Legal

Privacy Policy

This policy explains what Truen collects from students, candidates, employers, GitHub, optional AI-tool signals, and generated analysis — and how that data is used, shared, retained, and deleted.

Last updated: July 12, 2026

These pages describe how Truen currently works. They are product disclosures, not legal advice. Have qualified counsel review them before a public launch or paid commercial release.

Who this covers

  • Students and candidates who create accounts, connect GitHub, optionally share AI-tool signals, browse jobs or directories, apply, or submit their profile to a listed employer.
  • Employers using Jobs, Directories, candidate sourcing, qualification briefs, and share links.
  • Recipients of directory candidate share links who view a read-only Truen Profile without creating an account.

Account and employer data

  • We collect account data such as name, email address, password credentials handled by Supabase Auth, role, and session information.
  • For employers, we collect company name, optional website, optional directory listing, job titles, job descriptions, qualifications, location, remote status, and employment type.
  • Open job information and employer company names may be visible to authenticated users so candidates can browse and apply. Employers who publish a directory listing may be visible to candidates who choose to submit a profile.

GitHub connection and repository metadata

  • When a student connects GitHub through the Truen GitHub App, Truen stores GitHub identity data such as user id, username, display name, avatar URL, installation id, and connected timestamp. GitHub access tokens are encrypted at rest on our servers.
  • For repositories authorized through the GitHub App, Truen syncs repo names, descriptions, languages, public/private status, pushed dates, topics, fork signals, issue counts, contributor counts, and related metadata.
  • Students choose which authorized repositories Truen may analyze. Unselected repositories are removed from Truen’s working set for that student.

Transient raw GitHub evidence (deleted after profile generation)

  • To generate or regenerate a Truen Profile, Truen temporarily ingests bounded raw evidence from selected repositories. That working set may include commit messages and author metadata, pull request titles and bodies, issue titles and bodies, discussion comments, selected file paths, selected code file contents, selected markdown documentation, and related samples needed for analysis.
  • Truen does not clone or mirror full repositories. Ingestion is bounded and used as a temporary working set for analysis.
  • After every settled profile generation run — success, skip (unchanged evidence), or failure after retries are exhausted — Truen deletes that raw ingested content from its databases. Raw commit, pull request, file, issue, and comment rows are not kept as a lasting archive.
  • What remains after purge: repository metadata and summary signals (such as counts, ownership, tree summaries, and CI status), cached derived repo insights used to regenerate efficiently, and the generated Truen Profile itself — including the evidence references and code or commit snippets embedded in that profile.
  • If a student regenerates a profile, Truen re-fetches raw evidence from GitHub for the generation run, then deletes it again when the run settles. A broken or revoked GitHub connection can prevent regeneration because there is no retained raw fallback after a prior purge.

Generated profile and application data

  • Truen stores generated repo insights, Truen Profile JSON, evidence references, selected code snippets and commit-message samples that support claims, weaknesses, flags, limitations, interview questions, and qualification fit assessments.
  • When a student applies to a job, Truen stores a frozen profile snapshot for that application, along with job and company context, applicant name where available, GitHub username where available, profile version, application timestamp, and employer review statuses such as reviewed, shortlisted, or rejected. Those statuses are employer-managed and are not automated Truen hiring decisions.
  • A later profile regeneration does not automatically rewrite an already-submitted application snapshot.

Recruiter submissions, public GitHub reports, and share links

  • If a candidate submits their profile to a listed recruiter, Truen stores a frozen profile snapshot with that recruiter, separate from job applications.
  • Recruiters may create qualification briefs and generate AI-assisted fit assessments against a candidate record. Recruiters can enable or disable whether an assessment is shown to the candidate and on share links.
  • Recruiters may also generate a report from an attested public GitHub profile URL they are authorized to assess. Public-GitHub reports process only public repository data, are not automatically linked to an authenticated Truen account, and do not include private AI-tool telemetry.
  • Recruiters may create time-limited, revocable read-only share links (currently expiring after 30 days unless revoked earlier). Share links store a hashed token, not the raw secret, and can display the frozen profile plus an optional enabled assessment to anyone with the link.
  • Anyone with a valid share link can view the shared profile content until the link expires or is revoked. Candidates should treat recruiter submission as sharing with that recruiter and with recipients the recruiter may send a Truen share link to.

Optional AI coding-tool signals

  • If a student connects an AI coding tool through Truen Connect, Truen may receive derived session signals, tooling summaries, project identifiers the student consents to include, and capped redacted excerpts. The CLI shows an upload preview before confirmation; the server re-applies secret redaction as defense in depth.
  • Truen stores pairing credentials as hashes only (connect codes, upload tokens, and device tokens). Students can revoke a device token from the product.
  • AI-tool signals are used to assess AI collaboration style on the Truen Profile when enough evidence exists. Public-GitHub recruiter reports do not include this private telemetry.

AI processing and service providers

  • Truen may send selected repository evidence, derived signals, and related context to AI providers, currently OpenAI, to create profiles, public-GitHub reports, and qualification assessments. That processing happens during generation; Truen’s own databases purge the raw GitHub working set afterward as described above. AI providers process data under their own terms and retention practices.
  • Truen uses service providers such as Supabase (auth and database), GitHub (authorized repository APIs), OpenAI (structured AI outputs), Vercel (hosting and serverless runtime), Inngest (durable background jobs for profile generation), and Resend (transactional email where configured). See the Subprocessors page for the current list.
  • Data may be processed in the locations where those providers operate.

Sharing with employers and recruiters

  • A student profile is private by default.
  • Direct employers receive a frozen profile snapshot when a student applies to that employer’s job, plus any employer-generated qualification analysis for their own jobs.
  • Recruiters receive a frozen profile snapshot when a candidate submits to them, and may share a read-only Truen link with startup clients they represent.
  • Employers and recruiters do not receive raw repository access or the transient raw ingest tables through Truen. Shared profile evidence may still include file paths, commit message samples, repo names, interpretations, and selected code snippets that were embedded into the profile during generation.

Retention, deletion, and correction

  • Raw ingested GitHub content for student profile generation is deleted after each settled generation run — including failed runs after retries are exhausted — as described above.
  • Account data, repository metadata, derived insights, generated profiles, application snapshots, recruiter candidate records, assessments, share-link metadata, and optional AI-signal corpora are retained while needed to operate the service and honor shared application or recruiter snapshots.
  • Self-serve account deletion, full data export, and one-click GitHub disconnect workflows may not cover every record yet. To request correction, export, or deletion of your account or profile data, contact Truen using the contact channel listed with these disclosures. We will respond to verified requests as required by applicable law and as the product allows.
  • Revoking GitHub App access or a share link stops future access through that mechanism, but does not by itself erase already-shared application or recruiter snapshots.

Security

Truen uses server-side access controls, encrypted GitHub tokens at rest, hashed pairing credentials for AI-tool connects, and Supabase row-level security for sensitive data. No internet service can guarantee perfect security. Private repository evidence, profile snippets, and AI-tool excerpts should be treated as sensitive.

Children

Truen is intended for adults participating in professional hiring and early-career job search. It is not directed to children under 16, and we do not knowingly collect personal data from children under 16.

Questions about these disclosures, correction requests, or deletion requests? Contact the Truen team before connecting repositories, submitting to a recruiter, or applying to a role. You can also review the Privacy Policy, Terms, AI Disclosure, and Subprocessors.