ThryveJoin the waitlist

Thryve Privacy Policy

Effective date: September 23, 2026

This Privacy Policy explains how AVA Technologies LLC ("we," "us," or "our") collects, uses, shares, and protects information when you use Thryve, including the website and web app at thryve.college, the Thryve desktop app for macOS, the Thryve iOS app, and related services (together, the "Service").

Thryve is designed for college students. You must be 18 or older to use it, and the Service is intended for users in the United States. Your use of the Service is also governed by our Terms of Service.

If you have questions about this policy, email us at privacy@thryve.college.

The short version

  • We don't sell your personal information, and we don't show ads.
  • We don't use third-party analytics, advertising, or tracking tools. The usage analytics we collect are our own and never include the content of your tasks, events, notes, or files.
  • Your content is private by default. Others see it only when you share it with them, invite them, or create a link to it.
  • Meeting recordings stay out of AI services. Recordings are transcribed and summarized on your Mac. No recording, transcript, or summary is ever sent to an AI provider.
  • Two features use cloud AI. Syllabus extraction and the daily planner use AI models hosted by Amazon Web Services. Section 5 lists exactly what is sent.
  • You can delete your account at any time from your Profile. Section 10 explains what is deleted and what remains.

1. Who we are

AVA Technologies LLC operates Thryve and is responsible for the personal information described in this policy.

Thryve is an independent product. We aren't affiliated with or endorsed by your college or university, Instructure (the maker of Canvas), Google, Microsoft, Apple, or Zoom.

2. Information we collect

2.1 Account information

When you create an account, we collect your email address and full name. Your password is sent directly to Amazon Cognito, the Amazon Web Services (AWS) service that handles sign-in. Thryve's own servers never receive or store it. We also record when you last signed in.

Thryve doesn't offer sign-in through Google, Apple, Microsoft, or other social accounts.

2.2 Profile, preferences, and settings

We store the settings you choose in the app, such as:

  • your time zone, plus any additional time zones you pin to the calendar's time zone switcher;
  • display preferences like theme, accent color, and spell check;
  • reminder and notification preferences;
  • your working hours and whether your schedule is visible to others;
  • daily planner preferences and notes you write for the planner (for example, when you usually wake up and wind down);
  • the name you give your "Unassigned" task group, and your progress on the getting-started checklist.

2.3 Content you create or upload

  • Tasks, projects, and today lists, including titles, notes, dates, priorities, and assignees
  • Events, including names, descriptions, dates and times, locations, recurrence, reminders, and time zones
  • Courses, semesters, and course items
  • Rich-text notes
  • Syllabus files you upload (PDF files up to 30 MB and Word .docx files up to 4 MB)
  • Daily agenda plans, and the ratings and feedback you give on them
  • Availability votes on event polls
  • Meeting documents: titles, notes, and, on Mac, recordings, transcripts, and summaries (see Section 6)

2.4 Health and wellness information you choose to enter

The water and sleep trackers are optional. If you set them up, we store:

  • Water: your daily goal, unit of measure, glass size, how many glasses you log each day (including a dated history), whether hydration reminders are on, and when you last logged water or were reminded.
  • Sleep: your nightly sleep goal, your usual bedtime and wake time, and, for each night you log, when you went to bed, when you woke up, and your own rating of how you slept.

You enter all of this yourself. These features don't use sensors, wearables, your microphone, or motion data. We never show this information to other users, never send it to an AI model, and never share it with third parties. Section 12 has more detail.

2.5 Information from services you connect

Connecting any of these services is optional.

Calendars (Google Calendar, Microsoft Outlook, Apple iCloud, and calendar feed URLs). When you connect a calendar, we import and store its events, including titles, descriptions, dates and times, locations, recurrence, time zones, online meeting links, the event's organizer, its attendees (their names, email addresses, and responses), and your own response. To keep your calendars in sync, we store the credentials you give us in encrypted form: sign-in tokens for Google and Microsoft, or your Apple ID and an app-specific password for iCloud. For a calendar feed, we store its URL and the events it contains.

