PRIVACY POLICY

Last updated

This Privacy Notice for Syphon Labs LLP ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Visit our websites at https://www.syphonlabs.com/, https://talenry.com/, or any website of ours that links to this Privacy Notice
  • Use our products: Draft (AI resume and job-search workspace), Daisy Recruiter (AI recruitment tools), and Talenry (an AI career agent that finds matching jobs and prepares, fills, and submits job applications on your behalf, at your direction)
  • Install our browser extensions, including the Draft extension and Talenry Copilot, or our Talenry mobile app for iOS and Android
  • Engage with us in other related ways, including any sales, marketing, or events

Talenry, Draft, and Daisy Recruiter are products owned and operated by Syphon Labs LLP, a company based in India, which is the data controller responsible for your personal information under this Notice. Our systems run on Microsoft Azure in the United States (see Section 10).

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, contact us at admin@syphonlabs.com.

SUMMARY OF KEY POINTS

What do we process? Account details, your career profile (resume, work and education history, answers to application questions), payment data, and usage data. If you connect them, we also process records derived from your Gmail mailbox and a record of every job application we submit for you.

The heart of Talenry: you give us your career data precisely so we can act on it for you: match you to jobs, tailor your resume and cover letters, generate application answers, fill and submit applications to employers, track outcomes from your inbox, and draft outreach to recruiters. If you are not comfortable with your data powering those actions, do not use Talenry.

AI training: we do not use your resumes, documents, messages, or interactions to train or fine-tune AI models. Our AI provider, Microsoft Azure OpenAI, runs inside our own Azure tenant and does not train on your data. If this ever changes we will tell you and ask for your consent first.

Where your data lives: on Microsoft Azure in the United States, plus the service providers named in Section 4.

Analytics: the Talenry app, extension, and mobile app use PostHog to understand feature usage and reliability. Our marketing website syphonlabs.com uses Google Analytics, only after you accept cookies. Analytics never includes your resume text, answers, or form values, is not used for advertising, and is not sold.

Sensitive data: we do not intentionally request it, but resumes, applications, and voluntary self-identification questions may contain it; we process it only as needed to provide the Services.

Selling data: we do not sell your personal information. We do not currently offer any feature that shows your profile to recruiters or employers; if we ever do, it will be opt-in and we will ask you first.

1. WHAT INFORMATION DO WE COLLECT?

In short: we collect the information you give us, the information needed to act on your behalf, and technical usage data.

Personal information you disclose to us

  • Names, email addresses, passwords, phone numbers, contact preferences
  • Mailing/postal addresses (some employer application systems, such as Workday, require a full postal address)
  • Job titles, target role, work history, education history, skills, salary expectations
  • Resumes, cover letters, portfolios, and any documents you upload
  • Visa / work-authorization status where you provide it (used, for example, to filter for E-Verify-enrolled employers)
  • Answers to job-application questions, both answers you type and answers our AI drafts for you
  • Voluntary self-identification responses (e.g., gender, veteran status, disability status) only if you choose to provide them for inclusion in applications; we never fabricate these
  • Billing information, processed by our payment processors (see "Payment data" below); we never receive or store your full card number

Before you sign up: the website chat

If you use the chat on the Talenry landing page before creating an account, we keep your conversation so it can continue and, if you sign up, so our AI can draft your profile from it. Your browser gets a random identifier cookie (tl_lead); on our servers we store only a one-way hash of it, never the raw cookie value or your raw IP address. We also record the page you landed on, the referring site, and any campaign (UTM) parameters. Chats with no email address are deleted after 30 days of inactivity; chats where you gave an email are deleted after 365 days. When you sign up, the chat is merged into your account.

