Overview
This policy applies to the Primsy mobile app, the Primsy API that the app talks to, and this website. It is operated by Primsy ("we", "us"). In short:
- You sign in with an email address. A one-time code is sent to it. We do not use passwords.
- You connect one Threads account. We read its profile, its recent posts, and the performance numbers Threads reports for them. We publish only the posts you schedule.
- Everything you see comes from your own account. We do not compare you to other users, build audiences, sell data, or show ads.
- You can delete your account and its data from inside the app. Deletion takes effect immediately, uploaded media files included.
What we collect
Account information
- Email address. Used to sign you in with a one-time code and, if you contact us, to reply. Your email is held by our sign-in provider, Clerk. Our own database stores only an opaque account identifier that Clerk assigns to you.
- Time zone. The IANA time zone your device reports, so that scheduled posts and the weekly recap go out at the local hour you chose.
- Notification preferences. Whether you want a push when a post is published and whether you want the weekly recap.
Data from your Threads account
When you connect Threads, and on every sync afterwards, our servers call the Threads API on your behalf and store:
- Profile. Your Threads user ID, username, and profile picture URL. These are refreshed on every sync.
- Recent posts. The text, timestamp, media type, and whether a link is attached, for your 25 most recent posts. Reposts are skipped, and the link URL itself is not stored.
- Per-post metrics. Views, likes, replies, reposts, and quotes for each of those posts. Each sync stores a new snapshot rather than overwriting the last one, which is how the app shows how a post performed over time. One adjustment is made before storing: replies you posted yourself as later parts of a chain are subtracted from that post's reply count, so the number reflects other people.
- Account metrics. Your follower count, and your daily profile views for the past 90 days.
- Audience demographics. The aggregate breakdown of your followers by country, city, age range, and gender, exactly as Threads reports it. This is summary data about your audience as a whole. It never identifies an individual follower, and we never collect data about your followers as people.
Syncs run on our servers roughly every six hours, hourly for posts published in the last 24 hours, and when you open the app (at most once every five minutes).
Content you create in Primsy
- Scheduled posts. The text of each post and of each reply in a chain, the time you chose, the status of the post, and, after publishing, the IDs Threads assigned to it. If publishing fails, the error message Threads returned is stored with the post.
- Media. One photo or video per post part, if you attach one. The file is uploaded from your device to our storage the moment you attach it, even if you never schedule the post, and it is served from a public URL with an unguessable random name, because Threads fetches media from a URL when it publishes. See Retention for how long we keep these files.
- Link clicks. When a scheduled post contains a URL, we replace it with a short Primsy link so the app can show you clicks. For each click we record the time and the country the request came from. We do not record the IP address, device, or identity of the person who clicked, and clicks from known crawlers and link-preview bots are not counted.
Device and diagnostic information
- Push notification token. If you allow notifications, the Expo push token for your device and whether it is iOS or Android, so our servers can notify you when a post publishes, fails, or your Threads connection needs attention. The "post published" notification quotes the first 60 characters of the post, so that text passes through Expo's push service.
- Crash and error reports. The production app sends crashes and errors to Sentry with your account identifier, the app version, device model and OS version, and the screen the error happened on. App sessions also send performance timing to Sentry. Sentry is configured not to collect personal information by default, and it does not record your screen or replay sessions. Nothing is sent from development builds.
- Feedback service. The app uses Mite for in-app feedback. Each time the app launches it registers with Mite using an anonymous identifier and a description of your device: the device name as set in your phone's settings (which is often your own name), model, manufacturer, OS version and build, memory, and CPU architecture. Once you are signed in it also sends your account identifier and the app version. If you use "Report an issue", the text you write is sent with the same details. Bug reports do not include screenshots or a record of the screens you visited.
- Job history. Our database keeps a record of each sync, publish, and recap attempt for your account, with its status and any error message.
- Server logs. Our API runs on Cloudflare Workers. Its logs can contain your account identifier, post identifiers, and the error message Threads returned when something fails. We use them to find and fix problems.
Subscription status
If you subscribe to Primsy Pro, the purchase is made through Apple or Google and managed by RevenueCat. RevenueCat sends our servers a notice for each subscription event, saying whether your subscription is active, the product you bought, and when it expires. We store that notice in full, along with your account identifier. We never see your card number or your Apple or Google account details.
