Threading Privacy Policy

Last updated: September 13, 2026

About this policy

This policy covers Threading for Mac, the Threading iPhone app, the Threading service at remote.threading.codes, and Threading support. MJUKIS AB in Lund, Sweden, develops Threading and is responsible for the personal data described here. Company details are on our about page. Send privacy questions to support@mjukis.dev.

What stays on your devices

Your projects, agent sessions, conversations, terminal output, and provider sign-ins stay on your Mac. Threading has no analytics, usage tracking, or advertising, and it creates no identifier for your installation. We do not sell personal data.

When your iPhone connects to your Mac over Wi-Fi, a VPN, or Tailscale, the two talk to each other directly and we do not receive that traffic.

Requests the Mac app makes to other services

These are on by default, and you can turn each one off in Threading's settings. They go to the services named, not to us.

  • Update checks. Once a day Threading asks GitHub whether a new version is available, and checks npm and cursor.com for new versions of agent command-line tools. The requests carry the app version and, like any web request, your IP address.
  • Project icons. For a project whose Git remote is on GitHub, Threading looks up the repository owner on GitHub to show their avatar.
  • Account pictures. To show a picture for each agent account, Threading sends a hash of the account's email address to Gravatar and searches GitHub for the email address itself.

Some features contact a service only after you set them up: signing in to GitHub, adding an Anthropic or OpenAI API key, showing live usage for your Claude or Codex login, or installing an extension that asks for network access. Threading then sends the requests that feature needs to that service under your own account, and that service's privacy policy applies.

Problem reports

You can send us a report from Help › Report a Problem on the Mac, or from the iPhone app. Nothing is sent until you press Send. A report contains:

  • the description you write;
  • small screenshot previews, if included (up to four from the Mac, one from iPhone);
  • app and operating system versions;
  • a log of recent connection events, such as error codes and timings, with coded identifiers in place of names and addresses.

A report from the Mac also includes the app's state: which macOS permissions Threading has, how many projects, sessions, and accounts it has, whether recent launches crashed, and summaries of crashes and slowdowns. On iPhone you can choose to add device details such as the model, language, and available storage. If you shared diagnostics from your iPhone with your Mac, a report sent from the Mac can include those iPhone log entries.

Some identifiers in the log are derived from your Mac's identity. If you also use Threading Direct, we could therefore connect a report to that account.

Reports are stored in Cloudflare R2 and deleted automatically after 30 days. When a report arrives, Pushover sends us a notification with its reference number, type, time, and size, and nothing from its contents. The Mac app also keeps a copy of each report it sends in a folder on your Mac.

Threading Direct and notifications

Threading Direct is optional. It lets your paired iPhone reach your Mac from any network without a VPN, and it requires signing in with your Apple ID on the Mac.

When you sign in, Apple gives us an identifier for your Apple ID. We store a one-way hash of that identifier and an encrypted Apple token. We do not ask Apple for your name or email address. We also store your Mac's computer name (for example "David's MacBook Pro"), a random identifier for each Mac and paired device, and the credentials that let them connect.

To connect your iPhone and Mac, our service passes connection details between them, including their IP addresses. If they cannot connect directly, their traffic is relayed through Cloudflare's servers, encrypted between your devices. We do not store connection details or relayed traffic.

If you allow notifications in the iPhone app, it registers an Apple push token, which we store encrypted together with the device's random identifier. A notification from your Mac contains the chat's name and a short message, such as the name of a tool waiting for your approval. If you turn on response previews, which are off by default, it can also contain the start of the agent's reply. Our service passes that text to Apple's push notification service and does not store it.

How long we keep data

Threading Direct account data stays until you delete your account in Settings › Remote Access on the Mac, or remove Threading from the apps that use your Apple ID. Either way, the account, its Macs, paired devices, and push registrations are deleted. Device credentials and push registrations that expire or are revoked are deleted within 7 days.

Problem reports are deleted after 30 days. Our service keeps sampled operational logs, about one request in twenty, which contain coded identifiers and no conversation content. Cloudflare deletes them after a limited period.

Service providers

We use Cloudflare to run the Threading service, its database, report storage, and connection relays; Apple for Sign in with Apple and push notifications; Pushover for report alerts; and GitHub to host app downloads and update information. Cloudflare's network is global, so data can be processed outside the EU and EEA. Those transfers rely on Cloudflare's data processing terms, which include the EU Standard Contractual Clauses.

Your rights

We process problem reports to investigate and fix the problems you report, which is our legitimate interest, and Threading Direct data to provide the service you signed up for. You can ask to access, correct, or delete your personal data, or object to how we use it, by emailing support@mjukis.dev. The apps do not collect your name or email address, so tell us the report's reference number or which Mac the request is about. You can also complain to the Swedish Authority for Privacy Protection (IMY).

When you contact support

If you email us, we receive your email address and what you write, and use them to answer you. You can ask us to delete that correspondence.

This website

mjukis.dev is hosted on Firebase Hosting and uses TelemetryDeck for cookieless analytics of pageviews and link clicks. It stores your light or dark theme choice in your browser.

Changes

We will update this page and the date above when Threading's data practices change.

Back to Threading