Canvas. If you connect Canvas, you give us your school's Canvas address and a personal access token that you create in Canvas. We encrypt the token before storing it and never display it, log it, or place it in a web address. We use it only to read your courses and course materials. Thryve never changes anything in Canvas. You choose which courses to import and review every item before it's saved. We store:

  • your Canvas user ID and display name;
  • the courses and items you import, with their details and direct links back to Canvas (links to course files require you to sign in to Canvas to open them);
  • term and course information;
  • limited records of your imported items, kept only on our servers, so we can detect changes;
  • your import choices, such as a date before which you chose not to import coursework;
  • class meeting times from your syllabus, if you opt in to syllabus extraction (see Section 5).

We don't request or store grades, submissions, class rosters, messages, or activity data from Canvas. We don't use Canvas data for advertising, AI model training, or unrelated analytics. Once a week, we check your connected courses for changes and alert you in the app.

Zoom. If you connect Zoom, we store encrypted Zoom sign-in tokens and your Zoom account's email address, so you can see which account is connected.

2.6 Information about other people that you provide

Using Thryve often involves other people's information, such as:

  • email addresses of people you invite to events, share projects or tasks with, or assign tasks to;
  • your contacts' names and email addresses, and whether you've chosen to share your availability with each one;
  • email addresses you enter when sending someone a booking link (we use these only to send the email and don't store them);
  • attendees and organizers of events imported from your connected calendars;
  • the voices and words of anyone captured in a meeting recording.

You're responsible for having the right to share this information with us. Section 8 explains how we handle information about people who don't use Thryve.

2.7 Information from guests and visitors

Some parts of Thryve can be used without an account.

  • Invitations and polls. People who respond to an invitation or poll give us their name and email address, along with their responses and availability votes.
  • Booking links. People who book time through someone's "Meet with me" link give us their name and email address. We email them a six-digit code to confirm the address. We store the code only in scrambled (hashed) form. It expires after 10 minutes, and expired codes are deleted daily. If the confirmed email address belongs to an existing Thryve account, the booking is added to that account.
  • Checking a calendar as a guest. On an invitation page, a guest can connect their own Google, Microsoft, or iCloud calendar to see where they have conflicts. We fetch their busy times and event titles for up to 90 days and show them only to that guest. We don't store or log this information, and we never show it to the event's host or other invitees. The guest's calendar access is held only in their own browser while the page is open.

2.8 Usage and device information

We collect limited usage analytics ourselves. We don't use any third-party analytics service.

  • Actions in the app, such as creating a task, connecting a calendar, or running a search. These records contain IDs, counts, and status codes. They never contain titles, names, email addresses, file names, notes, or other content. For searches, we record a one-way hash of the search and the number of results, not the search text itself.
  • Device and app details sent with each request: platform, operating system and version, app version, browser and version (on the web), time zone, language setting, screen and window size, and whether the device was online.
  • A random device identifier, stored on your device, and a session identifier that resets after 30 minutes of inactivity. Neither is based on your hardware. The device identifier lets us connect activity from before you signed up (for example, on a booking or poll page) to your account afterward.
  • Sessions and screen time: when sessions start and end, and how many seconds you spend in each main section of the app, such as Tasks or Calendar. Time counts only while the app is visible and you've used it in the past 60 seconds. We record the section name, not the web address or anything shown on the screen.
  • Invite history: if you joined because someone shared something with you or you used their poll or booking link, which account invited you, through which feature, and when you signed up.
  • AI usage: for each cloud AI request, the model used, the size of the request and response, how long it took, and what it cost. These records never include the request or response itself.
  • Daily summaries of your usage, such as how many tasks are open, how much storage you use, and whether you were active that day.
  • File sizes of syllabi and recordings you upload.

2.9 Logs and security information

  • Our firewall logs each request it checks, including your IP address and request details, with sign-in credentials removed. These logs are kept for 30 days.
  • Our servers keep troubleshooting logs for 30 days. We design them to record codes and counts rather than content, but error logs can include account IDs, email addresses, and, when an iCloud sync fails, an identifier for the iCloud account.
  • We use IP addresses temporarily to limit request rates and prevent abuse.

