Legal
Privacy Policy
Last updated 28 July 2026
Most Thryve OS tools process files on your device. Accounts, purchases, optional cloud features, and Discover maker requests use limited data for the purposes described below.
Local-first processing
Most tools in the suite run in your browser using WebGPU and WebAssembly where needed. That includes local file editing, conversion, compression, signing, image tools, video and audio editing, QR codes, invoice generation, code formatting, metadata scrubbing, and local speech. For those tools, your documents, images, audio, and video are not transmitted to Thryve OS or another service. If a file leaves your device, you choose that path explicitly.
Optional cloud processing
The following cloud paths are opt-in. The relevant content is sent for that request and is not written to Thryve's D1 database or retained as Thryve product storage.
- Thryve Scribe: local transcription is the default and stays in your browser. If you choose cloud transcription, audio is sent to our Worker and passed to Cloudflare Workers AI Whisper in memory. It is not written to D1 or application logs. Cloud is never silent and is available only on entitled plans.
- Thryve Resume: creation, import, editing, ATS scoring, and export stay on your device. Pro AI features send the relevant resume and job text through Cloudflare AI Gateway to the configured model provider. Binary resume files are not kept as a permanent upload, and prompts and model output are not written to Thryve's database.
What we collect
- Account and session data: name, email, authentication records, a profile image you choose or a sign-in provider supplies, and a provider account identifier.
- Billing and entitlements: Dodo Payments is our Merchant of Record. We receive the customer reference and purchase, subscription, and entitlement status needed to provide access; we do not receive full card details.
- Workspace preferences: optional account-level settings, tool defaults, favourites, and recent-tool metadata. They do not include file contents or project documents.
- Usage metering: coarse quota and entitlement usage needed to enforce the plan you use, without file contents.
- Discover interactions: Discover may record an aggregate profile view, outbound website click, or source-code click for a published listing. These counters contain no account, cookie, file, referrer, URL, or visitor identifier.
- Maker requests: if you submit, claim, or correct a Discover listing, we store the contact and product information, public evidence and media URLs, and review history needed to assess that request. Do not submit private files through these forms.
- Discover operations: approved listing ownership, moderation status and audit events, evidence-based review checks, and campaign applications, payment state, placement windows, and daily aggregate campaign events needed to operate maker and staff workflows.
- Diagnostic reports: when browser error reporting is configured, it receives technical error information. Thryve removes request cookies and headers, strips URL query values, disables session replay, and does not intentionally send file contents.
How we use this information
We use account, session, billing, preference, and entitlement data to authenticate you, provide paid access, operate the workspace, prevent abuse, respond to support requests, and meet legal or accounting obligations. Maker-request data is used to review the request; it does not automatically publish or change a Discover profile.
Sponsored-placement reporting records daily aggregate impressions, sponsored profile clicks, and sponsored website clicks. Thryve respects Do Not Track and does not store visitor IDs, raw IP addresses, user agents, referrers, search terms, ad identifiers, geography, or device profiles for these reports.
Google Sign-In
Google Sign-In is optional. When you choose it, Google provides basic identity information such as your email address, name, profile image, and Google account identifier. We use that information only to create or authenticate your Thryve account, link it to an existing Thryve account with the same verified email, and restore purchases and account settings across devices.
We do not request access to your Gmail, Drive, Calendar, Contacts, or other Google content. We do not use Google account data for advertising, sell it, or share it with third parties for their own purposes.
What we do not collect as product data
- The files processed by local-only tools.
- Permanent copies of Scribe audio or Resume AI inputs and outputs in Thryve's database.
- Encryption passphrases or keys for on-device features.
- Local editor files, projects, or downloaded AI models from your browser storage.
Service providers
We rely on Cloudflare for the website, Worker, D1 database, Workers AI, and AI Gateway; Dodo Payments for checkout, billing, taxes, and payment records; Google when you choose Google Sign-In; and Sentry only when browser diagnostic reporting is configured. These providers process data only as needed to provide their respective services.
Retention, export, and deletion
Local editor files, projects, and downloaded models remain on your device until you clear them. Account preferences and entitlements are kept while your account is active. You can export the account data held by Thryve and delete your account from Workspace settings; local browser data must be cleared separately. Dodo retains payment records under its own legal and retention obligations.
Your privacy choices and rights
Thryve OS is designed to minimise personal data by architecture: the default for file tooling is processing on your device under your control. Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal data we hold about you, and to complain to the relevant supervisory authority.
You can use the in-product export and deletion controls for your Thryve account, or send a request to contact@thryveapps.in.
Thryve Redact and similar tools are assistive: they help you find and remove personal data, but they are not a guarantee of compliance. Always review output before sharing.
Changes
We'll post any changes to this policy here and update the date above.