Threads · Threads Privacy Policy · View original document ↗

Third-Party User Data Collection

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Threads changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Threads recorded 6 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Threads Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision states that Threads collects data about users of third-party federated services who interact with Threads content, including their username, profile picture, the name and IP address of their third-party service, content they share with Threads users, and their interaction activity with Threads content. This collection occurs regardless of whether the third-party user has a Threads account.

This analysis describes what Threads's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that Threads collects personal data, including IP address-level metadata of third-party service infrastructure, from individuals who are not Threads users but who interact with Threads content via the fediverse. This data collection may engage privacy regulatory frameworks in jurisdictions where those third-party users are located, and may require evaluation regarding lawful basis and notice obligations under GDPR and similar frameworks.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, individuals who use third-party federated services and interact with Threads content (by following, liking, or replying) have their username, profile picture, third-party service name, server IP address, content, and interaction data collected by Threads, even though they have not created a Threads account. The agreement establishes this collection as a function of the interoperable protocol.

Cross-platform context

See how other platforms handle Third-Party User Data Collection and similar clauses.

Compare across platforms →

Monitoring

Threads has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect information about the Third Party Services and Third Party Users who interact with Threads. If you interact with Threads through a Third Party Service (such as by following Threads users, interacting with Threads content, or by allowing Threads users to search for you, follow you or interact with your content), we collect information about your third-party account and profile (such as your username, profile picture, and the name and IP address of the Third Party Service on which you are registered), your content (such as when you allow Threads users to follow, like, reshare, or have mentions in your posts), and your interactions (such as when you follow, like, reshare, or have mentions in Threads posts).

Excerpt from Threads's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR's requirements for a lawful basis for processing, transparency obligations, and the rights of data subjects who are not Threads account holders. The collection of IP address-level metadata from third-party service infrastructure may also engage ePrivacy Directive obligations. EU data protection authorities are the primary enforcement bodies. The CCPA is relevant for California-resident third-party users. The FTC has general consumer protection jurisdiction. (2) GOVERNANCE EXPOSURE: High. The collection of personal data from non-Threads users who interact with Threads content raises questions about whether adequate notice and lawful basis exist for that collection, particularly under GDPR, where the data subjects may not have been presented with Meta's privacy disclosures at the point of interaction. (3) JURISDICTION FLAGS: EU/EEA jurisdictions create heightened exposure given GDPR's application to data subjects located in the EU regardless of where the controller is established. California residents using third-party federated services have CCPA-based considerations. Third-party users in any jurisdiction may not be aware that their interaction with Threads content results in data collection by Meta. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations operating federated services that are integrated with Threads should be aware that their users' interaction data, including server IP addresses, is collected by Meta under this provision. This may be relevant to those organizations' own privacy disclosures and data processing records. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the collection of third-party user data is adequately disclosed in relevant privacy notices and whether a lawful basis for that collection is documented. Teams should also evaluate whether data subject rights mechanisms are accessible to third-party users who have not consented to Meta's terms, particularly in GDPR jurisdictions.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data privacy and consumer protection; the collection of personal data from non-Threads users who have not agreed to Meta's terms may be relevant to FTC oversight of data handling practices.
    File a complaint →

Provision details

Document information
Document
Threads Privacy Policy
Entity
Threads
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016489
Document ID
CA-D-00248
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
5065d46d8667e1d98abf7e86f251273372e3710e71c6ffcc927abf46fcc8817f
Analysis generated
July 9, 2026 14:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Threads
Document: Threads Privacy Policy
Record ID: CA-P-016489
Captured: 2026-07-09 14:43:12 UTC
SHA-256: 5065d46d8667e1d9…
URL: https://conductatlas.com/platform/threads/threads-privacy-policy/provision/CA-P-016489/third-party-user-data-collection/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Threads's Third-Party User Data Collection clause do?

This provision establishes that Threads collects personal data, including IP address-level metadata of third-party service infrastructure, from individuals who are not Threads users but who interact with Threads content via the fediverse. This data collection may engage privacy regulatory frameworks in jurisdictions where those third-party users are located, and may require evaluation regarding lawful basis and notice obligations under GDPR …

How does this clause affect you?

Under this provision, individuals who use third-party federated services and interact with Threads content (by following, liking, or replying) have their username, profile picture, third-party service name, server IP address, content, and interaction data collected by Threads, even though they have not created a Threads account. The agreement establishes this collection as a function of the interoperable protocol.

Is ConductAtlas affiliated with Threads?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Threads.