THREADWELL · YOUR INFORMATION, EXPLAINED.
Privacy policy
Updated October 1, 2026. This policy describes the current Threadwell browser extension, its optional account service, and paid Pro subscriptions. Threadwell uses Supabase for email-code sign-in and Stripe Managed Payments for paid subscriptions.
Operator: Threadwell.app, USA. For product support, account assistance, privacy questions, or account-deletion requests, email contact@threadwell.app.
Threadwell is an independent browser extension and is not affiliated with OpenAI.
Information read and stored
Threadwell reads the signed-in ChatGPT account’s conversation and project catalog: titles, identifiers, links, and project membership. It requests active and archived conversation lists, project lists, and conversation lists within projects, including additional pages. It does not request or store conversation transcript bodies.
The current Chrome profile’s local extension storage (chrome.storage.local) contains:
- Conversation and project titles, URLs, and source identifiers.
- Local folder names, hierarchy, ordering, optional per-item color selections and tags, favorite markers, saved filters (names, title queries, tag criteria, and item type), and empty folder templates.
- Flags recording local name and placement choices so later refreshes preserve them.
- A catalog identity combining the ChatGPT user identifier and active workspace identifier, or a personal-workspace marker.
- Organizer preferences and settings, including the selected refresh mode and interval, backup schedule/retention, and collapsed search controls.
- Device-sync preferences, status, device identifier, and bounded conflict-resolution metadata when sync has been configured.
- Last refresh times, the next scheduled check, any rate-limit pause, and a temporary coordination record identifying the tab or page handling a refresh or rename (rename records also hold the requested title, conversation link, and intended local destination) so tabs do not duplicate requests. These coordination records are local and not included in exported folder backups.
Manual saving uses the current ChatGPT URL and available page title or label. Undo snapshots are held separately in Chrome’s in-memory session storage (chrome.storage.session), with a maximum of ten changes and a 4 MiB history budget. Large collections may retain fewer changes. Settings are excluded from undo.
Saved titles, identifiers, and links can reveal private information even without transcripts. Anyone using the same Chrome profile may be able to view them.
Authentication and network behavior
User-requested or enabled scheduled refreshes make authenticated, read-only requests to https://chatgpt.com. It obtains the existing session through /api/auth/session and uses the returned access token for the catalog requests. The token stays in memory for that refresh; it is not written to extension storage, backups, or logs and is not sent to an external server.
The content script reads the _account value from the page’s accessible cookies to identify the selected workspace and set the relevant account header for catalog requests. It does not store the cookie string. The resulting user/workspace identity is stored with the organizer to prevent a later refresh from merging a different account’s catalog. Normal browser credentials are included only in requests to ChatGPT; redirects are rejected.
Manual-only mode is the default. Free access permits manual refresh; automatic schedules require verified Pro access. Losing Pro access disables the schedule without deleting saved colors or organizer entries. No catalog requests run solely because the page loads, reloads, navigates, or regains visibility in manual-only mode. Requests run when you choose refresh, or when your enabled schedule is due while a ChatGPT tab is visible. Tabs share one scan at a time. Requests within a scan are spaced apart, and rate-limit responses stop further requests and establish a shared pause. The reader requests metadata lists, not transcript endpoints. Partial or failed refreshes are reported in the sidebar. These are undocumented ChatGPT website endpoints, and their availability or format may change.
Only when you explicitly save a conversation name, Threadwell obtains the current session and sends a title-only PATCH to that conversation on ChatGPT. It checks the organizer’s account/workspace binding before writing, rejects redirects, and requires a positive server acknowledgement before committing the name locally. The token stays in call memory and is never returned or stored. Renames and catalog refreshes share a lock and rate-limit pause; there is no rename polling or automatic retry. No transcript is fetched to confirm a rename. Imports and previously saved local aliases do not trigger writes.
Threadwell adds no analytics or advertising telemetry. The optional account service communicates with Threadwell's configured Supabase project as described below. End users do not enter API keys. If you opt into device sync, it writes organization metadata to Chrome's built-in sync storage; Chrome may transfer it through the Google account configured for browser sync. It does not upload the organizer to the Supabase account service. Opening a shortcut navigates directly to ChatGPT, which controls access under its own terms and privacy practices.
Optional Threadwell sign-in
The current build uses Supabase Auth for email-code sign-in. Supabase receives the email address, sign-in verification requests, and session credentials needed for authentication. Sign-in codes are delivered through the configured Namecheap SMTP mailbox, signin@threadwell.app; Namecheap and the recipient's email provider process delivery of those messages. Support and privacy requests go to contact@threadwell.app. Google sign-in is not offered in the current version.
