Skip to content

Privacy Policy

Effective Date: July 22, 2026

ThriveOnDev Ltd (“ThriveOnDev”, “we”, “us”, or “our”), a private limited company registered in England and Wales under company number 14781768, with its registered office at 20-22 Wenlock Road, London, N1 7GU, United Kingdom, operates the website located at thriveondev.com, the ThriveOnDev mobile applications, and the ThriveOnDev agent orchestration platform (collectively, the “Service”).

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our website, communicate with us, or use the Service, and describes the rights you have in relation to your personal data.

1. Scope of This Policy; Controller and Processor Roles

ThriveOnDev Ltd is the data controller for personal data described in this policy — for example, data about website visitors, prospective customers, account holders, and people who correspond with us.

When an organization uses the ThriveOnDev platform, content that the organization and its users submit to or connect with the platform — such as source code, repository data, issue and project management content, and agent run logs (“Customer Content”) — is processed by us as a data processoron that organization's behalf and under its instructions. Processing of Customer Content is governed by our agreement with that organization, including any data processing agreement, rather than by this policy. If your data is contained in Customer Content, please direct privacy requests to the organization that administers your workspace; we will support that organization in responding as required by law.

2. Personal Data We Collect

2.1 Data You Provide to Us

  • Account information: When you register for an account, we collect your name, email address, organization details, and any other information you choose to provide in your profile.
  • Business contact information: When you book an introductory call, request a pilot, or otherwise contact us about the Service, we collect your name, business email address, company name, role, and the content of your inquiry. If you schedule a call, your booking details are also processed by our scheduling provider.
  • Communications: Information you provide when you contact us for support, submit feedback, or otherwise communicate with us, including the contents of those communications.

2.2 Data Collected Automatically

  • Usage data (with consent, website only): If you opt in to analytics on our website, we collect information about pages visited and calls-to-action clicked, together with approximate device and browser information. Analytics is disabled by default. See Section 6.
  • Service usage data: When you use the platform, we collect information about features used, actions taken, and the date and time of activity, as needed to operate, secure, and bill for the Service.
  • Device and log data: Information about the device and connection you use to access the Service, including device type, operating system, browser type, and IP address, recorded in infrastructure and security logs.
  • Error and diagnostic data: We use error monitoring (currently Sentry) to detect and diagnose failures. Error reports are configured to exclude personally identifiable information by default and do not include session replay.
  • Cookies and similar technologies: We use strictly necessary browser storage and, only with your consent, analytics cookies. See Section 6.

2.3 Data from Third Parties

If you sign in using a third-party authentication provider (e.g., Google, GitHub, Apple), we receive your name, email address, and profile picture from that provider, as authorized by your settings with that provider. If your organization connects the Service to third-party tools (e.g., Linear or a source code host), we receive the data those integrations are configured to share, which we process as described in Section 1.

3. How We Use Personal Data and Our Legal Bases

We use personal data for the following purposes. Where UK GDPR or EU GDPR applies, the legal basis for each purpose is indicated in parentheses.

  • Providing the Service: To create and manage your account, deliver features, and process your requests (performance of a contract).
  • Sales and onboarding: To respond to inquiries, schedule and conduct introductory calls, and scope pilot engagements (performance of a contract or steps prior to entering a contract; legitimate interests).
  • Improving the Service: To analyze usage patterns, diagnose technical issues, and develop new features (legitimate interests; consent, for optional website analytics).
  • Communications: To send you service-related notifications and respond to your inquiries (performance of a contract; legitimate interests), and, with your consent or as otherwise permitted by law, to send marketing communications (consent; legitimate interests). You can opt out of marketing at any time.
  • Safety and security: To detect, prevent, and address fraud, abuse, security incidents, and technical issues (legitimate interests; legal obligation).
  • Billing and administration: To invoice customers, maintain business records, and manage our relationship with customers (performance of a contract; legal obligation; legitimate interests).
  • Legal compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests, and to establish, exercise, or defend legal claims (legal obligation; legitimate interests).