Information created or collected when Talenry acts for you

  • Applications we submit: a record of each application, including the employer, role, the exact field values submitted, generated documents, timestamps, and outcome status. We keep a copy of your profile as it was at the time of each attempt so your history stays accurate, and we cache your answers so repeated questions can reuse them.
  • ATS accounts: some employer application systems (e.g., Workday, iCIMS) require an account. With your use of auto-apply you direct us to create one for you using your email address and a password we generate. The credentials are stored encrypted in Microsoft Azure Key Vault and are deleted when you delete your account.
  • Gmail-derived records (only if you connect Google): see Section 8A. Message bodies are never stored.
  • Mock-interview records: the transcript, our AI's feedback and scores, and the job description used, stored with your account. Talenry never receives or stores your audio. See Section 8D.
  • Recruiter contacts: business contact details of recruiters we look up for your outreach, and of recruiters who email you about an application (name, email, company), saved to your private contacts.
  • Push notification tokens: if you use our mobile app and allow notifications, a device push token.
  • Reliability snapshots: when an automated application fails, we save the filled form (as HTML), a full-page screenshot, and a redacted summary to diagnose the failure. These contain the information that was on the form (name, contact details, self-identification answers). They are deleted automatically after 14 days, or immediately when you delete your account.
  • Copilot reliability events: a small diagnostic record each time you click Fill in the Talenry Copilot extension. It contains no form content. See Section 8B.
  • Browser session state: our cloud-browser provider keeps site cookies from your automated sessions between applications so later submissions work better. See Section 8C.

Information automatically collected

Server logs. Our servers record standard request logs (time, endpoint, status, IP address, browser details) to run and secure the Services. Logs are kept for 90 days.

Usage analytics (PostHog). The Talenry web app, mobile app, Copilot extension, and our servers send usage events to PostHog, our product-analytics provider. Events are linked to your account ID and email and describe things like the feature used, screens viewed, buttons tapped (never the text you type), your plan, sign-up and sign-in, auto-apply outcomes, and Copilot fill results (the job site's hostname and field counts). Analytics never includes resume text, application answers, or form values. In the web app, analytics runs only after you accept it, and we send events without your IP address. In the mobile app, events currently include your IP address, from which PostHog may derive an approximate location; you can turn mobile analytics off in Settings. Events sent by our servers carry no IP address. Session replay, surveys, and heatmaps are switched off.

Website analytics (syphonlabs.com). Our marketing website uses Google Analytics to measure traffic and performance. It runs only after you accept analytics cookies in the banner, and you can change your choice at any time through the cookie preferences link in the footer.

We also use cookies and similar technologies; see our Cookie Notice and Section 5.

Payment data

Payments are processed by Razorpay and PayPal. When you pay, they receive your name, email address, billing details, and payment method and process them under their own privacy policies. Talenry never receives or stores your full card number. Checkout pages load their scripts, which set their own cookies.

2. HOW DO WE PROCESS YOUR INFORMATION?

In short: to run your job search for you, to run and improve the Services, to communicate with you, for security, and to comply with law.

  • Account management — create and secure your account and authenticate you (email and password with email verification, or Google sign-in). Verification and password-reset emails are sent through Microsoft Azure Communication Services.
  • Job matching — we compute AI representations (embeddings) of your profile and of job listings to rank roles by fit.
  • Application preparation — tailor your resume and cover letter to a role; draft answers to application questions from your profile and your previously approved answers.
  • Application submission (auto-apply) — at your direction, fill and submit applications to employers' systems on your behalf. This includes operating cloud browser sessions, routing traffic through proxies, completing anti-bot challenges, creating required ATS accounts for you, and entering one-time verification codes emailed to your connected inbox to finish a submission you initiated. See Section 8C.
  • Application tracking — read job-application-related emails in your connected mailbox (confirmations, interview invitations, rejections) to keep your dashboard current and label them in Gmail. See Section 8A.
  • Recruiter outreach — where you enable it, identify a relevant recruiter at a company you applied to and draft an introduction for you. See Section 8E.
  • AI mock interviews — run voice interviews and generate feedback and scores.
  • Website chat — continue your pre-signup conversation and, if you sign up, draft your profile from it.
  • Reliability and diagnostics — diagnose failed applications (reliability snapshots), measure which application systems the Copilot extension works on (reliability events), and troubleshoot automated sessions (cloud-browser session recordings).
  • Analytics — understand how the Services are used so we can operate, secure, and improve them. Not used for advertising, not sold, and not used to train AI models.
  • Notifications — send you push notifications about your applications (mobile app, if enabled).
  • Support, feedback, marketing (with your preferences), security and fraud prevention, and legal compliance.