The Threadwell account database records the Auth user identifier, account plan fields, optional Pro expiration, and creation time. Pro access is determined from separate, fresh server-verified subscription records, not from a locally selected plan. Account responses include the verified email and access-check time. Authentication, hosting, and email providers may retain network, operational, and security logs under their own policies. No conversation content, titles, links, folders, colors, templates, or organizer backups are uploaded to this account backend.
Sign-in occurs on an account page belonging to the extension. Access/refresh tokens, user identifier, expiry, and backend issuer are retained in the extension's own local database (IndexedDB) so the session can resume. Content scripts and the ChatGPT page do not receive these credentials. The extension's background service stores the verified plan only in memory. Account credentials are excluded from manual backups, history snapshots, diagnostics, and Chrome Sync. Local browser-profile access is still sensitive; these controls are not protection against someone controlling the computer.
While Chrome runs, account access is checked approximately every five minutes. A temporary connection failure may preserve a previously verified plan for at most fifteen minutes in the running background service, bounded by the access token's expiry and any Pro expiry. The plan cache is not persisted, so after the background service or browser restarts a fresh server check is required. Supabase credentials are sent only to the configured project. Threadwell sign-in does not use or transmit the ChatGPT access token.
Sign-out removes the local Threadwell session and requests revocation of that session from Supabase when reachable; it does not delete local organization, history, exports, or Chrome Sync snapshots. Threadwell account switching does not create isolated collections. Free core organization remains available while signed out.
Deleting your Threadwell account
Hosted-account deletion currently requires operator assistance and verification of the account owner; there is no self-service deletion button. Send requests to contact@threadwell.app. Deleting the corresponding Supabase Auth user removes its Threadwell account, associated billing and subscription records, and per-account reconciliation queue records. Local organization, local backup history, exported files, and Chrome Sync data remain separate. Processed webhook IDs and aggregate scheduling records have different retention, described below.
Deleting the Threadwell account, signing out, or uninstalling the extension does not cancel a paid subscription or erase Stripe records. Cancel through Manage subscription before account deletion, or contact contact@threadwell.app to coordinate cancellation separately. Stripe may retain transaction and compliance records under its own policies. The portal manages billing; it does not delete a Threadwell account.
Payments and subscriptions
Pro checkout requires a signed-in Threadwell account. Threadwell's billing service contacts Stripe when the user loads plans, starts or reopens checkout, checks checkout status, refreshes subscription access, or opens subscription management. Signed payment events and scheduled background verification also cause server-to-server requests, as described below. These subscription checks are separate from the user's manual or scheduled ChatGPT catalog refresh setting.
The extension sends its Threadwell authentication token only to the configured Supabase project. The server verifies the current user and session, then contacts Stripe using a credential held only on the server. It sends the verified Supabase user UUID as an opaque account reference in Stripe metadata and checkout's client reference, plus the price, selected plan, and checkout-attempt identifiers. It does not automatically send the verified account email to Stripe. The user enters payment, contact, and any requested billing details directly on Stripe's hosted form. Stripe and its payment providers handle that information under their own practices. The extension never collects card details.
Stripe Managed Payments uses Stripe's affiliate Sold through Link, LLC as merchant of record for these transactions. Threadwell provides the extension. Stripe/Link processes payments and provides transaction support, including applicable tax handling under the Managed Payments service. See Stripe's privacy policy, Link's privacy center, and Link transaction support.
Supabase's protected billing records store the user UUID, Stripe customer/price/checkout identifiers, selected plan, checkout state, creation-attempt identifiers and timestamps, and request cooldown/lease records. These support status checks and prevent duplicate checkout creation. Ordinary extension users cannot directly read or change those tables. Records persist until operator cleanup or deletion of the associated Supabase Auth user; there is no scheduled deletion of the account's billing/subscription records. Stripe's records remain separate.
The account page receives the offered plans, bounded checkout/payment and subscription status, cancellation state, paid-through and verification expiry, and safe error messages. The extension's background service validates a Stripe checkout or portal URL before opening it in a separate tab; it does not expose that URL to the ChatGPT page. Local billing retry timing and bounded per-account automatic-refresh cooldowns are stored with account controls in the extension's own local database (IndexedDB) and are excluded from organizer backups and Chrome Sync. Signing out or switching accounts clears displayed billing state and prevents late results from the previous account being used.