2.10 What we don't collect

  • Precise location. Thryve never uses GPS or your device's location. The only location information is what you type into events and the time zones you choose.
  • Your device's contacts, photos, or files, other than files you choose to upload.
  • Advertising identifiers, device fingerprints, or tracking cookies.
  • Payment information. Thryve doesn't currently have any paid features.
  • Voiceprints. Thryve doesn't identify people by their voice.

3. How we use information

We use information to:

  • provide and operate the Service, including syncing your data across your devices and with services you connect;
  • send the emails you trigger, such as invitations, poll requests, event updates and cancellations, and booking links, and account emails such as verification codes;
  • run the AI features you use (Section 5) and personalize the daily planner using your preferences and feedback;
  • understand how the Service is used, fix problems, and improve features, using the usage information in Section 2.8;
  • keep the Service secure, prevent abuse and fraud, and enforce our Terms of Service;
  • comply with the law and respond to lawful requests.

We don't:

  • sell your personal information or share it for targeted advertising;
  • use your content for advertising;
  • use your content to train AI models;
  • use automated processing to make decisions that have legal or similarly significant effects on you.

4. How we share information

4.1 With people you choose

Your content is private by default. Others can see it only through the sharing features you use.

  • Projects and tasks. Project members and task assignees can see what you share with them. Assigning a task to an email address gives that person access to view the task. That access continues after you unassign them, until you remove them in the task's sharing settings.
  • Events. Invitees can see an event's name, time, location, and description. Invitees without a Thryve account receive an email link to the event, and anyone who has that link can open it. The event's location is shown on invitation and poll pages, so if the location is an online meeting link (such as a Zoom or Microsoft Teams link), anyone with the invitation link can see it.
  • Attendee lists from connected calendars. If you invite someone through Thryve to an event that came from a connected calendar, invitees who are signed in to Thryve can see that event's full attendee list (names, email addresses, and responses) and organizer, including people who don't use Thryve. People viewing the event through an emailed link without signing in can't see the attendee list or organizer.
  • Poll links. Anyone with an event's poll link can view the poll and add their availability.
  • Public task links. Anyone with a public task link can view that task without signing in. You can turn the link off at any time.
  • Availability. When finding a time to meet, contacts you specifically choose can see when you're busy or free, but not what your events are. If you set your schedule to private, your availability isn't shown to anyone.
  • "Meet with me" booking links. Anyone with one of your booking links can see your display name and either your free and busy times and working hours for a limited window (never event details) or only the specific times you choose to offer. We don't show your email address on booking pages. When you email a booking link to someone, the email shows your name, or your email address if you haven't set a name. If you use a group booking template that shares your calendar, that event's invitees, including guests without an account, can see your busy times and working hours until a time is scheduled. Switching a link off, deleting it, or making your schedule private stops the sharing.
  • Bookings. When someone books time with you, the booking appears on your calendar with their name and email address.

4.2 With service providers

We use service providers that process information for us, under our instructions:

  • Amazon Web Services (AWS) hosts the Service in the United States. AWS provides our servers, database, file storage, sign-in (Amazon Cognito, which also emails verification and password reset codes), email delivery (Amazon SES), encryption key management, logging, firewall, website hosting (AWS Amplify), and AI model hosting (Amazon Bedrock).
  • Cloudflare provides domain name (DNS) services for our websites. For a small number of our web addresses, it may also process request data, including IP addresses.

4.3 With services you connect

When you connect a service, information moves between Thryve and that service at your direction. Each service handles information under its own privacy policy.

