Draft — prepared for review by counsel. Bracketed items require confirmation. Not yet final.

Privacy Policy

Last updated: July 27, 2026 (draft)

1. Who We Are & Whose Data This Covers

tethr is an HR platform operated by Triples Global LLC, a California limited liability company (“tethr”, “we”). This policy covers three groups of people: customers and workspace users (the companies that use tethr and the people they invite), people whose records a customer stores in its workspace, and job candidates who apply through a customer’s public careers pages.

Our role differs by data type. For the account you create with us and for site data, we are the data controller. For the HR records a customer stores in its workspace — person profiles, reviews, compensation, survey responses, candidate applications — the customer is the controller and tethr is a data processor acting on the customer’s instructions under our Data Processing Agreement. If you are an person or candidate with questions about data your employer (or prospective employer) keeps in tethr, that organization is the right first contact.

2. Information We Collect

Account data (we are controller): name, email address, and authentication data managed through our sign-in provider; workspace name and settings.

Workspace data (customer is controller): whatever the customer and its users put into the workspace. Depending on how a customer uses tethr this can include person identification and contact details, job title and department, employment dates and status, manager relationships, compensation and offer details, performance targets and review content, survey responses, recognition messages, uploaded documents, and — if a customer chooses to store it — sensitive information such as health-related records.

Candidate data: when someone applies through a customer’s public careers page, we process the application on that customer’s behalf — contact details, résumé/CV and its parsed contents, salary expectations, and interview feedback the customer records.

Technical data (we are controller): server logs (IP address, timestamps, requests) and security events, used to operate and protect the Service.

3. How We Use Information

  • to provide and operate the Service and its features;
  • to authenticate users and secure workspaces;
  • to send transactional email — workspace invitations, review and goal reminders, and notifications (we do not send marketing email to workspace people or candidates);
  • to power AI features at the customer’s request (Section 4);
  • to monitor, debug, and improve the Service using technical and aggregate data;
  • to comply with law and enforce our Terms.

We do not sell personal data, use it for third-party advertising, or use workspace data to train AI models.

4. AI Features

tethr includes an embedded AI assistant, résumé parsing, and document search built on text embeddings. When a user invokes these features, the relevant content is sent to our AI providers (Anthropic for language models, Voyage AI for embeddings) to generate the response.

When the assistant retrieves data from your workspace to answer a question, a server-side filter removes sensitive fields — compensation and salary figures, government identifiers, medical information, personal contact details and addresses, and credentials — before that content reaches an AI provider. Features where you supply the content directly work differently by necessity: parsing a résumé, drafting from a job description, summarising a document you uploaded, or reading a roster you paste in all send that text as you provided it, including any personal details in it. Our AI providers are engaged under terms that restrict use of the data to providing the service and do not permit training on it. AI usage is rate-limited and metered per workspace.

5. Cookies

We use only cookies that are necessary for the Service to work: authentication and session cookies from our sign-in provider. Interface preferences (like your theme) are stored locally in your browser. We do not use advertising cookies, cross-site trackers, or third-party analytics.

6. Sub-processors

We use the following providers to operate the Service. Each is bound by contractual terms protecting personal data, and the same list appears in our DPA, which also describes how we give notice of changes.

ProviderPurposeLocation
VercelApplication hosting, and the AI Gateway through which all assistant and parsing requests are routed to model providersUnited States
NeonPostgres database hosting (all workspace data)United States
ClerkAuthentication and user managementUnited States
CloudflareDocument and file storage (R2)United States
AnthropicAI model provider, reached via the Vercel AI Gateway (assistant, résumé parsing, roster import, document summaries, job drafting)United States
Voyage AIText embeddings for document searchUnited States
ResendTransactional email (invites, notifications)United States
UpstashRedis used for rate limiting and short-lived subscription-status caching (processes user identifiers and IP addresses)United States

7. Retention & Deletion

We keep personal data for as long as the relevant workspace is active. Customers can export their full workspace as a machine-readable archive and can permanently delete their workspace self-serve (Settings → Data); deletion removes all workspace records — people, reviews, surveys, recognition, recruiting data, and documents — immediately and irreversibly. Residual copies in encrypted backups are purged on a short rolling cycle. We may retain limited records where required by law or to resolve disputes.

Responses to surveys a customer marks as anonymous are stored without the respondent’s identity; a keyed one-way hash is used solely to prevent duplicate submissions.

8. Security

Measures we maintain include: encryption in transit (TLS) and at rest; strict logical tenant isolation, enforced on every database query; role-based access control within each workspace (Owner, HR, Manager, Person); server-side filtering of sensitive fields in assistant retrievals before AI processing; audit logging of administrative actions; rate limiting and per-workspace AI usage caps; and least-privilege handling of secrets. No system is perfectly secure; if a breach affects personal data we will notify affected customers and authorities as required by law.

9. Your Rights

Depending on where you live (for example under the GDPR, UK GDPR, or US state privacy laws such as the CCPA/CPRA), you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing, and to complain to a supervisory authority. We do not “sell” or “share” personal information as those terms are defined in the CCPA, and we do not use it for targeted advertising.

To exercise rights over account data, contact us directly. For workspace or candidate data, where we act as processor, please contact the organization that controls the workspace; we will assist that organization in responding, and will forward requests we receive directly.

10. International Transfers

The Service is hosted in the United States and our sub-processors process data there. Where personal data of individuals in the EEA, UK, or Switzerland is transferred to the US, we rely on appropriate safeguards — the European Commission’s Standard Contractual Clauses (and the UK Addendum), as incorporated in our DPA, and/or sub-processors’ participation in recognized transfer frameworks.

11. Children

The Service is a workplace tool and is not directed to children. We do not knowingly collect personal data from anyone under 16; if you believe a child has provided us personal data, contact us and we will delete it.

12. Changes to This Policy

We may update this policy from time to time. For material changes we will give notice through the Service or by email to workspace administrators before the changes take effect. The date at the top reflects the latest revision.

13. Contact

Privacy questions or rights requests: tethr@tethr.work or [postal address]. See also our Terms of Service and Data Processing Agreement.