Legal
Subprocessors
Truen relies on third-party services to provide authentication, database storage, GitHub access, hosting, background jobs, email delivery, and AI-assisted analysis.
Last updated: July 12, 2026
These pages describe how Truen currently works. They are product disclosures, not legal advice. Have qualified counsel review them before a public launch or paid commercial release.
Current subprocessors
- Supabase: authentication, session handling, database storage, and row-level security.
- GitHub: GitHub App authorization and repository APIs for authorized or public repositories analyzed through Truen.
- OpenAI: structured AI outputs for Truen Profile generation, public-GitHub reports, and employer or recruiter qualification analysis.
- Vercel: application hosting and serverless runtime infrastructure.
- Inngest: durable background job orchestration for profile generation pipelines.
- Resend: transactional email delivery when configured for authentication and account email (for example password reset and verification).
Data processed
- Supabase stores account data, roles, GitHub connection metadata, repository summary signals, derived repo insights, generated profiles and embedded evidence snippets, optional AI-tool signal corpora, applications, recruiter candidate records, assessments, share-link metadata, and employer job or brief data. Raw GitHub ingest tables are a temporary working set and are deleted after each settled profile generation run, including failed runs after retries are exhausted.
- GitHub provides repository metadata, commits, pull requests, issues, selected files, and markdown documents for repositories authorized by the student, or public repositories analyzed for an attested recruiter public-GitHub report.
- OpenAI may process selected repository evidence, derived signals, and related context during generation of AI-assisted profile and qualification outputs.
- Vercel may process request metadata and application runtime data needed to serve Truen.
- Inngest may process job orchestration metadata needed to run durable generation steps (for example student identifiers and generation event payloads).
- Resend may process email addresses and email content needed to deliver transactional auth messages.
Future changes
Truen will update this list before adding analytics, error monitoring, payments, data warehouses, additional AI providers, or other vendors that process personal data. Review this page periodically.
Questions about these disclosures, correction requests, or deletion requests? Contact the Truen team before connecting repositories, submitting to a recruiter, or applying to a role. You can also review the Privacy Policy, Terms, AI Disclosure, and Subprocessors.