  • Google, Microsoft, and Apple calendars. We read your events and write back events you create or change on those calendars. When you invite people to an event on a connected calendar, we add them as attendees with that provider, and the provider sends the invitation. This means the provider receives their email addresses. When you respond to an invitation, your response is sent to the provider and the event's organizer.
  • Full sync to another calendar (currently Apple iCloud). If you turn this on, we copy events from the Thryve calendars you select into calendars named "Thryve – …" in the account you choose. This includes events that came from other providers, so, for example, your Google Calendar events would be copied to Apple. Changes you make to those copies, including deleting them, sync back to Thryve and to each event's original calendar. Turning full sync off deletes the copies. If the other service can't be reached at that time, the copies may remain in your account, and you can delete them yourself.
  • Canvas. We send read-only requests to your school's Canvas site using your access token.
  • Zoom. When you add a Zoom link to an event, or someone books an online meeting through your booking link, we ask Zoom to create the meeting in your Zoom account. We send the meeting's title, start time, length, and your time zone. We never send attendees' names or email addresses to Zoom.
  • Calendar feeds. When you subscribe to a calendar feed URL, the site hosting it sees requests from our servers.

4.4 When you send information elsewhere

  • Emails to invitees. Invitation, update, and cancellation emails include the event's details, your display name, and a calendar file. Some email services, such as Gmail, read that file and may add the event to the recipient's calendar automatically. We don't include your email address in the calendar file.
  • "Add to Google Calendar." If you, or a guest viewing your event, choose this option, the event's title, times, recurrence, location, and description are sent to Google in the link. This happens even if you've never connected a Google account.
  • Links you open. In the desktop app, web links open in your default web browser.

4.5 Other sharing

  • Legal and safety reasons. We may disclose information if we believe in good faith that the law, a subpoena, or other legal process requires it, or that it's necessary to protect the rights, property, or safety of AVA Technologies LLC, our users, or others.
  • Business transfers. If AVA Technologies LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. The recipient will be required to honor this policy for information we collected under it.
  • With your permission. We may share information when you ask us to or agree to it.
  • De-identified or aggregated information that can't reasonably be linked to you.

5. AI features

Two features send information to AI models hosted in Amazon Bedrock, an AWS service, in the United States. Your information goes to AWS. We don't send it directly to the companies that make the models. We haven't turned on any Bedrock setting that logs or keeps your requests, and we don't use your content to train AI models.

FeatureWhat we sendModel maker
Syllabus extractionYour syllabus file (or the text of a Canvas syllabus, if you opt in), plus fixed instructionsAnthropic
Daily plannerTitles of your tasks and course items; titles, times, and locations of the day's events; your free and busy times; your planner preferences and notes; any instructions you add when requesting a plan; recent feedback on plans; your previous planOpenAI
Planner learningYour recent written feedback on plans, and notes previously learned from itOpenAI

We never include your name, email address, or account ID in these requests. We may change the models we use. If a change means a different company's model would process your information, we'll update this policy first.

Syllabus extraction. When you upload a syllabus, we send it to the AI model to find course details, assignments, due dates, and class meeting times. For large PDFs, we may remove embedded images, such as photos of course staff, before sending the file. The original you uploaded isn't changed. The results are a draft: nothing is added to your courses or calendar until you review and confirm it. We keep your original file until you delete it or your account, and we may process it again to provide course features. If you opt in to syllabus extraction for a Canvas course, we fetch the syllabus from Canvas, convert it to text, and send it to the same model. We don't store the Canvas syllabus itself, only the course details you confirm.

Daily planner. We store the plans the planner creates, including its notes about why it placed each item, along with your ratings and feedback.

Planner learning. From time to time, we use your written feedback to generate short notes about your scheduling habits. We store these notes, along with statistics about how often you complete planned work, and use them to personalize future plans. You can erase your planner preferences, notes, learned habits, and plan history at any time by resetting the planner.

Meeting information is never sent to cloud AI. See Section 6.

AI output can be incomplete or wrong, so review it before relying on it. Our Terms of Service explain your responsibilities.

6. Meeting recordings (Mac only)

Meeting recording is available only in the Thryve app for Mac. The web and iOS apps can't record.