Subscription management returns to https://threadwell.app/?billing=return. Checkout returns to https://threadwell.app/?checkout=complete or https://threadwell.app/?checkout=canceled. Visiting them makes an ordinary website request; these return URLs contain no account token or checkout session ID. A redirect does not prove payment or grant Pro. Server checks verify payment and subscription ownership. After checkout or a portal change, the user can return to the Threadwell account page and choose Refresh subscription.
Pro requires active, paid, unexpired coverage and provider verification within the preceding 24 hours. Full refunds and unresolved or lost payment disputes can remove that coverage; the extension does not issue refunds itself. Losing verified Pro does not erase the organizer. The billing disclosures explain the current plans, cancellation behavior, and refund policy.
Accounts and workspaces
An organizer belongs to a Chrome profile and is associated with the first successfully loaded or explicitly renamed ChatGPT user/workspace. A catalog refresh from a different user or workspace is rejected rather than merged.
This does not create separate organizers automatically or hide the existing collection on logout or account switching. The old collection can remain visible after switching accounts, including when refresh fails. Use separate Chrome profiles for accounts or workspaces that need separate organizers. Normal ChatGPT access permissions still apply when opening each link.
Browser access and source content
The content script runs on https://chatgpt.com/* to display the sidebar, read catalog metadata through the signed-in session, recognize the current page, and open links. The manifest requests Chrome’s storage and alarms permissions. Alarms schedule local backups, paced device-sync checks, and configured account rechecks while Chrome runs; they do not themselves make ChatGPT catalog requests. Threadwell also permits requests to its configured Supabase project for the account service. The toolbar action shows or hides Threadwell. Valid imported chat.openai.com links are normalized to chatgpt.com; the sidebar does not run on the old host.
Threadwell hides the native ChatGPT sidebar and collapsed rail by default. Only its ChatGPT icon reveals the full native sidebar for the current tab; the compact rail remains hidden even during that temporary access. Collapsing Threadwell keeps native navigation hidden.
Saving or renaming a conversation name changes the source ChatGPT title after server acknowledgement. Folder and project renames, all local moves, and removal of organizer entries affect only local organization. The extension does not move, archive, or delete source chats or projects. Local placement beneath a project does not change that conversation’s ChatGPT project membership.
Backups, deletion, and retention
Manual backups
Manual JSON export and import require Pro access. JSON export creates a local backup of titles, links, folder structure, item colors, tags, favorite markers, saved filters, folder templates, preferences, catalog identity, source identifiers, and local override markers. A backup cannot grant Pro access. It includes no transcripts or session token. You decide where to keep or share that file.
JSON import merges data while preserving current display settings. Matching links preserve the existing item, including its color, tags, and favorite marker; imported folders get new identities and can be duplicated by repeat imports. New imported items retain valid preset color choices, tags, and favorite markers. Saved filters are merged without overwriting existing views. Older backups without colors remain accepted. A backup with a conflicting catalog user/workspace identity is rejected.
Local backup history
Scheduled backup history is opt-in and requires Pro access. It is kept in local extension IndexedDB, persists across browser restart and extension reload/update, and contains organization metadata and catalog identity, including saved filters and templates. It excludes display preferences, account credentials, and conversation transcripts. Retention is 5/10/20/50 snapshots with a 50 MiB budget; older snapshots are pruned. Unchanged scheduled snapshots are skipped. You can delete individual points. A safety snapshot precedes restore or application of an incoming sync arrangement; these safety points are local even if the schedule is off. Restoring replaces organization while preserving device settings and does not write conversation titles to ChatGPT.
Chrome Sync
Optional device sync sends titles, links, hierarchy, ordering, source metadata, colors, tags, Favorites, saved filters, templates, and the organizer's user/workspace identity through Chrome Sync. It excludes conversation bodies, tokens, cookies, local restore history, device settings, and request/rename coordination records. Changes are compressed and integrity-checked; compression is not encryption. Chrome controls account sync, delivery, and storage. Threadwell cannot establish that a write reached another computer or override Chrome's sync choices.
Device sync stores per-device updates and remembered deletions for conflict resolution. Turning sync off stops participation but does not erase cloud snapshots or other devices' local copies. Removing a current item does not immediately erase prior snapshots or deletion metadata. Uninstalling should not be treated as a guarantee of cloud erasure. Chrome's account and sync settings govern its cloud data. This release does not include a global cloud-reset button. Local sync metadata has a 3 MiB budget; Chrome's shared sync quota can be reached earlier. Quota, malformed data, and account mismatch errors preserve the current collection and are shown in sync status.