We do not use your resumes, documents, messages, or interactions to train or fine-tune AI models. See Section 6.

3. WHAT LEGAL BASES DO WE RELY ON?

In short: consent, contract, legitimate interests, legal obligations, and vital interests, as applicable in your jurisdiction (GDPR/UK GDPR, Canadian law, and others).

If you are in the EU/UK: we process your information with your consent (for example, when you connect your Gmail account, accept analytics, or opt in to marketing; you can withdraw consent at any time), for performance of a contract (most of Talenry's processing exists to deliver the service you asked for: applying to jobs on your behalf), for our legitimate interests (securing the Services, diagnosing failures, and understanding usage where consent is not required, balanced against your rights), to meet legal obligations, and to protect vital interests. If you are in Canada, we process with express or implied consent, with limited legal exceptions.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In short: with the employers you apply to, and with the service providers that make the Services work. We do not sell your data.

Employers and their applicant-tracking systems (ATS). When you apply, yourself or via auto-apply, your application data (profile fields, resume, cover letter, answers) is transmitted to the employer and its ATS provider (e.g., Greenhouse, Ashby, Workable, SmartRecruiters, Workday, iCIMS). They process it under their own privacy policies. This sharing is the purpose of the product and happens at your direction.

Service providers. The companies below process data on our behalf under written contracts. Each receives only what its role requires.

ProviderRoleWhat it receivesWhere
Microsoft AzureHosting, database, file storage, secrets (Key Vault), email delivery (Azure Communication Services)All account and application dataUnited States
Microsoft Azure OpenAIAI models (resume parsing, answers, documents, chat, email classification, interview scoring)Resume text, profile, job descriptions, form questions, email bodies our rules cannot classify, interview transcripts. Runs in our own Azure tenant; Microsoft does not train on this dataUnited States
Azure AI Document IntelligenceResume OCRUploaded resume filesUnited States
PostHog, Inc.Product and reliability analytics (Talenry web app, mobile app, servers, Copilot extension)Account ID, email, event names and properties (feature used, plan, ATS hostname, fill counts). Mobile events include your IP address. Never resume text, answers, or form valuesUnited States
BrowserbaseCloud browsers for automated applications, residential proxies, captcha solving, persistent per-user browser stateEvery page the automation loads, including the filled application form. Sessions are recorded (video replay, console and network logs) for troubleshooting and deleted after 30 daysUnited States
ElevenLabsVoice for AI mock interviews (LiveKit carries the audio inside ElevenLabs' mobile SDK)Microphone audio streamed directly from your device; your name, the role, company, job description, and a profile summary. See Section 8DUnited States
2Captcha, CapSolverCaptcha solving (integrated; not currently in use)The challenge, page address, and site key only. Never your profile dataPer provider
Hunter.io, ApolloRecruiter contact lookupThe employer's company name or domain and recruiter job-title filters. Nothing about youPer provider
ExpoPush notifications (mobile)Device push token and the notification text (which may name an employer or role)United States
Cloudflare TurnstileBot check on the website chat (only when enabled)Standard challenge dataPer Cloudflare
Razorpay, PayPalPaymentsName, email, billing details, payment method. We never receive full card numbersIndia (Razorpay); PayPal per its policy
LangfuseAI request monitoring (currently switched off)If enabled: metadata only (model, timing, token counts, hashed fingerprints). No prompt or response textUnited States
GoogleSign-in (web and mobile); Gmail integration (web only); Google Analytics on syphonlabs.comSee Section 7, Section 8A, and Section 5Per Google
  • Recruiters. Outreach you approve is shown to you as a draft to copy into your own mail app; we do not currently send it for you. When you send it, the recruiter receives what the draft contains: your name, the role, the company, an optional LinkedIn link, and your resume.
  • AI assistants you connect. If you connect a third-party AI assistant to Talenry, it acts with your credential at your direction. See Section 8G.
  • Business transfers and legal obligations, as in any privacy notice: merger/acquisition contexts, and where disclosure is required by law or to protect rights, property, or safety.