Your Threads connection
Connecting Threads authorizes Primsy through Meta's OAuth flow. We ask for the following permissions, and here is what each one is for:
| Permission | Why we need it |
|---|---|
| threads_basic | Read your profile and your own posts. |
| threads_manage_insights | Read views, likes, replies, reposts, quotes, follower count, and audience demographics. |
| threads_content_publish | Publish the posts you schedule, at the time you chose. |
| threads_manage_replies | Publish the later parts of a multi-post chain as replies to the first part. |
| threads_read_replies | Requested alongside reply publishing. The app does not currently read replies, and we do not store any. |
Connecting runs through Clerk, which holds the short-lived token from the OAuth handshake as part of your sign-in identity. Our servers exchange it for the long-lived access token that the service actually uses, and store that token in an isolated per-account store on Cloudflare. It is never stored in our main database and never sent to your device. The app itself never talks to Threads; every request goes through our API. Long-lived tokens expire after 60 days. Our servers refresh yours automatically around day 45, retrying if that fails, and send you a push notification when a connection is about to expire or has expired so you can reconnect.
Your use of Threads is also governed by Meta's own terms and privacy policy. You can revoke Primsy's access at any time from your Threads account settings. If you do, syncs and scheduled publishing stop until you reconnect.
How we use your data
- To show you your insights. Best posting hour, per-post performance, follower growth, and audience breakdowns are computed from your own snapshots on our servers, using ordinary arithmetic. No machine learning models, and no data from other accounts, are involved.
- To publish what you scheduled. At the scheduled minute our servers create the post on Threads using your token and the text and media you provided.
- To notify you. Push notifications when a post publishes or fails, a weekly recap on Sunday evening in your time zone if you keep it on, and a warning when your Threads connection needs to be renewed. Failure alerts cannot be turned off, because a silently failed post is the one thing the app must never do.
- To run subscriptions. To unlock Pro features when RevenueCat tells us your subscription is active.
- To keep the app working. Crash reports, feedback, and server logs are used to find and fix bugs.
What we do not do
- We do not sell, rent, or share your data with anyone for their own purposes.
- We do not show ads or use advertising or tracking SDKs.
- We do not compare your account to other accounts, and there are no benchmarks, cohorts, or aggregate statistics built across users. Every number in the app comes from your account alone.
- We do not send your posts, metrics, or any other content to AI or language-model services.
- We do not collect your contacts, location, photos you did not attach to a post, or any data about your followers as individuals.
- We do not publish anything to Threads that you did not schedule yourself.
- We do not use cookies or analytics on this website.
Service providers
These are the companies that process data on our behalf. Each receives only what is needed for its job, and each is bound by its own privacy terms.
| Provider | Role | What it receives |
|---|---|---|
| Meta Platforms (Threads API) | Source of your insights and the destination for your posts | Your access token, the posts you publish, and API requests for your own data |
| Clerk | Sign-in and account identity | Your email address, one-time sign-in codes, and the Threads OAuth link |
| Cloudflare | Hosting for the API, background jobs, token storage, media storage, and logs | Everything the API processes, and uploaded media files |
| PlanetScale | Hosted Postgres database | Your account record, Threads data, scheduled posts, metrics, and preferences |
| Expo | Push notification delivery and over-the-air app updates | Your push token and the notification text, which can include the first 60 characters of a post |
| Sentry | Crash and error reporting | Error details, device and OS version, app version, and your account identifier |
| Mite | In-app feedback and bug reports | Device details including the device name, an anonymous identifier, your account identifier, app version, and any report text |
| RevenueCat | Subscription management | Your account identifier and purchase events from Apple or Google; we keep each event notice it sends us |
| Apple and Google | App distribution and payment processing | Handled under your Apple or Google account; we do not receive payment details |
We may also disclose data if the law requires it, or to protect the rights and safety of Primsy and its users. If Primsy is ever acquired, your data would transfer with it under this policy, and we would tell you first.
Data on your device
The app keeps very little on the phone itself:
- Your sign-in session token, in the device's secure keychain.
- Your time zone preference, in the secure keychain.
- Onboarding progress, in local app storage.
