Privacy Policy
Last updated: 11 July 2026. This document describes how truelo handles your data.
What we collect
- Identity — your Slack user ID, display name, email and avatar. When an admin adds truelo to a workspace we import the current member roster (name, email, avatar) so the Employees list isn't empty on day one; we also read these via Slack sign-in. If you connect GitHub or Jira/Linear, your username / account ID too.
- Work activity — commit metadata (repository, branch, message, additions/deletions, timestamps) from your connected GitHub organization, and issue metadata from your connected Jira or Linear site. We do not store source code.
- Self-reported input — what you submit via the
/wrapcommand (hours, notes, an optional one-tap mood check and optional blockers) and time-off requests (dates, type, optional reason). - Wellbeing & work-pattern signals — where your workspace enables them, we derive light wellbeing indicators from your optional mood check and blockers, and surface work-pattern signals (for example frequent after-hours or weekend activity) computed from commit timestamps. These are shown to your workspace admins/managers. The mood check is always optional and can be skipped.
- Operational data — settings, integration connection records (secrets encrypted at rest), and logs needed to run the service.
How we use it
To generate end-of-day summaries and dashboards, manage time off, and provide the features you and your workspace admins configure. Commit messages and notes may be sent to a third-party AI provider (OpenAI or Anthropic) to generate summaries and ratings; that content is processed to produce the output and is not used to train their models under the applicable API terms.
Legal basis (GDPR)
Where the GDPR applies, we process personal data to perform our contract with your organization (Art. 6(1)(b)), on our legitimate interests in operating, improving and securing the service (Art. 6(1)(f)), and, where legally required, on your consent. We do not carry out automated decision-making that produces legal effects.
Who can see it
Your data is scoped to your organization. Access within your organization follows the roles your admins configure. We do not sell your data or share it with third parties except the sub-processors needed to run the service — see the list of sub-processors (hosting, database, AI provider, Slack and payments).
International transfers
Some sub-processors (for example the AI provider) may process data outside the European Economic Area, including in the United States. Where they do, the transfer is covered by an appropriate safeguard such as the EU Standard Contractual Clauses.
Cookies
We use only strictly-necessary cookies: a session cookie to keep you signed in, and short-lived security cookies during OAuth sign-in. We do not use advertising, marketing or third-party analytics cookies or trackers, so no consent banner is required — clearing cookies in your browser simply signs you out.
Retention & deletion
We keep your data for as long as your organization uses the service. You are always in control:
- Self-serve export — you can export your own activity at any time from within the app.
- Remove a member — an admin removing a person deletes their personal data from the workspace.
- Delete the organization — an owner can delete the organization from Settings, which cancels any subscription and erases all of its data (members, activity, submissions, integrations). Billing records held by our payment processor (Stripe) are retained by them as required by law (e.g. tax/accounting).
When an organization or member is deleted we remove the data promptly and, in any case, within 30 days (backups roll off shortly after). We do not retain personal data longer than needed for the purposes above or as required by law.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and the right to data portability. To exercise them, email us or ask your workspace admin; we respond within one month. You may also withdraw any consent at any time.
Complaints
You have the right to lodge a complaint with your local data protection supervisory authority.
Our role
For data about your organization's members and activity, your organization is the data controller and truelo acts as a data processor on its behalf. A Data Processing Agreement (DPA) is available on request.
Security
Integration secrets are encrypted at rest, access is authenticated and role-gated, and server-side credentials are never exposed to the browser.
Contact
Questions or data requests: trueloapp@gmail.com.