Privacy Policy
This Privacy Policy explains how Jubel LLC (full legal name: Общество с ограниченной ответственностью "Джюбел", registered in Bishkek, Kyrgyz Republic, registration number 143045-3301-ООО; "Jubel", "we", "us") handles personal data in connection with the website jubeltrading.com and with the Lunchbox Threads application (the "App").
1. Who we are and how to contact us
The data controller is Jubel LLC. Legal address: Kyrgyz Republic, Bishkek, Oktyabrsky district, microdistrict 4, building 21, apt. 12.
Email for all privacy questions and requests: info@jubeltrading.com.
2. What the App is
Lunchbox Threads is an internal tool of the team behind Lunchbox Passport UAE, a guide to school lunchboxes for parents in the UAE. The App connects to the Threads API provided by Meta and helps the guide's author to:
- find public Threads posts about school lunchboxes and children's food;
- read replies in the conversations where the author takes part;
- publish replies from the author's own Threads account.
Every reply is written or approved by a person before it is published. The App sends no automated mass replies and no direct messages.
The App is not offered to the general public. Only Threads accounts invited by us (the author's account and accounts of team members) can authorize it.
3. What data we process
3.1. Accounts that authorize the App
Threads user ID, username and profile name; the access token issued by Threads; the account's own posts and replies, replies to them, and publishing quota information.
3.2. Public content found through the Threads API
For public posts returned by keyword search and for replies in the author's conversations: post ID, text, media type, permalink, timestamp, the author's username, and reply or quote flags.
3.3. Working records
When a team member marks a public post as relevant, we keep a working record: the link to the post, the author's username and public display name, a short excerpt of the post, its date, the public follower count and the city if the author states it publicly in the profile, the text and link of our reply, and the replies to our comment.
We do not collect phone numbers, email addresses or other contact details from profiles. We do not collect special categories of personal data and we do not build advertising profiles.
3.4. Website and web console
The public pages of this website have no forms, no user accounts, no analytics and no advertising cookies. The web console of the App at jubeltrading.com/app/ sets only strictly necessary cookies: a temporary one while you log in with Threads and a session cookie after you log in (up to 12 hours). Keyword search results in the console are shown on the screen and are not stored.
Our server keeps standard technical logs (IP address, time, requested page, browser type) for up to 30 days for security and troubleshooting. Login codes and search words are removed from these logs.
3.5. Email
If you write to us, we process your email address and the content of your message in order to reply.
4. Why we process data
- To let the guide's author take part in public conversations on the topic of the guide: our legitimate interest.
- To operate the features of an authorized Threads account: the authorization given by the account holder, which can be withdrawn at any time.
- To keep the service secure and to fix errors: our legitimate interest.
- To comply with legal obligations.
We do not sell personal data, do not use it for advertising targeting, and do not make automated decisions that produce legal or similarly significant effects.
5. Data received from Meta
We use data received through the Threads API only to provide the functions described in section 2 and in accordance with the Meta Platform Terms and Developer Policies. We do not transfer this data to data brokers or advertising networks, and we do not use it for surveillance, for decisions about eligibility, or for discrimination.
6. Where data is stored and who receives it
- A server located in Germany (European Union), rented from a hosting provider.
- A private Google Sheets spreadsheet (Google LLC) shared only with named team members.
- Internal notifications to team members in a private Telegram chat. They may contain excerpts of public posts.
- Meta Platforms receives the content of the replies that we publish through the Threads API.
- Email that you send us is handled by our email provider Titan (titan.email) and may be forwarded to a Gmail mailbox (Google LLC) of a team member.
Team members access the data from the countries where they work, currently the United Arab Emirates. We do not share personal data with anyone else, unless the law requires it.
7. How long we keep data
- Access tokens: until the account holder withdraws the authorization or we stop using the App. After that the token is deleted within 30 days.
- Keyword search results that were not marked as relevant: no longer than 30 days.
- Working records: while the project is active, but no longer than 24 months after the last activity on the record. They are deleted earlier on request.
- Server logs: up to 30 days.
- Email correspondence: up to 24 months.
8. Your rights
You can ask us to confirm whether we process your data, to give you a copy, to correct it, to delete it, to restrict its processing, or you can object to the processing. If the processing is based on your authorization, you can withdraw it at any time. You can also complain to the data protection authority of your country.
If you are the author of a public post and do not want it to be in our working records, write to us and give your Threads username. We will delete the records within 30 days and will not reply to your posts again.
Send requests to info@jubeltrading.com. We answer within 30 days. Step by step instructions are on the Data Deletion page.
9. Children
The App and this website are intended for adults. We do not knowingly collect personal data of children.
10. Security
Access tokens are stored on the server in a file that only the service account can read. The working spreadsheet is shared only with named team members. Administrative access to the server is restricted. The website and all API connections use HTTPS.
11. Changes to this policy
We may update this policy. The current version is always available on this page, and the date of the last update is shown at the top.