Privacy notice
This notice explains the information Tharros processes to provide the platform, why it is used, and the service providers involved.
Information you provide
Tharros processes account details such as your name and email address; organization, team, employee and scheduling information you enter; documents uploaded to the knowledge workspace; messages and prompts sent to AI features; feedback you submit; and information required to administer your subscription.
Employee portal data can include availability, assigned shifts, sick-call information, replacement responses, swap requests and time-off requests. Organizations are responsible for deciding what employee and business information they place in Tharros.
Information created by the service
The platform creates operational records needed to run the product, including organization memberships, document-processing state, AI conversation history, citations, token-usage records, schedules and schedule versions, notifications, audit events, job execution state, and security or diagnostic logs.
How information is used
Information is used to authenticate users, isolate organization data, provide the assistant and scheduling products, process documents, deliver notifications and email, operate subscriptions, measure plan usage, troubleshoot failures, secure the platform, and maintain an audit trail for important operational actions.
AI processing
Different AI providers are used for specific tasks. Anthropic is used for assistant generation, OpenAI is used for document embeddings, and DeepSeek is used for structured scheduling tasks. Only information required for the requested feature should be sent to the relevant provider. AI output can be incomplete or incorrect and should be reviewed before it is used for consequential business decisions.
Infrastructure and service providers
Tharros currently relies on Supabase for database, authentication and storage; Stripe for subscription billing; Resend for transactional email; Vercel for application hosting and performance analytics; Sentry when configured for error monitoring; and the AI providers described above. These providers process information under their own service terms and privacy commitments.
Payment-card details are handled by Stripe. Tharros does not need to store complete card numbers in its application database.
Isolation and security
Organization-scoped application data is protected with database Row-Level Security. Server-only administrative credentials are restricted to backend operations, and employee portal access is token-scoped. No online service can guarantee absolute security, and account owners should use strong credentials and restrict access to authorized people.
Retention and deletion
Tharros keeps information while it is needed to operate an account, satisfy legitimate operational and security needs, and maintain records required for billing or dispute handling. Product deletion controls may remove organization or account data where the platform supports that action. Some records can remain for a limited period in backups, logs, payment-provider records, or other systems that have their own retention schedules.
Your choices
Users can update profile and organization information through the product, manage subscription settings through billing controls, and use available deletion or membership controls. Requests concerning personal information can be sent to tharrosdev@gmail.com.
Changes to this notice
This notice may change as the product, providers, or legal requirements change. The date above identifies the current published version.