We do not sell your personal information, and we do not currently make your profile visible to recruiters or employers through any discovery feature.

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

Talenry (talenry.com): sets strictly necessary cookies for sign-in, security, and preferences, and, with your consent where the law requires it, an analytics cookie from PostHog. Analytics is off until you accept it. The Talenry app honours the Global Privacy Control signal. Checkout pages load Razorpay and PayPal scripts that set their own cookies. Our browser extensions and mobile app set no cookies.

syphonlabs.com: sets a cookie to remember your consent choice and, only after you accept, Google Analytics cookies. You can change your choice at any time through the cookie preferences link in the footer.

We do not respond to Do Not Track browser signals (see Section 13). Where cookies are a "sale" or "sharing" under applicable US state law, you can opt out (Section 14). Full details, names, and lifetimes are in our Cookie Notice.

6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

In short: yes, AI is the core of our products. We do not train AI models on your data.

Our AI-powered features ("AI Products") include: job matching and ranking; resume and cover-letter generation and tailoring; application-answer generation; the auto-apply agent that fills and submits applications; email classification for application tracking; recruiter-outreach drafting; the website chat; AI insights; and AI mock interviews.

Language and embedding models run on Microsoft Azure OpenAI inside Talenry's own Azure tenant; Microsoft does not train on the data. Resume OCR uses Azure AI Document Intelligence. Mock-interview voice is provided by ElevenLabs. The inputs these providers see are your resume text, profile, job descriptions, application questions, email bodies our rules cannot classify, interview transcripts, and chat messages, as described in Section 4. You must not use the AI Products in ways that violate an AI provider's policies.

AI training. We do not use your resumes, documents, messages, or interactions to train or fine-tune AI models. Our AI provider does not train on your data. If this ever changes we will tell you and ask for your consent first. Data obtained through Google APIs (including your connected Gmail mailbox) is never used to develop, improve, or train AI or machine-learning models, consistent with the Google API Services User Data Policy.

AI request monitoring. We may use Langfuse to monitor AI requests. It is currently switched off. If enabled, it receives metadata only (model, timing, token counts, hashed fingerprints), never prompt or response text.

7. SIGN-IN, SESSIONS, AND GOOGLE SIGN-IN

You can register with an email address and password (we send a verification email) or sign in with Google, on the web and natively in the mobile app. We do not offer Apple sign-in or magic links. When you sign in with Google we receive basic profile information (name, email address, profile picture) and use it only as described in this Notice. The mobile app's Google sign-in requests basic identity only and never accesses Gmail. Connecting Gmail for application tracking is a separate, optional step on the web, covered in Section 8A.

Sessions last 7 days. Signing out clears the session cookie. Verification and password-reset emails are sent through Microsoft Azure Communication Services.

8A. GOOGLE API SERVICES & GMAIL DATA (TALENRY)

Talenry's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Scopes. When you connect Gmail on the web (which also signs you in), we request openid, email, profile, and https://www.googleapis.com/auth/gmail.modify. This is the only Gmail scope we use. The mobile app never accesses Gmail.

What we do with it. We access your mailbox only to provide features you can see and control:

  • Detect application updates. When you connect, we look back 30 days; after that we check new inbox mail roughly every 15 minutes. For each message we read the sender, subject, recipients, and body. Rules classify most messages; the rest (the first 6,000 characters of the body) are sent to Azure OpenAI for classification. Promotions and sent mail are excluded, and bank, shopping, and social senders are skipped.
  • Store only the outcome. For each relevant message we keep the message ID, its category (applied, screening, assessment, interview, offer, rejected), a confidence score, the date, and an interview time if one is found. Message bodies are never stored.
  • Label your mail. We create and apply the labels Talenry/Applied, Talenry/Screening, Talenry/Assessment, Talenry/Interview, Talenry/Offer, and Talenry/Rejected to messages that change an application's status.
  • Enter verification codes. During an automated application, we read a one-time code an employer's system emails you, enter it to finish the submission you initiated, and discard it. Codes are never stored or logged.
  • Save recruiter contacts. A recruiter who emails you about an application is saved to your private contacts (email, name, company).
  • Recruiter outreach. Where you enable it, we prepare outreach for your approval. Sending from your mailbox is currently disabled: approved drafts are shown for you to copy into your own mail app.