Your acknowledgment. Before your first recording, or before you import a recording, you must acknowledge that Thryve doesn't notify other participants that you're recording, that getting their consent is your responsibility, and that recording laws vary. We store the date you acknowledged this.

What's captured. A recording captures your microphone and all audio playing on your Mac, not just the meeting app. Anything else playing while you record, such as another call, a video, or notification sounds that read out messages, is captured and transcribed too. This means people who aren't in your meeting can end up in a recording. You can mute your microphone during a recording, and muted audio is never written to the file. Thryve's own sounds are not captured.

Processing happens on your Mac. Transcripts are created on your Mac by Whisper, an open-source speech recognition model. Summaries are created on your Mac by either Gemma, an open model from Google that runs on your device, or Apple's built-in on-device model. No recording, transcript, or summary is sent to Google, Apple, or any other AI provider. Transcripts label speech as "You" or "Others" based on whether it came through your microphone or your Mac's audio, not by recognizing voices.

Model downloads. When you first need them, the app asks your permission to download the speech model (about 574 MB) and, if you want it, the summary model (about 2.4 GB) from Hugging Face, a public model hosting site. Nothing is downloaded without your approval. Hugging Face sees your IP address and basic technical details, as with any download, but no account, meeting, or personal information is sent. The models stay on your Mac after you sign out, because they contain no personal information.

What we store. After a recording finishes, the audio and transcript are uploaded to our storage so you can use them on your other devices. Notes and summaries are stored in our database. Recordings and transcripts are encrypted with an encryption key used only for meeting data. Meetings are private to you. There's no way to share them with other Thryve users.

Copies on your Mac. Recordings and transcripts also stay on your Mac so you can play them offline. You can remove a recording's audio from your Mac without deleting the meeting. The app also keeps a diagnostic log on your Mac to help troubleshoot recording problems. It doesn't contain meeting content and is never uploaded. Recordings, transcripts, and the diagnostic log are erased from your Mac when you sign out, switch accounts, or delete your account.

Uninstalling. Moving the app to the Trash doesn't delete recordings stored on your Mac. To remove everything first, use Profile › Uninstall › Prepare to uninstall, or sign out before uninstalling.

Suggested tasks. Summaries may suggest action items. Nothing is added to your tasks until you review and confirm it.

Permissions. Recording requires the macOS Microphone and Screen Recording permissions. macOS requires the Screen Recording permission for apps to capture system audio. Thryve uses it only for audio and doesn't record video of your screen. You can turn off either permission in System Settings. Without Screen Recording, Thryve records your microphone only.

How long we keep it. Recordings, transcripts, notes, and summaries are kept until you delete the recording, the meeting, or your account. Deleting a recording also stops any processing still running on it.

7. Cookies, local storage, and your devices

No cookies or trackers. Thryve doesn't use cookies for sign-in, analytics, or advertising, and doesn't load third-party scripts, pixels, or trackers.

Information stored on your device. To make Thryve fast and usable offline, we store some information on your device:

  • sign-in tokens, managed by the AWS Amplify sign-in library;
  • preferences, such as layout choices, saved filter views, and the order of your projects (which can include project names), and a list of your connected calendars' names (which are often email addresses);
  • the random device identifier described in Section 2.8;
  • in the web app, a temporary copy of your data that's cleared when you close the tab or sign out;
  • in the Mac and iOS apps, a full offline copy of your working data: tasks, events, projects, calendars, contacts, courses, today lists, meeting notes and summaries you've opened, your water and sleep information, and your name and email address.

The offline copy in the Mac and iOS apps is protected by your device's own security, such as FileVault on Mac or the built-in encryption on iPhone, rather than by separate encryption from Thryve. We recommend turning on disk encryption and using a device passcode. Your data is erased from the device when you sign out or switch accounts. A few device settings, such as your automatic update preference, stay on the device.

Files you save. If you open or download a syllabus you uploaded, a copy is saved on your device, either in a temporary folder or in your Downloads folder. Thryve can't delete these copies, so they're yours to manage.

