Privacy Policy

What we collect, and what we do not.

TalentGraph processes two very different kinds of personal data: information about you, our customer, and information about candidates whose resumes you upload. They are handled differently, and this page separates them.

Not legal advice.This document is a good-faith plain-English draft describing how TalentGraph actually works. It has not been reviewed by a lawyer. Have counsel review and adapt it for your jurisdiction before you rely on it as a binding published policy.

Last updated: 10 September 2026

1. Data about you (our customer)

When you create an account we collect your name, work email, company name and, on paid plans, billing details handled by our payment processor. We use this to run your account, bill you, provide support and send service notices. If you opt into the newsletter we use your email for that too, and every message carries an unsubscribe link.

We also collect ordinary operational telemetry — request logs, error traces, aggregate usage counts — to keep the service running and to understand which features are used. Logs are retained for a limited period and are not used to build a profile of you.

2. Data about candidates (documents you upload)

Resumes contain names, contact details, employment history, education and sometimes far more. For this data you are the controller and TalentGraph is the processor: we process it on your instruction, for the purpose of providing the service, and for no purpose of our own.

  • We do not sell candidate data, ever.
  • We do not use candidate data to train any model.
  • We do not share one customer’s talent pool with another.
  • We do not contact candidates.

Whether you have a lawful basis to upload a given resume is your responsibility as controller — most commonly the candidate applied to you, or consented to being kept on file.

3. Sub-processors

We use a cloud hosting provider to run the service, a payment processor for billing, and a model provider (Google Gemini, OpenAI or Anthropic, as you configure) for the AI fallback path. Model providers do not train on content sent through their paid APIs. On Enterprise you may supply your own keys, or self-host and disable the fallback entirely. A current sub-processor list is available on request.

4. Retention

Account data is kept while your account is open. Parsed candidate records are kept until you delete them or close the account, after which customer data is deleted within 30 days. Original uploaded files are not retained unless you enable document storage. Enterprise customers can configure shorter retention windows.

5. Cookies

We use cookies and local storage that are necessary to run the app — your session and your light/dark theme preference. We do not run third-party advertising trackers.

6. Your rights

Depending on where you live you may have rights to access, correct, delete, port or object to the processing of your personal data, and to complain to a supervisory authority. Contact us and we will act on a request within the applicable statutory period. If your request concerns a candidate record held by one of our customers, we will refer you to that customer, who is the controller of it.

7. International transfers

Data may be processed in a country other than your own, including where your chosen model provider operates. Where required we rely on Standard Contractual Clauses or an equivalent transfer mechanism. Enterprise customers can pin processing to a specific region, or self-host.

8. Security

Encryption in transit and at rest, restricted production access and a documented deletion path. The detail — including what we have not yet certified — is in the security overview.

9. Changes and contact

If we change this policy materially we will notify account holders before the change takes effect. Questions go to our contact form.