Privacy Policy
This policy is for ThreadPool, a product of YourAmaryllis (youramaryllis.us). It covers the macOS, Windows, iPhone, and Android apps and any later clients that talk to the same service. It is the listing policy for Slack, GitHub, and Atlassian. It is not a substitute for counsel.
What ThreadPool is
ThreadPool clusters your work (messages, issues, pull requests, mail, and docs) into topics and can show prior decisions during meetings. It is not a recording archive and does not join calls as a bot.
Who we are
YourAmaryllis operates ThreadPool. Questions: support@youramaryllis.us or the contact page.
What we collect
ThreadPool is a work aggregator. To cluster topics we ingest work from services you connect. Topic summaries, statements, and OAuth tokens are encrypted on your devices before they are stored. We keep ciphertext and metadata for longer than 24 hours. That includes:
- Account: email via sign-in. We map that to an internal user id. Device public keys so sibling apps can unwrap a space key. A recovery backup is wrapped with a secret you save once. We cannot unwrap it.
- Connected services (you click Connect): OAuth tokens for Slack, GitHub, Jira, Google, and API credentials for Lightfield. Tokens are encrypted with your space key on the client. Ciphertext is stored on our servers, scoped to your account and space. Company Client Secrets never ship in an app, Keychain Settings fields, or logs. Vendor identity after Connect: Slack user id, GitHub login, Atlassian accountId, display name, and email when the vendor gives them to us.
- IMAP: host, username, and port metadata may be stored so the desktop can reconnect. The mailbox password stays in the OS keychain on that device. We do not upload it.
- Work graph: encrypted summaries of threads we ingest, plus metadata we need to cluster and retrieve: people maps, source links, which Slack workspace, GitHub repos, Jira site and projects, Google sources, and Lightfield objects you chose. We do not need your GitHub source code (PR description, comments, commit messages only) or Jira attachments.
- Meetings (opt-in): calendar title and attendees for pre-brief. Live capture is captions-first or on-device audio. We do not send meeting audio to our cloud. We do not add a participant bot to Zoom, Meet, or Teams. Companion cards on a phone are session metadata and cards, not the raw transcript.
- Bring-your-own AI: provider choice may be stored. The API key stays in the OS keychain. We do not upload it.
- Billing: if you subscribe, Stripe sees your payment method. We store Stripe customer and subscription ids, not card numbers.
- Waitlist: email and optional role/company if you submit the form.
We do not sell personal data. We do not use your work graph to train public models. We cannot read encrypted topics or tokens without a key that lives on your devices (or your recovery secret).
What we do not pull
- Every Slack channel you can read, only places you already spoke in.
- GitHub source code, diffs, or file contents.
- Jira attachment bytes, or every issue in a project you did not pick.
- Gmail attachments or Drive file bytes.
- IMAP passwords, BYO AI keys, or meeting audio.
Who else sees it
We use processors to run the product: Supabase (auth and encrypted database rows), Google Cloud (company-provided models when you have not brought a key), Stripe (payments), and the vendors you connect (Slack, GitHub, Atlassian, Google, Lightfield, IMAP hosts you name). Each sees only what that job needs.
If you use company-provided models for Ask or HUD judging, retrieved topic cards are sent to that model to produce an answer. If you bring your own AI key (Gemini, Claude, Groq, Grok, NVIDIA, OpenAI), that generate step runs with your contract. Embeddings for clustering use a consistent company model so topics stay comparable.
Because we keep Atlassian account identifiers, display names, and emails, we report those accountIds to Atlassian about once a week through their Personal Data Reporting API. If Atlassian says an account is closed or the profile changed, we erase or refresh our copy. We do not send your Slack or GitHub data in that report.
We disclose if required by law.
How long we keep it
Until you disconnect that integration, delete your account, or ask us to erase it. Disconnecting removes that vendor’s tokens and stops new pulls. A full account delete (Settings or email us) removes your ThreadPool rows (topics, people, credentials, devices, billing customer mapping). Stripe may retain invoices as required by tax law. Backups roll off on our host’s schedule. Email support@youramaryllis.us if the in-app controls are not enough.
Your choices
- Do not connect a vendor you do not want us to read.
- Pick specific GitHub repos and Jira projects.
- Use a separate space for Work vs Family so those graphs never mix.
- Bring your own AI key if you do not want company models to judge Ask.
- Disconnect or request deletion at any time.
- If you are in the EEA/UK or California: access, correction, deletion, export. We do not sell or share for cross-context ads. You may also complain to a supervisory authority.
Children
Not directed at children under 16.
Changes
We will post a new date on this page. Material changes to meeting capture, encryption, or subprocessors will be called out in the app.