Privacy policy
Last reviewed 3 September 2026.
This describes what Readyweek stores, why, for how long, and how to have it removed. It describes the product as built, not as intended.
Who we are
Readyweek is a service operated by the independent operator identified through Readyweek support at readyweek.app. It is not affiliated with, sponsored by, or endorsed by Meta. Threads is a trademark of Meta Platforms, Inc.
What we store about you
- Your account. The verified email address and display name supplied by the identity provider when you sign in, and the identifier it uses for you. We never receive your password.
- Your sessions. A hash of the session token, its creation and expiry times. The token itself is only in the cookie in your browser.
- Your workspaces. Name, slug, analytics timezone, and who belongs to them.
- Your connected Threads accounts. The Threads user identifier, username, display name, the permissions granted, expiry and health information — and the access token itself, encrypted (see below).
- Your agents. Name, description, autonomy level, the capabilities granted, and an Argon2id hash of each key. Never the key.
- Your content and measurements. Posts synchronized from your connected account, the insight values Meta returned at each captured horizon, and any strategy labels you added.
- Images you upload for a post. One JPEG or PNG, its filename and technical metadata are kept in workspace-isolated temporary storage only long enough to review and publish it.
- Your activity history. A redacted record of each operation: what was attempted, the outcome, a reason code, and a correlation identifier. Post and reply text is not written to these records by default.
- If you requested the free Threads guide. The address, which resource it was for, when you consented, the wording you consented to, and the campaign parameters in the link you arrived through.
- Your subscription. Stripe customer, subscription, price and event identifiers, status and billing-period dates. Readyweek does not store your complete card number or card security code.
What we deliberately do not store
- No password, ever.
- No plaintext Threads access token, and no preview, prefix or suffix of one.
- No agent key, only a hash.
- No advertising identifier, no cross-site tracker, no third-party analytics, and no visitor tracking cookie. The only cookie Readyweek sets is your sign-in session.
- No IP address or browser fingerprint in the acquisition records.
Your Threads access token
The token Meta returns is encrypted before storage using a separate data key for each credential, protected by a managed key service and bound to your workspace and connection. It is decrypted in memory only immediately before a request to Meta. It is never returned by our API, never returned to an AI agent, never written to a log, and never displayed in the interface.
What we ask Meta for
| Permission | Purpose |
|---|---|
| threads_basic | Read the connected profile and its posts. |
| threads_keyword_search | Find public posts by a creator-approved keyword or topic. |
| threads_content_publish | Publish a root post that you approved. |
| threads_read_replies | Read replies and conversation context on your own posts. |
| threads_manage_replies | Publish a reply that you approved. |
| threads_manage_insights | Read the post insight fields Meta returns for your posts. |
How long we keep things
| Data | Retention |
|---|---|
| Sign-in session records | Deleted 7 days after the session expires or is revoked. |
| Sign-in and Threads authorization records | Deleted 24 hours after they expire. |
| Duplicate-request records | Deleted after 7 days. |
| Rate-limit counters | Deleted after 2 days. |
| Activity history | Deleted after 365 days. |
| Temporary post images | Deleted after publish, rejection or cancellation; otherwise within 24 hours of upload. |
| Threads access credential | Erased immediately when you disconnect the account. |
| Posts, snapshots and annotations | Kept while the workspace exists; removed when it is deleted. |
| Lead-capture email and consent record | Kept until you ask for removal or withdraw consent. |
| Billing account, subscription status and Stripe event identifiers | Kept while the workspace exists and as required for financial, dispute and legal records. |
Who else sees your data
Meta receives the requests we make on your behalf to your connected account. Stripe processes checkout, payment methods, invoices and subscription management. Our identity provider handles your sign-in. Our hosting, temporary object-storage and managed-key providers process the data needed to run the service. We do not sell data, we do not share it for advertising, and there is no third-party analytics service on this site.
Your choices
- Disconnect a Threads account at any time. The stored credential is erased as part of that.
- Revoke an agent at any time. It stops working on its next request.
- Delete a workspace or your whole account. See Delete your data.
- Unsubscribe from guide and launch emails, or ask us to remove your address, by writing to [email protected].
Changes
If this policy changes materially we will change the review date above and describe the change on the build log.