Legal

ThreadProof Privacy Policy

Last updated: September 1, 2026 · Version 2026-09-01

This policy explains what Pest Leads Pro LLC d/b/a ThreadProof ("ThreadProof," "we," "us") collects, why, and your choices. Short version: your screenshots and documents never leave your device; we collect only what we need to run accounts, take payments, send transactional email, and measure the Site.

1. The most important part: Your Content stays on your device

Images you import, redactions, case and Matter data, logos, templates, and the PDFs you generate are processed entirely in your browser and stored in your browser's local storage (IndexedDB) on your device. They are not uploaded to us. We cannot see, access, recover, or restore them. When you export a case backup, that file is created and saved on your device. If you choose to email a PDF to yourself or share a preview, you initiate that transmission.

Encrypted case sync (optional). If you turn on "Keep my cases on my account (encrypted)", each case is packed and encrypted in your browser with a key derived from a passphrase only you know, and the resulting ciphertext is stored in a private area of our storage. We store ciphertext, a random per-blob nonce, the salt, the size, and timestamps. We never receive your passphrase, your key, or any readable content, so we cannot read, decrypt, or recover your cases. If you lose the passphrase, the data is unrecoverable. Turning sync off deletes the stored blobs within 24 hours.

2. What we collect

2.1 Account data: email address, hashed password (managed by Supabase), account creation date, plan and subscription status, and your chosen preferences (for example, theme).

2.1b Encrypted case sync data (only if you turn it on): the ciphertext of each case, a random nonce, the key-derivation salt, the encrypted case name, sizes, and timestamps. All of it is unreadable to us.

2.1c Timestamp receipts: when you add a file, export a packet or sign a declaration, your browser sends us a SHA-256 fingerprint of that file and a one-word label (image, video, pdf, packet or signature). We sign the fingerprint together with the current UTC time and send the signed receipt straight back. We never receive the file itself, we cannot reconstruct it from a fingerprint, and we do not keep a copy of the receipt: it is stored with your case on your device. All we keep is a counter used to stop abuse.

2.2 Payment data: purchases are handled by Paddle.com Market Ltd, which acts as the Merchant of Record. Your card details are entered into Paddle's hosted checkout and never reach ThreadProof. Paddle is the controller of the payment data it collects, is shown on your card statement and invoice, and handles taxes, refunds and disputes. From Paddle we receive and store only a customer and subscription reference, your subscription status and dates, and the last four digits of the card. We never receive or store full card numbers or security codes. See Paddle's privacy notice at paddle.com/legal/privacy.

2.3 Draft and resume data: if you use "text me / email me / copy the link" on the start page, we store a random token, the time, the situation type you selected, campaign parameters from the link you clicked (utm and click identifiers), a device type hint, and a cryptographic hash (fingerprint) of your screenshot. The hash cannot be reversed into the image. We use this only to reconnect you to the draft stored on your own device.

2.4 Communications data: the emails we send you (type, time, delivery status) and, if you request a text, the phone number you entered and the delivery status of that one message. Support emails you send us.

2.5 Signing-record data: when you request or complete a two-party signature, we store the requester and signer names and email, the selected block, the SHA-256 fingerprints before and after signing, and created, expiry, signed and used times. We retain these records for 12 months and delete them sooner on a verified request. We never store or link the PDF.

2.6 Usage data: first-party, cookieless analytics events (for example, "page viewed," "export completed," "upgrade clicked") with the page path, a random per-session identifier, device type, coarse timing, and situation type. We do not collect IP addresses, precise location, or your name in analytics, and we do not use third-party analytics services.

2.6 Technical data: standard server logs kept by our hosting providers for security and debugging (which may include IP address and browser type) for a limited time.

2.7 Reminder data: if you opt into a case reminder or deadline reminder, the case name you entered and the reminder date.

3. What we do not collect

We do not collect your images or document contents, government identifiers, precise geolocation, or biometric identifiers. The Service does not perform facial recognition or extract biometric information from images; redaction is a pixel operation you control. We do not sell personal information and have not sold it in the past 12 months. We do not share personal information for cross-context behavioral advertising, except as described in Section 6 for advertising measurement when it is enabled.

4. Why we use data (and our legal bases where they apply)

To provide the Service and your account (contract performance); to process payments and prevent fraud (contract performance and legitimate interests); to send transactional messages (contract performance); to send reminders you requested (consent); to measure and improve the Site with cookieless analytics (legitimate interests); to comply with law and enforce our Terms (legal obligation and legitimate interests); to measure advertising when enabled (consent where required, otherwise legitimate interests).

