Privacy Policy
Throughline ("Throughline," "we," "us") is operated by Morgan Foundry. This policy explains what we collect, why, and your choices. We built Throughline to be honest with you — that includes how we handle your data.
What we collect
- Account information: your email, name, and basic profile details from Google sign-in if you use it.
- Your career data: the résumé text, work history, skills, and STAR stories you add to your master profile.
- Roles you submit: the job descriptions and posting URLs you paste in for analysis.
- Pipeline data: the opportunities, stages, notes, and tasks you create.
- Usage data: basic logs (e.g., actions taken, errors) needed to operate and secure the service.
How we use it
We use your data to provide the service: to analyze fit between a role and your background, generate tailored application materials, and run your pipeline. We use limited usage data to operate, secure, and improve the product. We do not use your résumé, job descriptions, or pipeline data for advertising.
We do not sell your data, and we do not train AI models on it
We do not sell or rent your personal information. We do not use your content to train our own or third parties' AI models.
Third-party processors
We rely on a small number of service providers who process data on our behalf:
- Supabase — authentication, database, and hosting.
- OpenAI — to generate fit reads and tailored content, we send the text of the job descriptions you submit and the relevant parts of your profile to OpenAI's API. OpenAI processes this to return results and, under its API terms, does not use data submitted via the API to train its models.
- Google — only if you choose Google sign-in, to authenticate you.
These providers are bound to use the data only to provide their service to us.
Data retention and deletion
We keep your data while your account is active. You can delete your account at any time from your settings; deletion removes your associated data from our database. Backups and provider logs may persist for a limited period before cycling out.
Security
Access to your data is isolated per user at the database level, traffic is encrypted in transit, and AI provider keys are held server-side and never exposed to your browser. No system is perfectly secure, but we take reasonable measures to protect your information.
Your rights
Depending on where you live (e.g., the EU/UK under GDPR, California under CCPA/CPRA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. You can exercise these in-app or by contacting us at privacy@runthroughline.com. We will not discriminate against you for exercising these rights.
Cookies
We use only the cookies/tokens necessary to keep you signed in and operate the app. We do not use advertising or cross-site tracking cookies.
International users
We operate in the United States; if you use Throughline from elsewhere, your data may be processed in the U.S. and other countries where our providers operate.
Children
Throughline is not intended for anyone under 18, and we do not knowingly collect data from them.
Changes
We may update this policy; we'll revise the "Last updated" date and, for material changes, provide notice in-app.
Contact
Questions or requests: privacy@runthroughline.com.