1. Introduction & Scope
This Privacy Policy ("Policy") applies to ThryvLoop ("ThryvLoop," "we," "us," or "our"), available at https://thryvloop.com, and describes how we collect, use, store, share, and protect personal data when you use our website, web application, and related services (collectively, the "Service") — whether you access the Service from India or any other country.
This Service is offered to individuals and businesses globally, with particular attention to users and organisations in India. By using the Service, you confirm you have read this Policy in a language you understand and agree to its terms, subject to mandatory rights that apply in your jurisdiction and cannot be waived.
This Policy is designed to comply with, among others:
- India: Digital Personal Data Protection Act, 2023 ("DPDPA"); Information Technology Act, 2000; SPDI Rules, 2011; IT (Intermediary Guidelines) Rules, 2021; Consumer Protection Act, 2019 (where applicable);
- European Economic Area (EEA) & United Kingdom: General Data Protection Regulation (EU GDPR), UK GDPR, and ePrivacy rules where applicable;
- United States: California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) and other state privacy laws where applicable;
- Other countries: Local data protection, consumer, and electronic communications laws that apply to your use of the Service.
This Policy must be read with our Terms of Service. Product guidance is available in our Help Centre. If you do not agree with this Policy, do not access or use the Service.
2. Who Controls Your Data & Contacts
For personal data processed through the Service (except where a business customer acts as controller/fiduciary — see Section 15), ThryvLoop (productivity software operator, India) is:
- The Data Fiduciary under India's DPDPA;
- The data controller under the EU/UK GDPR (where GDPR applies to our processing);
- The business responsible for personal information under US state privacy laws (where applicable).
2.1 Registered details
- Legal / trade name: ThryvLoop
- Registered / business address: Bengaluru, Bengaluru, Karnataka 560038, India
- Website: https://thryvloop.com
- Privacy enquiries (all regions): privacy@thryvloop.com
- General support: support@thryvloop.com
2.2 Grievance Officer (India)
For users in India, we have appointed a Grievance Officer under applicable Indian law:
- Designation: Grievance Officer / Data Protection Contact
- Name: Grievance Officer
- Role: Data Protection & Grievance Officer
- Email: grievance@thryvloop.com
- Alternate: privacy@thryvloop.com
- Response timeline: Acknowledgement within 24 hours; resolution within 15 days (or sooner if required by law).
Indian users who are unsatisfied may escalate to the Data Protection Board of India (or successor authority under the DPDPA) where they have standing under applicable law.
2.3 International privacy requests
Users outside India should direct privacy requests, GDPR enquiries, and CCPA requests to privacy@thryvloop.com. We respond within timelines required by applicable law (e.g. 30 days under DPDPA/GDPR, 45 days under CCPA where applicable). We do not currently maintain a separate EU representative; if that changes, we will update this Policy.
3. Personal Data We Collect
"Personal data" (or "personal information") means information relating to an identified or identifiable individual. We may collect:
3.1 Data you provide
- Identity & account data: name, email address, profile photograph, authentication credentials, and sign-in method (email/password or Google via our auth provider).
- Preferences: theme, timer settings, soundscape configuration, notification choices, and in-app settings.
- Workspace content: tasks, descriptions, statuses, priorities, categories, due dates, completion records, and productivity notes.
- Calendar data: events created in ThryvLoop and events synced from connected accounts (Section 3.3).
- Communications: ThryvBot messages, support tickets, feedback, and business enquiries.
- Organisation data: company/workspace name, team membership, roles, and shared tasks for B2B features.
3.2 Data collected automatically
- Usage data: features used, focus-session duration, page interactions, and timestamps needed for analytics and Service delivery.
- Technical data: IP address, browser type, device/OS, language, time zone, and referral source.
- Log & diagnostic data: error logs, security events, and performance metrics.
- Cookies & local storage: see Section 13.