Browser privacy signals. We don't track you across other websites or apps, and we don't sell your information or use it for targeted advertising. We treat Global Privacy Control and similar signals as a request to opt out of those activities, which we already don't do.

Notifications and sync. Reminders are local notifications from your browser or operating system. We don't use a push notification service. To keep your devices in sync, the app keeps a connection open to our servers that carries only a signal to check for updates, never your content.

Mac app updates. The Mac app checks for updates when it opens. The check sends only the app version, platform, and processor type, along with your IP address and basic technical details, as with any internet request. It includes no account or device identifier. By default, updates install automatically. You can turn this off in Profile › Preferences › Updates.

8. Information about people who don't use Thryve

  • Invitees. When you invite someone who doesn't have a Thryve account, we create a placeholder record with their email address so they can respond through an emailed link. If they later sign up with that address, the placeholder becomes their account, we send them a welcome email listing what they were added to, and we record who invited them and through which feature.
  • Attendees and organizers from connected calendars. This information is stored with the imported event. We don't create accounts for these people, don't email them, and don't use their information to build contact lists or for AI. It's replaced each time the calendar syncs and deleted along with the event.
  • People in recordings. See Section 6.
  • Guests and people who book time. See Section 2.7.

We never use information about people who don't use Thryve for marketing. If you don't use Thryve and have questions about information we may hold about you, email privacy@thryve.college. Some of it, such as your name on another person's calendar event, is part of that person's content, and we'll handle your request in line with applicable law and their rights.

9. How long we keep information

InformationHow long we keep it
Account and profile informationUntil you delete your account
Tasks, events, projects, courses, notes, and syllabus filesUntil you delete them or your account
Meeting recordings, transcripts, notes, and summariesUntil you delete the recording, the meeting, or your account
Water and sleep historyUntil you reset the tracker or delete your account
Planner preferences, plans, and learned notesUntil you reset the planner or delete your account
Work pushed to "tomorrow's plan"14 days after the day it was planned for
Credentials for connected servicesUntil you disconnect the service or delete your account (see below)
Canvas change alertsUntil 30 days after you read them, or until you delete your account
Booking links and the times you offer on themUntil you delete the link or your account
Booking verification codesUp to 10 minutes; expired codes are deleted daily
Usage events and session records18 months (de-identified sooner if you delete your account)
Daily usage summariesIndefinitely (de-identified if you delete your account)
Record of who invited youAs long as your account exists
Records used to sync deletions across devices (IDs and dates only)90 days
Server and firewall logs30 days
Database backupsUp to 7 days

When you disconnect a calendar account that is receiving full-sync copies, we keep its encrypted credentials for up to one hour while we remove the copies, and then delete them.

Disconnecting Canvas deletes your token and removes the courses, coursework, and class meeting events imported from Canvas. Items you created yourself in those courses are moved to a separate course so you don't lose them.

10. Deleting your account

You can delete your account at any time from your Profile. When you do, we delete:

  • your account and sign-in identity;
  • your tasks, events, projects, courses, notes, plans, trackers, contacts, and settings;
  • your syllabus files, meeting recordings, and transcripts;
  • the credentials for services you connected; and
  • if you use full sync, the "Thryve – …" calendars we created in your other calendar account.

Some information remains after you delete your account:

  • Backups and logs. Database backups remain for up to 7 days, and server and firewall logs for up to 30 days. In rare cases, such as when we retire a database system, we may keep an encrypted archive copy until we delete it.
  • De-identified usage data. We keep usage records for statistics, but we remove your account and device identifiers from them, give each of your daily summaries a separate random ID, and clear the values that could link those days together. We also remove your account ID from the records of people you invited.
  • A record that the account was deleted, so an old sign-in session can't recreate it.
  • Emails already sent, such as invitations delivered to other people.
  • Events on your other calendars. Events you created in Thryve on a connected Google, Microsoft, or Apple calendar stay on that calendar, because they're part of your account there. If we can't reach your other calendar account when you delete your Thryve account, full-sync "Thryve – …" calendars may also remain there. You can delete them yourself.
  • Copies on your devices. Offline copies are erased from each device the next time it connects to Thryve. A device that's never opened again keeps its last copy. Files you downloaded stay on your device.