Token storage. Your Gmail refresh token is stored in Microsoft Azure Key Vault, encrypted at rest, as a separate secret per user.

We do not: use Gmail data for advertising; sell Gmail data; use Gmail data to train AI models; or allow humans to read your mailbox data except with your explicit consent for support, for security and abuse investigation, or where required by law. You can disconnect Gmail at any time in Settings, which removes our token and also revokes Talenry's access in your Google account. You can also review or revoke access at myaccount.google.com/permissions.

8B. BROWSER EXTENSIONS

Draft extension

When you explicitly click "Save," the Draft extension extracts the job title, company, location, description, and URL of the active job posting and syncs it to your Draft dashboard for resume tailoring and career insights. It stores a secure access token locally to maintain your session and may collect technical logs for stability. Its broad site access is used solely to detect and extract job listings when you trigger a save; we do not track your browsing history and do not collect data from pages you do not save.

Talenry Copilot extension

Talenry Copilot helps you complete job applications that Talenry's cloud agent could not finish (for example, forms behind strict anti-bot checks). It is distributed through the Chrome Web Store and works on your command:

  • Access. At install it can access only talenry.com. It asks for access to a job site the first time you use it there, or to all sites if you choose "Enable on every job site." You can revoke either at any time at chrome://extensions.
  • What it does when you click Fill. It fetches your profile, generated answers, resume, and cover letter from talenry.com over HTTPS and fills the form in front of you. It never clicks Submit. You review, complete anything missing, solve any captcha, and submit yourself.
  • Reading the form. It reads the values already in the form so it does not overwrite what you typed. Those values stay in your browser and are never sent anywhere.
  • Sign-in pages. It refuses to fill pages whose address indicates sign-in, registration, or password reset, and never fills password fields anywhere.
  • Job understanding (Save, Match, Draft answers). When you ask it to, it sends the posting's title, company, location, description text, and page address to talenry.com so our AI can parse the role, score the match against your profile, and draft answers. On pages without structured job data the description may be the page's visible text, up to 20,000 characters. When drafting answers, only the unanswered questions' text and options are sent. No screenshot or page HTML is ever sent.
  • Matching on panel open. When you open the panel on an application page, it asks talenry.com for your fill data using that page's address so we can match it to the right application. This is not added to analytics.
  • Confirmation detection. After a fill you started, it checks locally whether the page is a confirmation page and asks talenry.com to mark the application as applied. If the application is not already in your dashboard, the page address and title are sent to create it. No page content is sent.
  • Badge and job-page detection. Runs entirely in your browser and sends nothing.
  • Reliability event. Each time you click Fill, the Copilot sends Talenry a small reliability event so we can see which application systems work and which do not. It contains the website's hostname (never the page address), whether the fill succeeded, a fixed error category if it failed, how many fields were filled, skipped, or left for you, the number of frames on the page, how long the fill took, and the extension version. It never contains field names, the values on the form, or anything about your browser or device. Our servers forward these events, linked to your account, to our analytics provider PostHog. The extension itself contains no analytics code and never contacts PostHog. You can turn off reliability events in the Copilot settings; the extension works the same either way.
  • Cookies. It reads only Talenry's own session token on talenry.com. It reads no cookies on any other site and sets no cookies.
  • Storage. Chrome's local extension storage holds your Talenry session token and your answer to the all-sites prompt. For the current browser session only, it also holds the IDs of tabs awaiting a confirmation page. Nothing syncs through your Google account.
  • No copy of your profile at rest. Your profile, answers, and resume are held in memory while the panel is open and discarded when it closes. The session token is removed when you sign out. Uninstalling removes all extension storage.
  • No other code. No crash reporting, advertising, or third-party analytics; no remote scripts or fonts. It communicates only with talenry.com.

We do not sell extension data, do not use it for advertising, and do not use it for creditworthiness or lending. We do not transfer it to third parties other than the employer page you are actively filling and PostHog, which receives only the reliability event described above.