3.3 Third-party integration data
Only with your explicit consent through OAuth or similar flows:
- Google (optional): account email; Google Calendar events (title, times, meeting/Meet links, availability); Gmail hub data — for recent messages we store subject line, sender ("From"), read state, received time, and a link to open in Gmail (typically the 10 most recent items; stale items may be removed after ~14 days). We do not access Gmail message bodies;
- Clerk (authentication): when you sign in with Google or email, profile fields permitted by the provider; Clerk Organizations — org membership, roles, and invite metadata for team workspaces;
Disconnect integrations anytime via Settings → Integrations. OAuth tokens are stored encrypted on our servers. A short-lived cookie may be set during the Google connect flow. Prior synced data may remain until deleted by you or upon account closure.
3.4 Sensitive & special-category data
The Service is not designed to collect sensitive or special-category data (e.g. health, biometrics, racial/ethnic origin, religious beliefs, sexual orientation, government IDs, financial account numbers). Do not enter Aadhaar, PAN, SSN, passport numbers, bank details, medical records, or similar data into tasks, chat, or free-text fields. If you voluntarily submit such data despite this warning, you do so at your own risk; we may delete it without notice and process it only with safeguards to the extent we retain it.
3.5 What we do not collect knowingly
We do not knowingly collect personal data from children below the age required in your jurisdiction (see Section 14). We do not sell personal data or use it for cross-context behavioural advertising.
3.6 Application-specific product data
The following data is generated or stored when you use ThryvLoop features (in Supabase, browser local storage, or both):
- Focus sessions — start/end time, duration, timer mode (e.g. Pomodoro), stored for analytics;
- User preferences — theme, timer settings, soundscape mix, sidebar state, synced to your account where applicable;
- Soundscape state — active ambient layers, volumes, and saved recipes;
- In-app notifications — titles, bodies, and links shown in the Home bell (separate from Gmail sync);
- Calendar reminders — reminder offsets you set on ThryvLoop calendar events;
- Tasks — including optional assigned_users references to other users when you assign work;
- Analysis & insights — aggregated productivity metrics, streaks, charts, and AI-generated insight text;
- PDF export — when you export analytics, your report data is rendered on our servers (server-side PDF generation) and downloaded to your device; we do not retain the PDF file after delivery;
- ThryvBot — conversation history and message metadata stored per account.
3.7 Pre-account & marketing data
Before you create an account, you may submit your email address on our landing page (e.g. Company Hubs waitlist / "Notify me"). We store this in our waitlist database and may send operational emails via our email provider. Lawful basis: consent (by submitting the form) or legitimate interest in informing you about product launches, depending on your region.
3.8 Third-party individuals' data
When you sync Gmail or assign tasks, we may process personal data about other people (e.g. email senders in your inbox, calendar attendees, task assignees). You are responsible for ensuring you have a lawful basis to bring that data into ThryvLoop. We process it only to provide the Service to you.
3.9 Security & abuse-prevention data
We process IP addresses and request metadata for rate limiting, fraud prevention, and API security (e.g. on public forms and AI endpoints). This is retained briefly in server memory and logs as described in Section 9.
4. Purposes of Processing
We process personal data for lawful purposes connected with the Service, including:
- Registering and authenticating your account;
- Delivering focus mode, tasks, calendar, analytics, notifications, and team workspaces;
- Operating ThryvBot (AI assistant) and generating productivity insights;
- Syncing with third-party services you authorise;
- Improving, securing, and debugging the Service;
- Sending service-related communications (marketing only with consent where required);
- Complying with legal obligations, court orders, and lawful government requests;
- Establishing, exercising, or defending legal claims;
- Preventing fraud, abuse, and unauthorised access.
We process data only for purposes specified in this Policy or notified at collection. We do not use personal data for incompatible purposes without fresh notice and consent where required by law.
5. Legal Bases for Processing
Depending on your location and the type of processing, we rely on one or more of the following legal bases:
5.1 India (DPDPA)
- Consent — for optional features (integrations, marketing, non-essential cookies, notifications). Consent is free, specific, informed, and withdrawable;
- Legitimate uses — where permitted without consent under DPDPA (e.g. voluntary provision for a purpose, legal compliance, employment/safeguarding in enterprise contexts);
- Contract / service delivery — to provide the Service you request, alongside consent where DPDPA requires it.
