MindThread manages your Threads accounts on your behalf. We understand the importance of account security. Here's how we protect your data and credentials.
Transport Encryption
All connections enforced with HTTPS/TLS encryption
Data in transit between browser and server is fully encrypted
Plain HTTP connections are not supported
Infrastructure
Database on Google Firebase Firestore (Google Cloud infrastructure)
Frontend deployed on Vercel (global CDN + DDoS protection)
Server-side code is not publicly accessible
Token Management
Threads Access Tokens stored in a protected server environment
Tokens auto-refresh every 60 days to ensure uninterrupted authorization
Tokens are immediately purged upon expiry or account removal
We never store your Threads password
Account Isolation
Each user can only access their own account data
All account APIs require authentication; there is no unauthenticated access
API responses never contain other users' tokens or keys
API Security
The official-API line (scheduling, auto-replies on your own posts, analytics) uses only Meta's official Threads Graph API
The official-API line uses no unofficial or undocumented Threads endpoints
All official API requests include valid OAuth 2.0 credentials
Access Control
Admin panel requires Firebase Authentication
Admin functions have independent isAdmin dual verification
Sensitive operation paths have input boundary validation to prevent path traversal attacks
Patrol (Taiwan customers only, optional, a separate line)
Browser patrol runs as an extension in your own browser, does not go through Meta's official API, and sits in a grey area of the platform terms; the account carries risk
Patrol is optional, off by default and can be turned off anytime; the official-API statements above do not cover browser patrol
We do not claim patrol has zero ban risk; see the patrol page (mindthread.tw/haixun) for the full disclosure
AI Auto-Reply Security
Auto-reply has 5 built-in security layers to prevent malicious comments from manipulating AI behavior (Prompt Injection attacks).
Prompt Injection Detection: Analyzes comments for instruction override, role switching, system probing, and sensitive data extraction patterns. Covers English, Chinese, and Unicode variants.
Input Sanitization: Removes control characters, truncates overly long inputs, ensuring raw comments enter the AI model in a safe format.
Gemini Built-in Safety Filters: Enables Google Gemini's native safety review, blocking harassment, hate speech, sexual content, and dangerous content (BLOCK_MEDIUM_AND_ABOVE).
Randomized Boundary Prompt Structure: Uses randomly generated boundary markers to isolate comments from instructions, preventing attackers from forging instruction boundaries.
Output Validation: AI replies are reviewed before sending: length limits, no links allowed, no system information leakage (API Keys, Tokens, system prompts).
Blocked comments are logged with reasons and synced to the dashboard without affecting normal account operations.
What we never do
Never store your Threads password
Never share your tokens with any third party
Never post without your authorization
Never collect personal information beyond Threads
Never sell any user data
Never use unofficial Meta APIs in the official-API line (patrol is separate, see above)
Report a Security Issue
If you discover any security concerns or vulnerabilities, please contact us directly. We will respond within 48 hours. contact@ultralab.tw