Where we rely on legitimate interests, we balance those interests against your rights and freedoms and do not process your personal data where your interests override ours. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

4. How We Share Personal Data

We do not sell personal data, and we do not share personal data with third parties for their own advertising purposes. We share personal data only in the following circumstances:

  • Service providers (sub-processors): We use trusted third-party providers to operate the Service, limited to the following categories: cloud hosting and infrastructure; error monitoring and diagnostics; website analytics (EU-hosted, consent-based); email delivery and communications; scheduling; and payment and invoicing. These providers act on our documented instructions, are bound by contractual confidentiality and data protection obligations, and may use personal data only to provide services to us. The current list of sub-processors, including their locations and how to subscribe to change notifications, is published at thriveondev.com/legal/subprocessors.
  • AI providers you configure:The platform orchestrates coding agents using the AI provider subscriptions or accounts that your organization connects (e.g., Anthropic, OpenAI, GitHub, Google). Content routed to those providers is sent on your organization's instructions and is governed by your organization's own agreements with those providers. We do not grant AI providers any rights to personal data beyond what is needed to execute the runs you request.
  • Professional advisers: Lawyers, accountants, auditors, and insurers, where necessary and under duties of confidentiality.
  • Legal requirements: Where disclosure is required by law or in response to valid legal process, such as a court order or government request. Where legally permitted, we will notify the affected customer before disclosing Customer Content.
  • Protection of rights: Where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, to investigate fraud or abuse, or to enforce our agreements.
  • Business transfers: In connection with a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to confidentiality obligations. We will notify you of any change in ownership that materially affects how your personal data is processed.

We may also share aggregated or de-identified information that cannot reasonably be used to identify you.

5. International Data Transfers

Our primary Service infrastructure is hosted in the United Kingdom (London region). Your personal data may nevertheless be transferred to and processed in countries other than your country of residence — for example, where a sub-processor provides support from another location. Where we transfer personal data originating in the UK or the European Economic Area (EEA) to a country that has not been deemed to provide an adequate level of protection, we implement appropriate safeguards required by applicable law, such as the UK International Data Transfer Agreement or Addendum, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, and we assess the circumstances of the transfer as required. You may contact us for more information about the safeguards applicable to a specific transfer.

6. Cookies and Tracking Technologies

We use strictly necessary browser storage and, only with your consent, analytics technology to understand the effectiveness of this website. We use PostHogas our analytics platform, hosted in the European Union. On this website, analytics is disabled by default and starts only after you select “Allow analytics”. The types of storage we use include:

  • Strictly necessary storage: Used to remember your analytics preference and provide essential Service functionality. This cannot be disabled.
  • Analytics cookies (optional): Set by PostHog to help us understand page visits and calls-to-action so we can improve the website. We disable session recording, automatic interaction capture, and person profiles on this website.

You can change your choice at any time using “Cookie settings” in the website footer or through your browser settings. Declining optional analytics does not affect website functionality.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The criteria we use to determine retention periods include: the duration of our relationship with you or your organization; whether retention is required by law (for example, UK law requires certain financial and tax records to be kept for six years); and whether retention is advisable in light of our legal position (such as applicable limitation periods or ongoing disputes).

If you delete your account or your organization's agreement with us ends, we will delete or anonymize the associated personal data within a reasonable period, except where retention is required by law or necessary to resolve disputes or enforce our agreements. Residual copies may persist in encrypted backups for a limited period before being overwritten in the ordinary course.

8. Data Security

We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit, access controls based on the principle of least privilege, environment segregation, logging and monitoring, and periodic review of our security practices. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting your personal data, we will notify you and the relevant authorities where required by applicable law.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data, subject to certain exceptions.
  • Restriction: Request that we restrict the processing of your personal data in certain circumstances.
  • Data portability: Request a copy of personal data you provided to us in a structured, commonly used, and machine-readable format.
  • Objection: Object to processing based on our legitimate interests, and object at any time to processing for direct marketing purposes.
  • Withdraw consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at support@thriveondev.com. We may need to verify your identity before acting on a request. We will respond within one month, and we will inform you if we need to extend that period (by up to two further months) for complex or numerous requests, as permitted by applicable law. Exercising these rights is free of charge, except that we may charge a reasonable fee or decline to act on requests that are manifestly unfounded or excessive.

If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In the EEA, you may complain to the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. We would appreciate the chance to address your concerns first, so please consider contacting us before approaching a supervisory authority.

10. Automated Decision-Making

We do not use your personal data to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

11. Children's Privacy

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly. If you believe we may have collected data from a child, please contact us at support@thriveondev.com.

12. Additional Information for United States Residents

We do not “sell” personal information or “share” it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar US state privacy laws, and we do not use or disclose sensitive personal information for purposes requiring a right to limit under those laws. Depending on your state of residence, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to not receive discriminatory treatment for exercising those rights. You may exercise these rights, or appeal a decision we have made about a request, by contacting us at support@thriveondev.com.

13. Third-Party Links

The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policy of every website you visit.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. If we make material changes, we will notify you by posting the revised policy on the Service and updating the “Effective Date” above, and, where the changes materially affect registered users, by additional means such as email or an in-product notice before the changes take effect. We encourage you to review this policy periodically.

15. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, or wish to exercise your rights, please contact us at:

For details of the terms governing your use of the Service, see our Terms of Service.