5. Who we share data with (service providers)

Supabase (authentication, database, hosting, USA); Paddle.com Market Ltd (Merchant of Record and payment processing, United Kingdom and USA); Resend (transactional email, USA); Twilio (SMS, only if you request a text, USA); Cloudflare Turnstile (bot protection at signup and checkout, if enabled); Lovable/hosting infrastructure (application hosting). These providers process data only to provide their services to us. We may also disclose data to comply with law, protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice to you).

6. Cookies, local storage, and advertising measurement

6.1 Essential: an authentication cookie/token to keep you signed in; a theme preference; local storage for Your Content and drafts. These are required for the Service.

6.2 Analytics: our first-party analytics use a random per-session identifier stored in session storage, not a persistent cookie, and set no third-party cookies.

6.3 Advertising measurement (when enabled): if we run advertising, the Site may load the Meta Pixel and use Meta's Conversions API to report events such as page views, checkout starts, and purchases to Meta, including a hashed (irreversible) version of your email at purchase, Meta's fbp/fbc cookies, and campaign identifiers. This is used only to measure whether ads led to purchases and to reach people who visited our Site with our own ads. It never includes your images or case content. You can opt out of Meta's use of this data through Meta's ad settings, and you can block the Pixel with browser tools. Where consent is required by law, we will ask before loading it.

6.4 We honor Global Privacy Control signals for the advertising-measurement cookies described above.

NamePurposeType
sb-*-auth-tokenKeeps you signed inEssential
tp_themeLight or dark preferenceEssential
tp_sessionRandom per-session analytics id (session storage)Analytics
_fbp / _fbcMeta advertising measurement, only when enabledAdvertising

7. Retention

Account data: while your account exists and for up to 90 days after deletion for backups and fraud prevention. Payment event records: 7 years for tax and accounting. Draft and resume tokens: 60 days. Signature request records: 12 months, or sooner after a verified deletion request. Email logs: 12 months. Analytics events: 24 months, then aggregated or deleted. SMS delivery records: 12 months. Server logs: per our providers, typically 30 days.

8. Your choices and rights

8.1 Access, correction, deletion: view and update your email on the Account page; delete your account there at any time, which cancels any subscription and deletes your profile and login. Local data on your device is under your control and can be cleared from the builder or your browser.

8.2 Email and SMS: transactional messages are part of the Service. Reminder and optional emails include an unsubscribe link. Reply STOP to any text.

8.3 California residents: you have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; to opt out of sale or sharing (we do not sell, and sharing for advertising measurement can be opted out of as described in Section 6); to limit use of sensitive personal information (we do not collect it); and not to be discriminated against for exercising these rights. Submit requests to abe.mainlinesites@gmail.com; we will verify your identity through your account email. Authorized agents may submit requests with written permission.

8.4 Other US states (including Colorado, Connecticut, Virginia, Texas, Oregon, and others with comprehensive privacy laws): you have similar rights to access, correct, delete, obtain a copy, and opt out of targeted advertising or sale. Use abe.mainlinesites@gmail.com. If we deny a request you may appeal by replying to our decision.

8.5 EU, UK, and Switzerland: if you use the Service from these regions, you have rights under the GDPR and UK GDPR to access, rectify, erase, restrict, port, and object, and to withdraw consent. Our legal bases are listed in Section 4. Data is processed in the United States under standard contractual clauses or equivalent safeguards with our providers. You may lodge a complaint with your local supervisory authority. Pest Leads Pro LLC is the controller.

8.6 Illinois residents: we do not collect biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act.

9. Security

We use HTTPS everywhere, tokenized payments, row-level security on our database, signed webhooks, rate limiting, and least-privilege access. Because Your Content never leaves your device, the most important security step is on your side: keep your device and browser secure, export backups, and review every page before sharing a document. No system is perfectly secure; if we learn of a breach affecting your account data we will notify you as required by law.

10. Children

The Service is for adults. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, email abe.mainlinesites@gmail.com and we will delete it.

11. Do Not Track and Global Privacy Control

We do not track you across other websites. We honor Global Privacy Control for advertising-measurement cookies as described in Section 6.

12. Changes

We will post updates here with a new date and, for material changes, email account holders at least 14 days before they take effect.

13. Contact

Pest Leads Pro LLC d/b/a ThreadProof, 9155 Beloit Ave, Bridgeview, IL 60455, USA. 888-424-3720. abe.mainlinesites@gmail.com. Privacy requests: subject line "Privacy request." You can also use our privacy request form.

ThreadProof formats documents. It is not a law firm and does not provide legal advice. Requirements vary by court and jurisdiction; confirm them with the court or an attorney.