11. Your choices and rights

In the app, you can:

  • view, edit, and delete your content;
  • disconnect calendars, Canvas, or Zoom at any time;
  • control sharing by making your schedule private, choosing which contacts can see your availability, and turning booking links and public task links on or off;
  • reset the planner, water tracker, or sleep tracker;
  • turn off automatic Mac updates and notifications, and revoke device permissions in your device settings.

By request, you can ask us to:

  • tell you what personal information we have about you and give you a copy;
  • correct inaccurate information;
  • delete your information;
  • opt you out of the sale of personal information, targeted advertising, or profiling that has legal or similarly significant effects (we don't do any of these).

Some states give residents these rights by law. We honor them for all users in the United States. To make a request, email privacy@thryve.college from the email address on your account. We may need to verify your identity before responding. We'll respond within a reasonable time, and within any deadline set by applicable law. Where state law allows, you can use an authorized agent, and we may ask for proof that the agent is authorized. We won't treat you differently for exercising your rights.

If we deny your request, you can appeal by replying to our decision and asking us to reconsider. If you disagree with the result of your appeal, you can contact your state's attorney general.

We don't share personal information with third parties for their own direct marketing.

12. Consumer health data

Some state laws, such as Washington's My Health My Data Act, protect certain health-related information. The water and sleep information you enter in Thryve (Section 2.4) may be covered by these laws. For this information:

  • We collect it only if you choose to set up the water or sleep tracker, and only what you enter.
  • We use it only to provide those trackers to you, including charts, trends, and the hydration reminders you turn on.
  • We share it with no one except AWS, which stores it for us as our service provider. We don't sell it, show it to other users, send it to AI models, or use it for advertising.
  • You control it. You can delete it at any time using "Reset tracker" (water) or "Reset tracking" (sleep), or by deleting your account, and you can make the requests described in Section 11.

13. Security

We protect information with safeguards that include:

  • encryption in transit (HTTPS) and at rest for our database and file storage;
  • additional encryption for credentials such as connected-service sign-in tokens and passwords, invitation links, and booking links, plus a dedicated encryption key for meeting recordings and transcripts;
  • access controls that keep each account's information separate;
  • rate limiting and a web application firewall;
  • private file storage that doesn't allow public access and never runs uploaded files.

No system is completely secure. If a security breach affects your personal information, we'll notify you and the appropriate authorities as required by law, including Massachusetts law.

You can help protect your account by using a strong, unique password, turning on disk encryption and a passcode on your devices, and signing out on shared devices. If you believe you've found a security vulnerability, please email privacy@thryve.college.

14. Students and schools

Thryve is a personal tool that you choose to use. We don't provide Thryve on behalf of your school, and information you give us is governed by this policy, not by your school's policies for education records. When you connect Canvas, you direct us to access your own Canvas account using a token you create, and you can revoke that token in Canvas at any time. Your school may have rules about personal access tokens or third-party tools, and you're responsible for following them.

15. Age requirement

You must be 18 or older to use Thryve. We don't knowingly collect personal information from anyone under 18. If we learn that someone under 18 has an account, we'll delete it. If you believe someone under 18 is using Thryve, please contact privacy@thryve.college.

16. Where we process information

Thryve is intended for users in the United States. We store and process information in the United States. If you use Thryve from outside the United States, your information will be transferred to and processed in the United States.

17. Changes to this policy

We may change this policy at any time. When we do, we'll post the updated policy and change the effective date at the top, and the changes take effect on that date. We may make changes without notifying you directly, except that we'll give you advance notice of material changes, by email or in the app, before they take effect. If we want to use personal information we've already collected in a way that's materially different from what this policy said when we collected it, we'll ask for your consent first. By continuing to use the Service after a change takes effect, you accept and agree to the updated policy.

18. Contact us

AVA Technologies LLC

privacy@thryve.college