8C. AUTOMATED APPLICATIONS (AUTO-APPLY)

When you enable auto-apply or approve an application, Talenry submits it for you in a cloud browser operated by Browserbase in the United States (Oregon). To make submissions work reliably, the browser's traffic exits through a residential proxy matched to the country in your profile (United States by default), and Browserbase keeps your browser session state (site cookies) between applications.

  • Session recordings. Browserbase records each automated session (video replay, console logs, and network traffic) for troubleshooting. Because the session includes the form as it is filled, the recording contains the information on the form. Browserbase deletes recordings after 30 days.
  • Anti-bot challenges. Captchas may be solved by Browserbase's own solver, or by 2Captcha or CapSolver (integrated but not currently in use). They receive the challenge and page address only, never your profile data.
  • ATS accounts. Where an employer's system requires an account, we create one with a password we generate and store it encrypted in Azure Key Vault. It is deleted when you delete your account.
  • Reliability snapshots. When an application fails, we save the filled form (HTML), a full-page screenshot, and a redacted summary to diagnose the failure. They contain the information on the form. They are deleted automatically after 14 days, or immediately when you delete your account.
  • Your history. We keep a copy of your profile as it was at each attempt with the application record, and we cache your answers so repeated questions reuse them.

You can pause auto-apply or stop using the Services at any time; doing so does not retract applications already submitted to employers.

8D. AI MOCK INTERVIEWS

Your microphone audio streams directly from your device to ElevenLabs, which runs the interview voice; on mobile, LiveKit carries that audio for ElevenLabs. Talenry does not receive or store audio. To run the interview, ElevenLabs receives your name, the role, the company, the job description (up to 4,000 characters), and a summary of your profile (up to 4,000 characters).

ElevenLabs does not record or store your audio. It keeps the interview transcript, together with the name, profile summary, and job description we sent it, for 30 days so we can investigate a broken interview, then deletes them. We store the transcript, our AI's feedback and scores, and the job description with your account. Feedback and scores are practice signals, not assessments used by employers.

8E. RECRUITER OUTREACH AND CONTACTS

Finding a recruiter. Where you enable outreach, we send the employer's company name or domain, and job-title filters, to Hunter.io or Apollo to find a relevant recruiter. Nothing about you is sent. The results are stored as contacts in your account.

Sending outreach. An outreach email you approve contains your name, the role, the company, an optional LinkedIn link, and your resume. Sending from your mailbox is currently disabled: approved drafts are shown for you to copy into your own mail app, so you decide what is sent and to whom.

Recruiter discovery. We do not currently offer any feature that indexes your profile or makes it visible or searchable to recruiters or employers. We may in future offer an opt-in recruiter discovery feature; if we do, we will update this Notice and ask for your consent before enabling it.

8F. MOBILE APP

The Talenry app for iOS and Android uses the same account and backend as the web app. It requests microphone access only for live mock interviews. It does not access your contacts, location, camera, or photos. It uses PostHog for usage analytics (app open and close, screens viewed, taps without the text you type, linked to your account ID and email; events include your IP address) and contains no advertising SDKs. You can turn analytics off in Settings. Push notifications are optional and delivered through Expo's push service, which receives your device token and the notification text. Your session token and preferences are kept in the device's secure storage (Keychain or Keystore) and removed when you sign out or uninstall the app.

8G. AI ASSISTANTS YOU CONNECT

You can connect an AI assistant such as Claude or Codex to Talenry with our connector. It runs on your own device with your Talenry credential and, at your direction, can read your profile, jobs, and applications and take actions you allow, including updating your profile, submitting an application through auto-apply, and preparing outreach you approve. We do not host the connector, and we do not share your credential with the assistant's provider. The assistant provider processes what it accesses under its own privacy policy.

8H. INFORMATION ABOUT PEOPLE WHO ARE NOT OUR USERS

  • Recruiters. To prepare outreach for your application, we obtain a relevant recruiter's business-contact details (name, title, work email) from business-contact data providers, and we save the details of recruiters who email you about an application. We process this business contact information under our legitimate interest in delivering the outreach you requested. A recruiter may contact admin@syphonlabs.com to have their details removed from our records.
  • Referrals. If you use referral features and enter a friend's name or email address, those details are used to provide the referral feature. Only refer people you know and who would want to hear from you.