5.2 EEA & United Kingdom (GDPR)
- Contract — processing necessary to perform our agreement with you;
- Consent — optional integrations, marketing, and non-essential cookies;
- Legitimate interests — securing and improving the Service, fraud prevention, and analytics, balanced against your rights;
- Legal obligation — compliance with applicable law.
5.3 United States & other regions
Where US state laws apply, we process personal information based on consent, contractual necessity, legitimate business purposes permitted by law, or other bases recognised locally. We do not sell or share personal information for cross-context behavioural advertising as defined under CCPA/CPRA.
6. Consent, Notice & Withdrawal
We provide clear notice of what we collect, why, how to exercise rights, grievance channels, and cross-border transfers before or at collection, as required by applicable law.
By creating an account, you consent to core processing described in this Policy where consent is the appropriate basis. Optional processing uses separate in-app toggles or OAuth authorisation.
To withdraw consent: disconnect integrations, adjust cookies, unsubscribe from marketing, or email privacy@thryvloop.com. Withdrawal may limit Service functionality. Where required (e.g. GDPR), withdrawal does not affect prior lawful processing.
8. Cross-Border Data Transfers
Personal data may be processed and stored outside your country, including in India, the United States, the European Union, and other locations where our processors operate. This is necessary to deliver a global cloud service.
8.1 Transfers from India
Under the DPDPA, transfers are permitted to countries not restricted by the Government of India, with safeguards as required. We will comply with notified restrictions.
8.2 Transfers from the EEA, UK & Switzerland
Where GDPR requires safeguards for transfers outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, adequacy decisions, or other lawful mechanisms. Contact privacy@thryvloop.com for details of safeguards applicable to your request.
8.3 Other international users
By using the Service where cross-border transfer is required and permitted, you acknowledge such transfer. We apply encryption, access controls, and processor agreements consistent with industry practice and applicable law.
9. Data Retention & Erasure
We retain personal data only as long as necessary for the purposes in this Policy or as required by applicable law:
- Active accounts — for the duration of use (paid plans, when introduced, follow the billing term disclosed at checkout);
- Waitlist emails — until you unsubscribe, the feature launches, or we delete the list after a reasonable period;
- Gmail hub notifications — rolling window; stale entries may be deleted after ~14 days;
- After account closure — up to 90 days for backup purge and dispute resolution, unless a longer period is legally required;
- Logs — typically 30–90 days, longer for security investigations;
- ThryvBot history — until you delete conversations or close your account;
- OAuth tokens — until disconnect or revocation.
Upon verified erasure request, we delete or anonymise data unless retention is legally required. Anonymised aggregated data may be retained for analytics.
10. Security
We implement reasonable technical and organisational measures (including under Indian SPDI Rules and GDPR Article 32 where applicable), including:
- TLS/HTTPS encryption in transit;
- Encrypted storage of OAuth tokens and workspace credentials;
- Role-based access and row-level security in databases;
- Authentication controls via Clerk;
- Least-privilege API scopes;
- Internal access limitations and logging.
No system is completely secure. Safeguard your credentials and devices. Notify support@thryvloop.com if you suspect unauthorised access. We are not liable for breaches caused by your negligence except where liability cannot be excluded under applicable law.
We notify affected users and regulators of personal data breaches as required by applicable law (e.g. DPDPA, GDPR within 72 hours to authorities where required).
11. Your Privacy Rights
Your rights depend on where you live. Below is a summary; mandatory local rights always apply even if not listed.
11.1 India (DPDPA — Data Principal rights)
- Access — summary of personal data and processing activities;
- Correction — rectify inaccurate or misleading data;
- Erasure — deletion when consent is withdrawn or data is no longer necessary;
- Grievance redressal — via our Grievance Officer (Section 2.2);
- Nominate — designate another person to exercise rights upon death or incapacity, as per DPDPA rules;
- Withdraw consent — for consent-based processing.
