registered address will be published in this section as soon as they exist, and this policy will be given a new version when they are. Until then, the contact routes below are live and monitored.
For anything about your data — access, correction, deletion, objection, or a complaint — write to privacy@tendthread.com. For anything else, hello@tendthread.com.
What we hold
If you have an account
- Your name, email address, and company name.
- Your password, stored only as a hash, or the Google or Microsoft account you sign in with.
- The context you give us about what you sell — your offers, proof points, and any material you paste in for us to draw on.
- Which mailbox you connected, and the access needed to use it.
About the people you contact
- Their name, email address and company, and whatever you record about them.
- The full text of every message sent and every reply received in the threads Tendthread manages for you.
- The follow-up plans we generate, and the reasoning behind each version of them.
Access to your mailbox
Tendthread works by reading the threads it started, so that a reply is noticed and the follow-ups stop. To do that you grant it access to your mailbox through Google or Microsoft, and you can withdraw that access at any time — from Tendthread's settings, or from your account with the provider.
The read access these providers grant covers your whole mailbox, not only the threads Tendthread manages. That is a limitation of the permissions they offer, not a description of what we do with them: Tendthread reads the threads belonging to leads you created, and nothing else. We are working to request narrower access.
Google API Services User Data Policy
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, data obtained from Google is never sold, never used for advertising, and never used to train an AI model.
How an AI model is involved
Tendthread uses AI models to plan follow-ups, decide what a reply means, and write drafts. This means the content of messages — including replies from leads — is sent to AI model providers outside our own systems, and a record of each request is kept so that an email that went out can be explained afterwards.
Those providers are engaged as processors, act only on our instructions, and are configured so that nothing they are sent is used to train a model. What each category of provider receives and where it operates is set out in the disclosure linked below.
Why we are allowed to hold a lead's data
For customers, we process data because we have a contract with you, and to meet our legal obligations.
For leads we rely on legitimate interests. The reasoning, in plain terms:
- The interest. Our customer wants to reach someone at a business about something that business might buy, and to stop contacting them once they reply.
- Why it needs this data. There is no way to send a relevant follow-up, or to know when to stop, without holding the address and the thread.
- The balance. The data is business contact data, used to send business email that says who it is from and can be stopped by replying. It is not combined with data from anywhere else, not sold, not used for advertising, and not used to build a profile beyond the conversation itself. Set against that, being emailed at work about a service is a limited intrusion — and one a recipient can end immediately.
- Where the balance fails. If you tell us to stop, the interest no longer outweighs your objection, and we act on it. Our customers are also contractually required to have their own lawful basis for contacting you, and to have obtained your address legitimately rather than buying or scraping it.
To object or to be erased, reply to the email you received asking to be removed, or write to privacy@tendthread.com. An opt-out is honoured automatically and before anything else in our system decides what to do with a reply. Erasure is currently carried out by hand, so allow us a few working days.
Who else processes this data
We use other companies to run the product. Each is bound by a contract limiting it to processing data on our instructions. The categories of recipient are:
- Database hosting — Stores everything Tendthread holds. This is the primary copy of your data.
- Application hosting — Runs and serves the website and the product itself.
- Background job execution — Runs the scheduled work — planning follow-ups, processing incoming replies, and sending on schedule.
- AI model providers — Generate follow-up drafts, decide what a reply means, and read the seller context you provide.
- AI request records — Keep a record of what each AI request asked for and what it returned, so an email that went out can be explained afterwards.
- Transactional email delivery — Sends Tendthread's own email to you: address verification, password resets and account notices.
- Mailbox providers — Google and Microsoft — The mailbox you connect. Tendthread reads the threads it manages and sends follow-ups through your own address, using the access you grant.
The full disclosure sets out what each category receives and where it operates. Business customers who need the named list for a data processing agreement can request it from privacy@tendthread.com.
Where data is processed
The database holding everything Tendthread stores is in the United Kingdom. Some of the services above operate in the United States or the European Union, and the providers serving AI models may operate elsewhere — which one handles a given request is chosen at the time by the routing service. Where data leaves the United Kingdom it is transferred under the contractual safeguards UK data protection law requires.