9. HOW LONG DO WE KEEP YOUR INFORMATION?

As long as needed for the purposes above, typically for as long as you have an account. The table below lists the specific periods. When there is no ongoing legitimate business need, we delete or anonymize your information, or isolate it from processing until deletion is possible (e.g., backups).

DataRetention
Account, profile, applications, documents, contacts, interview transcriptsLife of the account
Gmail-derived records (message ID, category, date)Life of the account; message bodies never stored
Verification codes read from GmailNot stored
Reliability snapshots14 days, or immediately on account deletion
Website chat before sign-up30 days without an email address; 365 days with one
Analytics events and profile (PostHog)Up to 7 years (our plan's retention setting); deleted when you delete your account
Interview transcript and context at ElevenLabs30 days, then deleted; audio never stored
Cloud-browser session recordings (Browserbase)30 days
Cloud-browser session state (site cookies)Until you delete your account
ATS accounts created for youUntil you delete your account
Server logs90 days
Database backups14 days
Deleted files (storage soft-delete)14 days
AI call records (model, tokens, cost; unlinked from you on deletion)Kept for accounting

10. HOW DO WE KEEP YOUR INFORMATION SAFE, AND WHERE IS IT PROCESSED?

We use appropriate technical and organizational measures: encryption in transit (TLS) everywhere, encrypted storage of secrets, tokens, and ATS credentials in Microsoft Azure Key Vault, access controls, and isolation of production data. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security; use the Services in a secure environment.

Where your data is processed. Talenry is operated by Syphon Labs LLP, based in India. Our systems run on Microsoft Azure in the United States. Your data is therefore transferred to and processed in the United States, and by our service providers in the countries where they operate (see Section 4). The data-protection laws of these countries may differ from those of your own.

International transfers. If you are in the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (supplemented by the UK Addendum or International Data Transfer Agreement where applicable) in our contracts with service providers, or, where a legal derogation applies, on your explicit consent or because the transfer is necessary to perform the contract you asked for (for example, submitting your application to an employer in another country). Contact admin@syphonlabs.com for more information about the safeguards used.

11. DO WE COLLECT INFORMATION FROM MINORS?

We do not knowingly collect data from or market to anyone under 18 (or the equivalent age of majority in your jurisdiction). If we learn we have collected such data, we will deactivate the account and delete it promptly. Contact admin@syphonlabs.com if you believe this has occurred.

12. WHAT ARE YOUR PRIVACY RIGHTS?

Depending on your location (EEA, UK, Switzerland, Canada, various US states, India, and others), you may have rights to access, correct, delete, restrict, or port your personal information; to object to processing; to withdraw consent at any time; and not to be subject to solely automated decisions with legal or similarly significant effects. If such a decision is made, we will tell you, explain the main factors, and offer human review. Note that Talenry's automated application submission acts on your instructions; you choose what is applied to, and the review settings in the product let you approve or stop it. To exercise rights: syphonlabs.com/contact or admin@syphonlabs.com. EEA/UK/Swiss users may also complain to their data-protection authority. You can review, update, or delete your data in your account settings, or request an export (see Section 18).

13. DO-NOT-TRACK AND GLOBAL PRIVACY CONTROL

No uniform Do Not Track standard exists, so we do not respond to DNT browser signals. California law requires us to say so. The Talenry app honours the Global Privacy Control signal: if your browser sends it, analytics stays off. On syphonlabs.com, use the cookie banner or the cookie preferences link in the footer to accept or reject non-essential cookies.

14. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In short: residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with comprehensive privacy laws have rights of access, correction, deletion, portability, and opt-out.

