AdamSofi is a one-person web development service in Malaysia, operated by Muhammad Adam Mohamad Sofi. This policy covers the adamsofi.com website and the private internal tool described below that uses the Threads API. We comply with Malaysia's Personal Data Protection Act 2010 (PDPA).
A Bahasa Melayu and Chinese version of our general site policy is available at adamsofi.com/privasi.
1. The Threads Listening Dashboard
We operate a private, single-user internal tool that uses the Threads API to find public posts from people asking for the kind of work we do (for example, someone publicly asking for help building a website). The tool is not open to the public and has no user accounts — only the site owner can access it.
What Threads data we access
- Our own Threads profile ID and username, to identify the connected account.
- Public Threads posts returned by the API's keyword search: post ID, post text, author username, timestamp and permalink. We do not access private accounts, direct messages, follower lists, or any non-public content.
What we actually store
Post text and author usernames are processed in memory to display them to the operator and to score their relevance. They are not written to our database. For each post we have looked at, we keep only:
- a SHA-256 hash of the post text, so the same post is not shown twice;
- the public post ID, so a reply can be attached to the right post;
- a relevance score (0-100) and a short category label;
- whether we replied, and the link to our own reply.
A hash cannot be reversed back into the original post. We store no author names, no follower data, and no profile information about the people whose posts appear.
Replies
The tool can publish a reply to a public post through the Threads API. Every reply is written or edited by a human, reviewed on screen and explicitly confirmed before it is sent. There is no automatic replying, no scheduling and no bulk sending.
Scoring
To rank posts, the text of a public post is sent to our own backend service (HermesOS), hosted by us, which returns a score and a one-line reason. That service does not retain the text after scoring, and the text is not shared with any third-party advertising or data broker.
Access tokens
The Threads access token is exchanged and stored entirely on our server, encrypted at rest with AES-256-GCM. It is never sent to a browser, never placed in local storage, and never written to logs. Disconnecting the account deletes the stored token immediately.
2. Website data
- Contact form: name, WhatsApp number, email, business name and your project description.
- Newsletter: name (optional) and email address, only if you subscribe yourself.
- Ebook purchases: name, email, optional WhatsApp number and transaction records. Card and banking details are handled by our payment provider and never reach us.
- Technical data: IP address, browser type, pages visited and article view counts, for basic statistics and site security.
3. How we use data
- To reply to enquiries and prepare quotes or free drafts.
- To find and respond to public posts from people looking for our services.
- To send drafts, invoices, receipts and purchased files.
- To send newsletters, only to people who subscribed.
- To improve site content, performance and security, and to meet accounting and legal obligations.
We do not sell, rent or trade any data to third parties, and we do not use it for advertising or profiling.
4. Service providers
Data is shared only with the providers needed to run the service:
- Vercel — website and API hosting.
- Neon — Postgres database.
- Resend — transactional and newsletter email.
- Billplz — ebook payment processing.
- Meta Platforms — the Threads API itself, when we search or publish a reply.
- HermesOS — our own scoring backend, operated by us.
- Authorities — only where required by law.
5. How long we keep data
- Post hashes, post IDs and scores: up to 12 months, then deleted.
- Threads access token: until the account is disconnected or the token expires (60 days).
- Project enquiries: up to 24 months after the last discussion.
- Newsletter subscriptions: until you unsubscribe.
- Purchase records: up to 7 years, as required by Malaysian accounting rules.
6. Security
All traffic is served over HTTPS. Secrets live in server-side environment variables, the Threads token is encrypted at rest, the internal tool sits behind an authenticated session, and our own endpoints are rate-limited. No system is perfectly secure; if a breach affects personal data we will notify those affected.
7. Your rights
Under the PDPA 2010 you may ask us to:
- tell you what we hold about you;
- correct anything inaccurate;
- delete your data (see /data-deletion);
- stop processing your data, or unsubscribe at any time.
We respond within 14 working days.
8. Children
Our services are aimed at business owners and educators, not children under 13. We do not knowingly collect children's personal data.
9. Changes
Any update is published on this page with a new date at the top. Material changes are announced by email to subscribers.
10. Contact
- Email: muhammad.adamx96@gmail.com
- WhatsApp: +60 18-239 9476
Operator: AdamSofi, Malaysia.