11.2 EEA & United Kingdom (GDPR)
- Access, rectification, erasure ("right to be forgotten"), and restriction of processing;
- Data portability — receive your data in a structured, machine-readable format where applicable;
- Object to processing based on legitimate interests or for direct marketing;
- Withdraw consent at any time;
- Lodge a complaint with your local supervisory authority (you may also contact us first).
11.3 United States (CCPA/CPRA & state laws)
- Know what personal information we collect, use, and disclose;
- Delete personal information subject to exceptions;
- Correct inaccurate personal information;
- Opt out of sale/sharing — we do not sell or share for cross-context behavioural advertising;
- Non-discrimination for exercising privacy rights.
11.4 Other international users
Users in Canada, Australia, Singapore, Brazil, and other jurisdictions may have additional rights under local law (access, correction, deletion, complaint to regulators). Contact privacy@thryvloop.com and we will honour requests to the extent legally required.
11.5 How to exercise your rights
Email privacy@thryvloop.com (or grievance@thryvloop.com for India grievances) from your registered email. We verify identity before acting. Response timelines follow applicable law (typically 30 days; 45 days for certain US requests). You may also edit data in-app, disconnect Google, delete ThryvBot threads, and delete your account via profile settings.
12. ThryvBot, AI & Automated Processing
ThryvBot uses artificial intelligence (including Google Gemini). Important limitations:
- Your prompts and relevant workspace summaries (tasks, calendar, focus time) may be sent to Google Gemini to generate responses, briefings, and analytics insights;
- ThryvBot may take actions in your workspace on your behalf when you ask — including creating or updating tasks and creating calendar events — using automated tool calls;
- Conversations are stored linked to your account;
- AI output may be wrong, incomplete, or biased — do not rely on it for legal, medical, financial, or compliance decisions;
- Do not submit passwords, OTPs, government IDs, payment data, or confidential employer information in chat;
- AI features are provided "as is" without warranty;
- We configure AI providers under terms that restrict use of your data to providing the Service, consistent with our provider agreements (we do not use your identifiable workspace content to train public models).
To the maximum extent permitted under applicable law, ThryvLoop is not liable for decisions based on AI-generated content. You remain responsible for verifying outputs.
Where GDPR applies, automated decision-making producing legal or similarly significant effects without human involvement is not used. AI assists productivity only.
14. Children's Personal Data
The Service is not directed at children. We do not knowingly collect children's personal data without appropriate parental or guardian consent:
- India (DPDPA): under 18 — verifiable parental consent required;
- United States (COPPA): under 13 — we do not knowingly collect data from children under 13;
- EEA/UK (GDPR): under 16 (or lower age set by member state, not below 13) — parental consent where required.
If you believe a child has provided personal data, contact privacy@thryvloop.com — we will delete it promptly unless legally required to retain it.
15. Businesses & Enterprise Customers
For companies, startups, and teams (in India and internationally) using ThryvLoop workspaces:
- Your organisation is typically the data controller / Data Fiduciary for employee/colleague data; ThryvLoop acts as a processor on your instructions;
- Clerk Organizations powers team workspaces — we sync organisation name, slug, member user IDs, and roles via webhooks;
- You represent lawful authority (contracts, notices, or consent) to upload colleague data and invite members;
- You are responsible for internal privacy notices, HR compliance, and lawful use of workspace features;
- Administrators may access workspace content per their role — configure roles carefully;
- Enterprise customers may execute our Data Processing Agreement or request a countersigned copy at privacy@thryvloop.com.
Indemnity: You indemnify ThryvLoop against claims from your unlawful processing of employee, contractor, or client data through the Service, except where caused by our breach of this Policy or applicable law.
16. Your Responsibilities
You agree to:
- Provide accurate information and keep credentials confidential;
- Use the Service lawfully under applicable local law (including data protection, copyright, and employment rules);
- Not upload unlawful, defamatory, obscene, harassing, or infringing content;
- Not attempt unauthorised access, scraping, reverse engineering, or disruption;
- Not transmit malware, spam, or phishing content;
- Ensure you have rights to data you sync from Google or other third parties.
Violation may result in suspension or termination, and reporting to authorities where required.