Removing saved data
Removing an item deletes it from the active organizer, but undo, local backup history, exports, or prior sync snapshots may retain its earlier state. If it is still present in the ChatGPT catalog, a later refresh can add it back. Threadwell does not automatically prune entries missing from a later source catalog. To remove extension-local active data and restore history, uninstall the extension; exported backups and Chrome Sync data are separate, and removing only a shortcut is not a way to erase its source data in ChatGPT.
A catalog refresh that changes the organizer clears earlier undo history. An unchanged refresh retains history. A confirmed or uncertain conversation rename clears prior Undo history; changing the title back requires another explicit rename. Chrome restart, extension disable, reload, or update also clears undo history. It is a best-effort convenience, not a substitute for a backup. Exported backups remain wherever you saved them until you delete them.
Chrome removes local extension storage when you uninstall Threadwell. Export first if you want to keep the organizer. Uninstalling Threadwell does not delete original ChatGPT chats or projects.
Chrome documents local and session storage lifecycles in its Storage API reference.
Optional sidebar diagnostic
A diagnostic is downloaded only when you click Save sidebar diagnostic. It contains extension build numbers, the last opening outcome, viewport dimensions, and bounded native-panel geometry and visibility flags. Chat text, titles, URLs, tokens, account details, and arbitrary DOM attributes are not included. The extension keeps the most recent failed-attempt report in tab memory until the next attempt or reload; it does not send or persist the report. You can choose to attach the downloaded file when requesting support.
Tags, Favorites, saved filters, templates, and bulk organization changes are local edits, optionally propagated through enabled Chrome Sync. They do not add catalog requests, rename ChatGPT conversations, or move conversations between ChatGPT projects. Automatic backup history stays on this computer and is not uploaded.
The Chrome alarms reference explains scheduling and browser restart behavior. Chrome Sync capacity and delivery are described in the Storage API reference.
Subscription events and background verification
Stripe sends signed checkout, subscription, invoice, refund, and dispute events to Threadwell's Supabase webhook endpoint. The service validates each signature and retrieves current provider records to determine access. To check paid coverage, it can read invoice, payment, refund, and dispute evidence in memory. Supabase stores a user/customer/subscription/price mapping, subscription status, paid-through and period end dates, verification dates, cancellation flag, request locks/cooldowns, and processed event identifiers. It does not persist the full event body, card data, or invoice line details in Threadwell's application tables. Provider operational logs remain subject to provider practices.
Background subscription verification runs on Threadwell's servers even when Chrome is closed. A five-minute timer checks for due work; it does not contact Stripe when nothing is due. An account normally becomes due six hours after its last successful provider verification. Webhooks or user-requested verification can defer redundant checks. Failed attempts use increasing delays. These checks read provider records and update Threadwell access; they do not create charges, refunds, or cancellations. Stripe handles recurring subscription charges separately.
The extension also has a fallback provider recheck when existing verification is at least twelve hours old, with a persisted one-hour attempt cooldown per account. This differs from the five-minute account-access checks against Supabase and the user-controlled ChatGPT catalog refresh schedule.
Per-account scheduling records include the user, checkout/attempt identifiers, last attempt and success times, next attempt, bounded outcome/failure counts, and temporary work locks. Aggregate run records contain timestamps, request identifiers, counts, and hashes of short-lived authentication tokens. The transient server request queue holds the token needed to dispatch a run; persisted run history stores only its hash.
Failed Stripe HTTP requests record only a fixed diagnostic code, a resource category (such as invoice), and the numeric HTTP status in server operational logs. These diagnostics exclude credentials, response bodies, user/customer identifiers, request paths, and portal links. Successful provider requests do not emit this diagnostic.
The portal receives the already-bound Stripe customer and explicit portal configuration from the server. No organizer content is shared with Stripe.
Billing record retention
Subscription and per-account scheduling rows are removed with the associated Supabase Auth account. Minimal processed-event identifiers remain until operator cleanup to prevent duplicate event handling; there is no automatic event-retention cleanup. While background subscription verification is enabled, the scheduler cleans up aggregate run records older than 30 days that are no longer referenced by an account's scheduling record. This is not a promise that all billing data, provider logs, or backups disappear after 30 days. There is no application-defined retention period for provider infrastructure logs/backups; those remain subject to provider settings and practices. Deleting Threadwell records does not cancel or erase the separate Stripe subscription.