- An anonymous identifier for the feedback service, in local app storage.
Insights and posts are fetched from our API each time you use the app and are held in memory only. Photos and videos you attach are read from where you picked them and uploaded; the app does not keep its own copies. Logging out or deleting your account clears the in-memory data and the session token.
Retention
- Account, Threads data, posts, and metrics are kept for as long as your account exists. Metric snapshots are not automatically pruned, because the history is what the trends are built from.
- Threads access tokens are destroyed the moment you delete your account or disconnect the channel.
- Uploaded media files are stored under an unguessable random name and kept only as long as a post still needs them. Canceling a post deletes its files at once, unless a requeued copy of the same post still points at them. Deleting your account deletes every file your posts and replies referenced. Files that no scheduled post references, including ones you attached but never scheduled and ones belonging to posts that already published, are deleted by a daily sweep once they are 30 days old. If you want a file removed sooner, email us at support@getprimsy.com.
- Crash reports, feedback, and server logs are kept by Sentry, Mite, and Cloudflare for the retention periods those services apply.
- Subscription records are kept by RevenueCat and by Apple or Google according to their policies.
Disconnecting and deleting
Delete your account from Account → Delete account in the app. This runs immediately and cannot be undone. In order, it:
- forgets your push token;
- destroys your Threads access token on our servers;
- deletes your account record, which removes your Threads profile data, all scheduled and published post records, every metric snapshot, audience data, tracked links and their click records, notification preferences, and subscription notices;
- deletes every media file those post records referenced from our storage;
- deletes your identity, including your email address, at Clerk;
- signs you out on the device.
Posts already published on Threads stay on Threads, including any media Threads copied when it published them. If you prefer, email us and we will delete your account for you.
Disconnecting Threads without deleting your account is possible by revoking Primsy in your Threads settings. That stops syncing and publishing. Data already synced stays in your account until you delete it. Scheduled posts that come due while disconnected fail and you are notified; they are never published later without your say-so.
Logging out keeps your data and your schedule. Scheduled posts still publish while you are logged out.
Security
- All traffic between the app, our API, and our providers uses HTTPS.
- Every request for your data is authenticated with a short-lived session token issued by Clerk. The only unauthenticated routes are the public media URLs and short links described above, a health check, and the RevenueCat webhook, which is protected by a shared secret.
- Threads access tokens live in an isolated Cloudflare Durable Object per account, separate from the main database, and are never sent to the device.
- Media files are served from URLs that contain a random identifier. Anyone with the exact URL can open the file; that is what allows Threads to fetch it. Do not attach media you would not want to be public, since the post it belongs to is public too.
- Crash reporting is configured not to send personal information by default.
No system is perfectly secure. If you believe you have found a vulnerability, please email support@getprimsy.com.
Your rights
Wherever you live, you can access, correct, export, or delete your data, and object to or restrict how we use it. Deletion is built into the app. For anything else, email support@getprimsy.com from the address you signed up with and we will respond within 30 days. We will not treat you differently for exercising these rights.
If you are in the European Economic Area or the United Kingdom, we process your data to provide the service you asked for (performance of a contract), to keep the service working and secure (our legitimate interests), and for anything else with your consent, which you can withdraw at any time. You also have the right to lodge a complaint with your local data protection authority.
If you are in California, we do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding twelve months.
Where your data lives
Our database is hosted by PlanetScale in the United States (AWS us-east-1). The API, token storage, and media storage run on Cloudflare's global network. Our other providers operate primarily in the United States. If you use Primsy from elsewhere, your data is transferred to and processed in the United States under this policy and under the safeguards our providers offer, such as standard contractual clauses.
Children
Primsy is not directed to children under 13, and Threads itself requires users to be at least 13. We do not knowingly collect data from anyone under 13. If you believe a child has created an account, email us and we will delete it.
This website
This site is static. It sets no cookies, loads no analytics or third-party scripts, and stores nothing in your browser. Our hosting provider, Cloudflare, may keep standard server logs to serve and protect the site.
Changes to this policy
When the app changes what it collects, this page changes with it, and the effective date at the top is updated. For a material change we will also tell you in the app or by email before it takes effect.
Contact
Questions, requests, and complaints go to support@getprimsy.com. You can also use "Report an issue" inside the app.