Affiliate Threads

Privacy Policy

Affiliate Threads is a self-hosted plugin for Hermes Agent. It reads product candidates from a Google Sheet you own, drafts Threads posts with the AI model you have configured, and publishes them through Meta's official Threads API, using the AIffiliate app you registered. This page describes the data all of that involves, and where it goes.

Last updated

The short version

1.What this policy covers

This policy describes two things: AIffiliate, the Meta Threads app you register and authorize, and the Affiliate Threads plugin in this repository that publishes through it. It covers what the software does with data.

Affiliate Threads is self-hosted. You install it on a machine you control, connect accounts you own, and run it yourself. The maintainers operate no service for it, so there is no account to create and no data held on your behalf.

This policy does not cover Hermes Agent itself, Meta Threads, Google Sheets, Telegram, or the AI provider you configure. Each of those has its own privacy policy and terms.

2.What the plugin reads and writes

Everything below is either read from a service you connected or written to a store on your machine. There is no other data flow.

From Meta Threads

Through the official Graph API, with three permissions: threads_basic, threads_content_publish, and threads_manage_insights.

Access token
A long-lived token you generate during setup. It is valid for 60 days, can be renewed, and can be revoked at any moment.
Profile
Your Threads user id and username, read once from the profile endpoint so the plugin knows which account it publishes to. The id can be pinned in your credential store, or left to be resolved and cached automatically.
Posts
The text and any image you approve, sent to the API for publishing.
Results
The media id and permalink of each published post, kept so the plugin can write the post's URL back to your sheet.
Post insights
Engagement metrics of your own published posts — views, likes, replies, reposts, quotes, shares, and per-link click counts — read on a weekly schedule and appended to a Metrics tab in the same spreadsheet.

Replies, mentions, and follower lists are not requested and cannot be read. AIffiliate never asks for those permissions; the insights it reads cover only its own posts and account totals.

From Google Sheets

Read and written under your own Google authorization.

Candidate rows
Product names, descriptions, affiliate URLs, categories, and statuses, read from the sheet id you configure.
Your answers
The Used and Testimonial cells, which hold your own account of using a product. They are written when you answer the pipeline's question, and used exactly as you wrote them.
Results
The Threads URL written back to a row once its post is live.

From Telegram

Previews, questions, and your approve, hold, or cancel decisions pass through the Telegram bot you configured in Hermes. The messages are delivered by Telegram and stored on your device like any other chat.

On your machine

Publish ledger
Product ids, media ids, permalinks, timestamps, and publish mode for the last 200 published products. It exists so that a retry after a failure cannot post the same thread twice.
Audit trail
Up to 50 records of publish attempts, kept in plugin state and appended to your Hermes log file.
Settings
The sheet id, tab name, and limits you set, in your Hermes configuration file.

3.Where it is stored

All of it stays on the machine that runs Hermes.

Credentials
The Threads token and sheet id, in the Hermes credential store: ~/.hermes/.env, or the secret manager you configured instead.
Runtime records
The publish ledger and audit trail, under ~/.hermes/plugin-data/.
Logs
Audit lines under ~/.hermes/logs/.
Settings
In ~/.hermes/config.yaml.

This repository ships the names of the variables the plugin needs and never their values. No secret is stored in any file here, and the maintainers receive no copy of your data.

4.What it does not do

  • No analytics, telemetry, or usage reporting. The plugin contains no reporting component.
  • No cookies, no tracking, no advertising, and no profiling.
  • No reading of other people's Threads content. Replies, mentions, and followers are outside the permissions AIffiliate requests; the only insights it reads are the engagement numbers of its own posts.
  • No publishing without approval. Every publish passes Hermes' human approval gate first, and a row is marked done only after the Threads API confirms the post.
  • No invented first-hand claims. Your Used and Testimonial answers are stored and used as written, and the guardrails refuse experience claims your own words do not support.
  • No selling or sharing of your data with anyone.

5.The services you connect

You bring these accounts; the plugin passes each one only what it needs to do its part.

Meta Threads (privacy policy)
Receives the posts you approve, the API calls needed to publish them, and the token exchange made when you set up AIffiliate.
Google Sheets (privacy policy)
Receives reads and writes on your spreadsheet, made with your own Google authorization.
Telegram (privacy policy)
Delivers the messages between you and your bot, including previews and approvals.
Your AI provider
Receives the prompts the pipeline builds, which include product candidates from your sheet, research notes, and drafts. Which company receives them depends on the model you configured in Hermes.
Research and image tools
Anything you connected in Hermes for browsing, research, or image generation handles public pages and prompts the same way it would for any other task.

6.How long data is kept

  • The Threads token: 60 days at a time, renewable while it is valid, and revocable at any moment. Renewing resets the clock.
  • The publish ledger: the most recent 200 records; older ones are dropped as new ones arrive.
  • The audit trail: the most recent 50 publish attempts.
  • Sheet rows, settings, and logs: kept until you remove them. They are files on your machine, under your control.

Nothing is retained on infrastructure run by this project, because no such infrastructure exists.

7.Deleting your data

Because the data lives with you, deletion is something you do directly. Four steps cover all of it.

  1. Revoke access in Threads. Open your Threads account settings, go to Website permissions, and remove AIffiliate. Its token stops working immediately.
  2. Remove the credentials. Delete the Threads token and sheet id from the Hermes credential store (~/.hermes/.env, or the secret manager you configured).
  3. Delete the local records. Remove the plugin's directory under ~/.hermes/plugin-data/, plus any log lines you want gone under ~/.hermes/logs/.
  4. Clear the sheet. Edit or delete the rows in your spreadsheet; the sheet is the system's only state store, and it is yours.

There is no deletion request to file with the maintainers, because they hold no copy to delete.

8.Security

  • No secrets in the repository. The plugin declares the names of the variables it needs; Hermes prompts for the values, masks them during entry, and stores them itself.
  • Values reach the plugin as environment variables at process start, and child processes receive only the variables the plugin declares.
  • Three Meta permissions, nothing more. AIffiliate cannot read replies or followers, and the insights permission covers only its own posts' engagement numbers.
  • A publish is written to your sheet only after the Threads API confirms it, and the ledger stops a retry from posting twice.

No system is perfectly secure. Keep the machine that runs Hermes protected, and connect only the Threads account you intend the plugin to publish to.

9.Children

The plugin is a publishing tool for the person running it. It is not directed at children, and it does not knowingly process their data. Meta's own terms set the age required to hold a Threads account.

10.Changes to this policy

This page lives in the repository, next to the code it describes. When the software's data handling changes, the page changes with it in the same history, and the date at the top is updated.

11.Contact

Questions or corrections: open an issue at github.com/msyamsularif/affiliate-threads-generator/issues. For how each connected service handles data on its own side, use the links in section 5.