How long we keep it
Each kind of data has its own period and its own reason for it. The periods below are the ones our systems actually enforce: a job runs every day and deletes what has passed them. This section is generated from the same configuration that job reads, so the two cannot drift apart.
Messages to and from a closed lead — deleted 24 months after the day the lead is marked closed, lost or archived. The full text of every message sent to that lead and every reply received from them. Once a lead is closed there is no follow-up to plan and no reply to interpret, so the reason for holding the conversation has ended. Twenty-four months is kept before deletion so a customer can reopen a dormant opportunity within a long B2B sales cycle without having lost the history. That is the permissive end of what is defensible, not the cautious end.
AI-written drafts about a closed lead — deleted 24 months after the day the lead is marked closed, lost or archived. The subject, body and reasoning of replies an AI model drafted for review but that were never sent. These drafts quote and paraphrase the lead's own words, so they hold the same personal data as the messages and are removed on the same clock. The record that a human review happened is kept, because that is what makes past automation explainable; the generated text inside it is not.
Rate-limit and spend counters — deleted 90 days after the last time the counter was incremented. The per-account counters behind the product's abuse and cost limits. A counter whose window closed months ago decides nothing. Ninety days is long enough to investigate a pattern of abuse after the fact and short enough that dormant accounts leave no trail behind them.
Your account and everything under it — not deleted on a schedule; held for as long as your account exists. Your account record, your leads, their follow-up plans, and the context you gave us about what you sell. This is the data the product is made of; holding it is the service. Deleting your account removes all of it immediately and irreversibly, and you can delete an individual lead at any time without deleting anything else.
What you agreed to, and when — not deleted on a schedule; held for as long as your account exists. One record per document and version you accepted. Deleting the record of a consent destroys the only evidence that it was given, which is the opposite of what a retention policy is for. These rows go when the account does, and not before.
Records of AI requests — not deleted on a schedule; held under the provider's own retention policy. The prompt and response of each AI request, kept so a sent email can be explained. These records are held by the provider that keeps them rather than in our database, so they expire under its retention policy and not one we set. We state that plainly instead of quoting a period we do not control.
A disconnected mailbox — not deleted on a schedule; held for as long as your account exists. Nothing on a schedule — the record that a mailbox was once connected is kept. Emails already sent were sent from that mailbox. Deleting the record of it would leave sends in the timeline that cannot be attributed to anything. The access itself is revoked at the provider on disconnection; what remains is the address and the dates.
Two things are quicker than any of the above and are always available to you. Deleting a lead removes that lead's messages with it, immediately. Deleting your account removes everything listed here at once, cancels any follow-up still scheduled, and cannot be undone.
What deletion does not yet cover.When a closed lead's conversation is deleted on the schedule above, the lead's own contact details — their name, email address and company — are kept, because your record of who you approached is what remains useful to you. If you are a lead and you want that removed as well, ask us and we will do it; see your rights.
Your rights
Under UK data protection law you can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to us processing it, ask us to restrict what we do with it, and ask for it in a portable form. These rights belong to leads as much as to customers, and we do not charge for exercising them.
Write to privacy@tendthread.com. If we get it wrong, you can complain to the Information Commissioner's Office, which is the supervisory authority for the England and Wales jurisdiction, at ico.org.uk. We would rather you came to us first.
Cookies
Tendthread sets one kind of cookie: the one that keeps you signed in. It is strictly necessary for the product to work, so it does not require your consent — which is why there is no cookie banner on this site.
There is no analytics, no advertising and no third-party tracking anywhere on this site or in the product. If that changes, this section changes with it, and a consent banner will appear before any such cookie is set.
Keeping it secure
Data is encrypted in transit and at rest. Mailbox access is held only for the mailbox you connected and is revoked when you disconnect it or delete your account. Passwords are stored as hashes and are never recoverable. Access to production systems is limited to those who need it.
Changes to this policy
This policy carries a version number and an effective date, both shown at the top. When something material changes we publish a new version, and — where the change affects what you agreed to — we tell account holders directly rather than relying on you re-reading this page.