TalentGraph processes two very different kinds of personal data: information about you, our customer, and information about candidates whose resumes you upload. They are handled differently, and this page separates them.
Last updated: 10 September 2026
When you create an account we collect your name, work email, company name and, on paid plans, billing details handled by our payment processor. We use this to run your account, bill you, provide support and send service notices. If you opt into the newsletter we use your email for that too, and every message carries an unsubscribe link.
We also collect ordinary operational telemetry — request logs, error traces, aggregate usage counts — to keep the service running and to understand which features are used. Logs are retained for a limited period and are not used to build a profile of you.
Resumes contain names, contact details, employment history, education and sometimes far more. For this data you are the controller and TalentGraph is the processor: we process it on your instruction, for the purpose of providing the service, and for no purpose of our own.
Whether you have a lawful basis to upload a given resume is your responsibility as controller — most commonly the candidate applied to you, or consented to being kept on file.
We use a cloud hosting provider to run the service, a payment processor for billing, and a model provider (Google Gemini, OpenAI or Anthropic, as you configure) for the AI fallback path. Model providers do not train on content sent through their paid APIs. On Enterprise you may supply your own keys, or self-host and disable the fallback entirely. A current sub-processor list is available on request.
Account data is kept while your account is open. Parsed candidate records are kept until you delete them or close the account, after which customer data is deleted within 30 days. Original uploaded files are not retained unless you enable document storage. Enterprise customers can configure shorter retention windows.
We use cookies and local storage that are necessary to run the app — your session and your light/dark theme preference. We do not run third-party advertising trackers.
Depending on where you live you may have rights to access, correct, delete, port or object to the processing of your personal data, and to complain to a supervisory authority. Contact us and we will act on a request within the applicable statutory period. If your request concerns a candidate record held by one of our customers, we will refer you to that customer, who is the controller of it.
Data may be processed in a country other than your own, including where your chosen model provider operates. Where required we rely on Standard Contractual Clauses or an equivalent transfer mechanism. Enterprise customers can pin processing to a specific region, or self-host.
Encryption in transit and at rest, restricted production access and a documented deletion path. The detail — including what we have not yet certified — is in the security overview.
If we change this policy materially we will notify account holders before the change takes effect. Questions go to our contact form.