Categories of personal information we collect (last 12 months)

CategoryExamplesCollected
A. IdentifiersName, email, IP address, account IDYES
B. Personal information (CA Customer Records)Name, contact info, education, employment historyYES
C. Protected classification characteristicsRace, gender, veteran status, etc.Only if you voluntarily provide them (e.g., in resumes or self-identification questions you choose to answer)
D. Commercial informationTransactions, subscriptionsYES
E. Biometric informationFingerprints, voiceprintsNO
F. Internet / network activityUsage of the Services, Copilot reliability eventsYES
G. Geolocation dataApproximate location derived from IP (server logs; mobile analytics)YES
H. Audio, visual, sensory infoInterview audio (streamed to our voice provider, not stored by us) and transcriptsYES (only if you use the AI interview feature)
I. Professional / employment infoWork history, roles, skills, applications submitted, work-authorization status you provideYES
J. Education informationSchools, degreesYES
K. InferencesAI-generated match scores, drafted answers, interview feedbackYES
L. Sensitive personal informationGovernment IDs, health, religionNO (but may appear in content you upload or answers you choose to provide)

We disclose personal information to service providers under written contracts, and to employers/ATS providers at your direction when you apply. We do not use personal information to train AI models. We have not sold personal information and will not sell it. Your state-law rights (know, access, correct, delete, portability, opt out of targeted advertising/profiling, limit sensitive-data use, non-discrimination, and state-specific rights such as third-party disclosure lists) can be exercised via syphonlabs.com/contact or admin@syphonlabs.com; authorized agents may act with valid proof of authorization. We verify requests against information we hold and may ask for more identification. Appeals: email admin@syphonlabs.com with subject "Privacy Rights Appeal"; if denied, you may contact your state attorney general. California "Shine The Light" requests are honored as described in that statute.

15. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?

India: we process personal data in accordance with the Digital Personal Data Protection Act, 2023. You may request access, correction, or erasure, withdraw consent, and file grievances with our Grievance Officer at admin@syphonlabs.com (attn: Grievance Officer, Syphon Labs LLP, Sarjapur road, Kaikondrahalli, Bangalore, Karnataka 560035); if unresolved, you may complain to the Data Protection Board of India.

Canada: we process personal information with your express or implied consent under PIPEDA and applicable provincial laws (including Quebec's Law 25); you may request access or correction, withdraw consent (subject to legal or contractual restrictions), and complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner (in Quebec, the Commission d'accès à l'information).

Brazil: we process personal data under the legal bases of the Lei Geral de Proteção de Dados (LGPD); you may request confirmation, access, correction, anonymization, portability, or deletion, and may complain to the ANPD.

Australia / New Zealand: this Notice satisfies the notice requirements of the Privacy Act 1988 (AU) and Privacy Act 2020 (NZ); you may request access or correction, and may complain to the OAIC or the NZ Privacy Commissioner respectively.

South Africa: you may request access or correction, and may contact the Information Regulator (enquiries@inforegulator.org.za) with POPIA complaints.

Other countries: where your local law grants you rights over your personal information, you can exercise them by contacting admin@syphonlabs.com, and we will honor them as the law requires.

16. DO WE MAKE UPDATES TO THIS NOTICE?

Yes, as needed to stay compliant with relevant laws and to reflect changes in the Services. The "Last updated" date at the top will change, and material changes will be prominently posted or notified directly.

17. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

Email admin@syphonlabs.com (privacy-specific requests: subject line "Privacy Request"), or write to:

Syphon Labs LLP
Sarjapur road, Kaikondrahalli
Bangalore, Karnataka 560035
India

18. HOW CAN YOU REVIEW, UPDATE, EXPORT, OR DELETE YOUR DATA?

You can review and update your profile in your account settings. To get a copy of your data, email admin@syphonlabs.com with the subject "Data export" and we will send it to you. To delete your account, use "Delete account" in Settings on the web or in the mobile app, or contact us.

Deletion is immediate and irreversible. It removes your profile, applications, documents, connected-account tokens, and all database records, and deletes your resume and document files from storage. Deletion also removes your analytics profile and events at PostHog, any accounts we created for you on employer systems, your stored browser session state, and any reliability snapshots. Copies in backups expire within 14 days and server logs within 90 days. Records we must keep for fraud prevention, dispute resolution, or legal compliance are retained only as long as those purposes require.

Deletion does not affect applications already submitted to employers, which they hold under their own policies. You can also submit a request at https://www.syphonlabs.com/contact.