Threadway

Privacy Policy

Effective 25 June 2026 · Version 2026-06-25

This Privacy Policy explains what data Threadway (the "Service"), operated by Abdulrahman Almaslamani, collects and how it is used. It applies to the hosted control panel. If you self-host Threadway, you are the operator of your own instance and responsible for its data.

1. Data we collect

  • Account data — your username, optional email address, optional display name, and a securely hashed (never plaintext) password. If you enable two-factor authentication or recovery options, related settings are stored.
  • Usage and connection metadata — IP addresses, timestamps, tunnel and subdomain names, byte and connection counts, and similar operational logs. We use these to run the Service, enforce plan limits, and detect and prevent abuse.
  • Captured request data — when you use the request catchers or out-of-band collectors, the Service records the requests sent to your endpoints (such as headers, bodies, and source addresses) so you can inspect them. This data is generated by the interactions you trigger in your own testing; you are responsible for what you cause to be captured.
  • Payment data — paid plans are processed by Stripe. Stripe handles your card details under its own privacy policy; we receive limited billing information (such as a customer and subscription identifier and subscription status) but not your full card number.
  • Cookies / local storage — the panel keeps your session token in your browser's storage to keep you signed in. We do not use third-party advertising trackers.

2. How we use data

To provide and maintain the Service; authenticate you and keep your account secure; enforce quotas and the Acceptable Use Policy; detect, investigate, and prevent abuse and security incidents; process payments; and send you essential account, security, and billing communications.

3. Data retention

We keep data only as long as needed for the purposes above. Operational records such as captured requests, connection events, and closed-tunnel history are retained for limited, configurable windows and then deleted or pruned automatically; audit records are kept longer for security and accountability. When you delete your account, we delete or anonymize associated data except where we must retain it for legal, security, or accounting reasons.

4. How we share data

We do not sell your personal data. We share data only with: our payment processor (Stripe) to handle subscriptions; infrastructure providers that host the Service; and, where we believe in good faith it is necessary, with law enforcement or other parties to comply with the law, enforce our terms, or protect the rights, safety, and security of users and the public.

5. Security

We use measures including password hashing, encryption of the control channel in transit, scoped access controls, and server hardening. No system is perfectly secure, and we cannot guarantee absolute security. Keep your credentials confidential and report suspected compromise to us.

6. Your choices and rights

You can view and update your profile, manage sessions and API keys, and delete your account from the panel. Depending on your jurisdiction, you may have rights to access, correct, export, or erase your personal data; to exercise them, contact us at support@threadway.cloud.

7. International data

The Service runs on servers that may be located outside your country. By using it, you understand your data may be processed in those locations under this policy.

8. Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect data from children.

9. Changes

We may update this policy; material changes will be shown by a new version and effective date here. Continued use after changes take effect constitutes acceptance.

10. Contact

Privacy questions: support@threadway.cloud. Abuse reports: abuse@threadway.cloud.

Terms of Service · Privacy Policy · Acceptable Use · Report abuse