ThreadDeck

WEBSITE PRIVACY

Useful counts.
Encrypted visitor detail.

ThreadDeck's website uses first-party, cookieless analytics to understand traffic and improve the project without building advertising profiles.

What is stored

Page date and path, acquisition or referring domain, country code, broad browser, operating system and device categories, selected theme setting, and displayed light or dark theme are stored as aggregate counts. A private owner-only recent visitor list also stores the latest access time and path, an encrypted exact network address plus a partially masked prefix, first and latest acquisition source, language, viewport size, broad device details, theme settings, approximate session and visible activity totals, normalized campaign tags, and counts of demo, GitHub, and download interactions. Full referring URLs and other query parameters are not stored.

Unique visitors

The server processes the network address and browser user agent to create a secret-key, one-way identifier. A separate secret-key identifier combines the exact address with broad device, operating-system, and browser categories, allowing related recent records to be folded together. For new visits, the exact address is protected with authenticated AES-GCM encryption before database storage and is decrypted only after the owner signs in to the private dashboard. A masked prefix is retained as a fallback for older records. Full user-agent strings are not stored. Because networks and browsers change or may be shared, unique visitor counts and groups are estimates.

Live visitor estimate

While a public page remains visible, it sends a brief first-party activity signal every 15 seconds. The private owner dashboard counts pseudonymous identifiers active within the last 60 seconds and updates their latest access time and visible activity total. A new approximate session starts after 30 minutes without activity. The signed-in owner can see a decrypted exact network address for new records together with broad device settings; older records show only the prefix that was originally retained. The dashboard does not store a full browser signature or claim to identify a person.

Campaign and interaction measurement

When present, only normalized utm_source and utm_campaign labels are kept; unrelated query parameters are discarded. A referring domain or campaign source is retained in temporary session storage for up to 30 minutes so internal navigation does not erase the original source; full referring paths and queries are not retained there. The private dashboard reports first-touch acquisition sources by estimated unique visitor instead of counting every reload as a new source. The site also counts interactions with its web demo and outbound ThreadDeck GitHub or release links. It cannot determine whether someone stars the repository or completes a download after leaving the site.

Purpose and sharing

The information is used only to understand site usage and improve ThreadDeck. Exact network addresses are visible only in the authenticated owner dashboard. There is no advertising analytics provider and the data is not sold. OpenAI hosts the Site and processes the data as needed to operate it.

Controls

Do Not Track and Global Privacy Control are respected. You can also disable analytics for this browser below; the preference stays only on this device.

Analytics on this browser: On

Retention

Pseudonymous visitor identifiers and encrypted exact network addresses are deleted after 90 days. Aggregate traffic and device statistics are deleted after 400 days. The rest of the owner-only recent visitor details are also deleted after 90 days, and temporary live-presence records expire after five minutes.

Your choices

Depending on where you live, you may have rights to access, object to, or ask for deletion of personal data. Use the contact address below for a request.

ThreadDeck plugin

The Stream Deck plugin itself has no telemetry or analytics and does not send Codex conversation data to this website.