Thrivr

Privacy Policy

Last updated: August 15, 2026

This Privacy Policy explains how Thrivr collects, uses, and protects your information across Thrivr Reset, Thrivr Compass, and other Thrivr products.

1. Information we collect

  • Account information: name, email, password (stored securely, not in plain text).
  • Assessment responses: your answers to our intake assessments, used to personalize your protocol.
  • Health-related information: self-reported wellness data (energy, sleep, stress, mood) submitted through daily check-ins, and — for Thrivr Compass — information a parent provides about their child’s patterns and behavior.
  • Purchase information: handled by our payment processor, Stripe. We do not store your full payment card details ourselves.
  • Usage data: basic analytics about how you use our products, to improve them.

2. How we use your information

  • To personalize your protocol and track your progress over time.
  • To process payments and manage your subscription.
  • To communicate with you about your account, your protocol, and (if you opt in) product updates.
  • To improve our products, using aggregated and de-identified data where possible.

3. A note on children’s information (Thrivr Compass)

Thrivr Compass is used by parents on behalf of their children. We do not knowingly collect information directly from children under 13 — all information about a child is provided by their parent or guardian. This information is used solely to personalize the child’s protocol and is not shared with third parties for advertising purposes. Parents can request access to, correction of, or deletion of their child’s information at any time by contacting us.

This section needs specific legal review to confirm full COPPA compliance — the structure above is a reasonable starting point, not a guarantee of compliance as written.

4. How we share information

We do not sell your personal information. We share information only with:

  • Service providers who help us operate (payment processing via Stripe, hosting/database, email delivery).
  • Law enforcement or regulators, only when legally required.
  • A successor entity, only in the event of a merger, acquisition, or sale of assets, with notice to you.

5. Data security

We use industry-standard security practices to protect your information, including encrypted storage and secure authentication. No system is perfectly secure, and we cannot guarantee absolute security.

6. Your rights

You can access, update, or delete your account information at any time through your account settings, or by contacting us directly. Depending on your location, you may have additional rights under applicable law (e.g., GDPR, CCPA) — contact us to exercise these.

7. Data retention

We retain your information for as long as your account is active, and for a reasonable period after account closure as needed for legal or business purposes.

8. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to you via email or in-product notice.

9. Contact

Questions about this Privacy Policy or your data: admin@thrivr.online