HR sees program-level analytics: activation rates, engagement trends, placement times by cohort, internal mobility metrics, and spend by category. All metrics are aggregated and de-identified.
Privacy Overview
HR oversight, not employee surveillance.
Most outplacement platforms force a tradeoff: either HR gets visibility, or employees get privacy. Ture's data model is built so both are real at the same time.
The principle
What HR sees, and what it doesn't.
Ture splits visibility along a clean, enforceable boundary. HR oversight stays at the program level. Private workspaces stay private.
- HR sees: activation, engagement, time-to-placement, internal mobility, spend, program-level participation.
- HR does not see: individual job applications, chat history with the AI Coach, personal documents, employer-side identifiers tied to private activity.
- The boundary is enforced by the data model — not by policy alone.
- Provider seats are a third permission tier with case-scoped access.
How the boundary works
Six controls, end-to-end.
Bifurcated data model
Employer-scoped and employee-scoped data live in separate row-level access paths. HR queries cannot reach employee-private rows.
De-identified analytics
All HR analytics aggregate over cohort thresholds. Cohorts below the threshold are suppressed automatically.
Encrypted private workspaces
Employee chats, documents, and job tracking data are encrypted at the row level. Keys are scoped per workspace.
Role-based access
HR, employee, and provider roles each have explicit permission scopes. There is no admin role that bypasses the boundary.
Auditable access logs
Every access to scoped data is logged and reviewable. Anomalies trigger automated alerts to the security team.
Employee data subject rights
Employees can export, correct, and delete their private workspace data at any time. Requests complete within the regulatory window.
What this looks like in the product
Three workflows where the boundary matters most.
Job search
Employees apply privately. HR sees activation.
When an employee applies to roles through the AI Coach, HR sees that the platform is being used. HR does not see which roles, which companies, or the application content. The employee chooses what to share back, if anything.
- Application content stays in the employee workspace.
- HR sees aggregated activation and engagement only.
- Inbox-aware tracking is opt-in per employee.
Coaching
Coaching conversations are private by default.
Conversations between the employee and the AI Coach (or a human coach via the Provider & Coach Hub) are scoped to the participant. HR sees that coaching is happening — never the content.
- AI Coach chat history scoped to employee.
- Provider notes scoped to assigned cases.
- Aggregated coaching engagement metrics for HR.
Spend
Employees spend Flex Credits autonomously.
When employees spend Flex Credits in the Marketplace, HR sees category-level spend reporting. HR does not see individual purchases. The employee's choices stay theirs.
- Category-level spend reporting only.
- Per-cohort thresholds before disclosure.
- Refunds and disputes handled in the employee workspace.
“The bifurcated privacy model let me tell the board honestly that we have visibility without surveillance, which mattered to our employee trust narrative. The ROI dashboard is the reason I bought the platform — the privacy model is the reason it worked.”
Howard Tan
Chief People Officer, CogniStream
Common privacy questions.
Want a deeper review?
We will walk you through the privacy model.
If you are evaluating Ture, your employees, your works council, or your privacy team should see exactly how the boundary is enforced. We can do that walkthrough on a call.