Trust and privacy
Thivio's entire dataset is other people's biographies. Here is what we do about that.
What verification means
Verification attaches to specific claims, not to people, and the tier is derived from the signals actually present — never assigned by hand.
- Unverified. Submitted, nothing checked.
- Submitted, nothing checked.Earned by: Default state on submission.
- Self-attested. The author confirmed their identity to us. The content itself is unchecked.
- The author confirmed their identity to us. The content itself is unchecked.Earned by: A registered account plus an explicit attestation.
- Source-linked. At least one claim in this pathway is corroborated by an external source.
- At least one claim in this pathway is corroborated by an external source.Earned by: A matching LinkedIn OAuth identity, a public profile URL, or a verifiable credential link.
- Institution-verified. An institution or employer email domain was confirmed for a step claimed in this pathway.
- An institution or employer email domain was confirmed for a step claimed in this pathway.Earned by: A .edu or employer domain challenge, or manual review of an uploaded credential.
Nothing here is scraped
Every pathway was submitted by the person it describes, or by someone with documented permission. There is no importer, no crawler, and no “claim your profile” flow built on data collected without your action.
You choose what is public, field by field
Name, institution, employer, compensation, location precision, graduation year, GPA band, and background tags are each independently controllable. Compensation defaults to private. Hidden fields are removed from the response entirely rather than blanked — a withheld field does not announce itself.
Pseudonymity survives verification
A pseudonymous pathway can still reach source-linked or institution-verified. Checks run against your real identity; only the badge is shown. Your real name is never sent to any viewer, share card, or search index at any tier.
Contact is a relay
Contactability is opt-in per pathway and revocable. Messages route through a rate-limited relay — your address is never exposed. Outreach must include context; blank messages are rejected. You can mute or cut off any thread, or all of them.
Deletion is real deletion
One tap exports your pathway as JSON. One tap deletes it — from the database, the search index, the caches, and from every “similar pathways” list. The only thing kept is a receipt proving the erasure completed, which contains none of your biography.
Background tags are self-declared, never inferred
Nothing here derives a demographic attribute from your name, institution, photo, or writing. No model guesses them. Every tag is optional and independently hideable.
Compensation is always a band
Thivio cannot store an exact salary figure. This reduces the doxxing surface and keeps submitters clear of pay-disclosure clauses.
Under 18
Reading Thivio is open to everyone. Submitting a pathway requires being 16 or older, and submitters aged 16–17 need verified parental consent. Withdrawing consent unpublishes the pathway immediately.
No engagement mechanics
No likes, no streaks, no infinite scroll, no notifications engineered to pull you back. Saved-search alerts are opt-in, email-only, and capped at a weekly digest. Ranking never uses popularity — view and save counts are structurally absent from the search index.