17. Third-Party Services & Links
The Service integrates with or embeds third parties, including Google (Calendar, Gmail, Meet, Gemini), YouTube (Focus Spaces ambient video — subject to YouTube Terms of Service), and Clerk. When you use these features, those providers may collect device, IP, and usage data under their policies. We do not control third-party practices.
ThryvLoop is not responsible for third-party acts, omissions, or outages, except to the extent we are liable as controller/fiduciary under applicable law for processors we engage.
18. Disclaimers & Limitation of Liability
To the fullest extent permitted by applicable law:
- The Service and this Policy are provided "as is" and "as available" without warranties of any kind, express or implied;
- We do not warrant uninterrupted, error-free, or completely secure operation;
- ThryvLoop's total aggregate liability for claims relating to personal data or this Policy is limited to the greater of (a) INR 10,000 / USD 120 (or local equivalent) or (b) fees you paid in the 12 months before the claim, except where liability cannot be limited (e.g. wilful misconduct, death/personal injury caused by negligence, or non-excludable statutory liability);
- We are not liable for indirect, incidental, special, consequential, or punitive damages, or loss of profits, goodwill, or business interruption, except where prohibited by law;
- Force majeure events relieve us from performance delays to the extent permitted.
Nothing limits rights that cannot be waived under DPDPA, GDPR, CCPA, or other mandatory law. Consumers in the EEA, UK, and certain US states retain non-waivable protections regardless of governing law below.
19. Changes to This Policy
We may update this Policy for legal, technical, or business changes. The "Last updated" date will change. Material changes will be notified via the Service, email, or prominent notice before they take effect where required by law.
Continued use after the effective date constitutes acceptance where permitted. If you disagree, discontinue use and request account deletion.
20. Governing Law & Disputes
This Policy is governed by the laws of the Republic of India, without regard to conflict-of-law rules, except that mandatory consumer and data protection laws of your country of residence apply where they cannot be contracted out.
Subject to mandatory local rights, courts at courts at Bengaluru, Karnataka, India have non-exclusive jurisdiction over disputes (Indian users may be subject to exclusive jurisdiction where permitted). EEA/UK consumers may also bring proceedings in their country of residence where EU/UK consumer rules allow.
Before litigation, parties shall attempt good-faith resolution via privacy@thryvloop.com or our Grievance Officer for 15 days.
21. Application Features Reference
This section maps ThryvLoop product areas to data practices for transparency:
- Home — dashboard aggregates tasks, calendar, focus stats, sync status, and in-app notifications;
- Focus mode — timer sessions logged; optional YouTube video backgrounds; soundscape audio preferences;
- Tasks — Kanban board data; optional assignees;
- Calendar — ThryvLoop-native events plus Google sync; optional browser reminders;
- Meet — opens embedded Google Meet for online events;
- Analysis — charts from focus/tasks data; AI insights; optional PDF export;
- ThryvBot — AI chat with tool access to your workspace (see Section 12);
- Settings — preferences, soundscape composer, Google connect/disconnect;
- Team workspaces (B2B) — shared org tasks and member management when enabled;
- Landing / waitlist — email capture before account creation (Section 3.7).
Paid plans: Pricing may be shown on our website. When payment processing is introduced, we will name the payment processor and update this Policy before collecting billing data. Until then, core features may be offered without payment. See our Billing & Refund Policy.
22. Contact Us
For privacy requests, grievances, or questions (all regions):
- Privacy / GDPR / CCPA: privacy@thryvloop.com
- Grievance Officer (India): Grievance Officer, Data Protection & Grievance Officer · grievance@thryvloop.com
- Customer Support: support@thryvloop.com
- Help Centre: https://thryvloop.com/help
ThryvLoop (productivity software operator, India) · Bengaluru, Bengaluru, Karnataka 560038, India
Your trust matters to us
This Privacy Policy describes how ThryvLoop handles personal data for users in India and worldwide, including rights under the DPDPA, GDPR, CCPA/CPRA, and other applicable laws. Read it together with our Terms of Service. This document is not legal advice.
These documents are provided for transparency. They are not legal advice. Have qualified counsel review them for your jurisdiction and business model before relying on them commercially.