PRIVACY POLICY
Last updated
This Privacy Notice for Syphon Labs LLP ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our websites at https://www.syphonlabs.com/, https://talenry.com/, or any website of ours that links to this Privacy Notice
- Use our products: Draft (AI resume and job-search workspace), Daisy Recruiter (AI recruitment tools), and Talenry (an AI career agent that finds matching jobs and prepares, fills, and submits job applications on your behalf, at your direction)
- Install our browser extensions, including the Draft extension and Talenry Copilot, or our Talenry mobile app for iOS and Android
- Engage with us in other related ways, including any sales, marketing, or events
Talenry, Draft, and Daisy Recruiter are products owned and operated by Syphon Labs LLP, a company based in India, which is the data controller responsible for your personal information under this Notice. Our systems run on Microsoft Azure in the United States (see Section 10).
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, contact us at admin@syphonlabs.com.
SUMMARY OF KEY POINTS
What do we process? Account details, your career profile (resume, work and education history, answers to application questions), payment data, and usage data. We also keep a record of every job application we submit for you and, if you choose to have Talenry send outreach from your Gmail, a copy of each email we send.
The heart of Talenry: you give us your career data precisely so we can act on it for you: match you to jobs, tailor your resume and cover letters, generate application answers, fill and submit applications to employers, and, if you choose, send outreach to recruiters from your own Gmail address. If you are not comfortable with your data powering those actions, do not use Talenry.
AI training: we do not use your resumes, documents, messages, or interactions to train or fine-tune AI models. Our AI provider, Microsoft Azure OpenAI, runs inside our own Azure tenant and does not train on your data. If this ever changes we will tell you and ask for your consent first.
Where your data lives: on Microsoft Azure in the United States, plus the service providers named in Section 4.
Analytics: the Talenry app, extension, and mobile app use PostHog to understand feature usage and reliability. Our marketing website syphonlabs.com uses Google Analytics, only after you accept cookies. Analytics never includes your resume text, answers, or form values, is not used for advertising, and is not sold.
Emails: we send account and security emails, plus optional product emails such as your weekly job matches. You can turn the optional ones off in Settings or with the unsubscribe link in each email. We do not send marketing emails, and we do not track whether you open or click our emails. See Section 8I.
Sensitive data: we do not intentionally request it, but resumes, applications, and voluntary self-identification questions may contain it; we process it only as needed to provide the Services.
Selling data: we do not sell your personal information. We do not currently offer any feature that shows your profile to recruiters or employers; if we ever do, it will be opt-in and we will ask you first.
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
In short: we collect the information you give us, the information needed to act on your behalf, and technical usage data.
Personal information you disclose to us
- Names, email addresses, passwords, phone numbers, contact preferences
- Mailing/postal addresses (some employer application systems, such as Workday, require a full postal address)
- Job titles, target role, work history, education history, skills, salary expectations, your home city and country, whether you are open to relocating, and any LinkedIn, GitHub, or portfolio links you add
- Resumes, cover letters, portfolios, and any documents you upload
- Visa / work-authorization status where you provide it (used, for example, to filter for E-Verify-enrolled employers)
- Answers to job-application questions, both answers you type and answers our AI drafts for you
- Voluntary self-identification responses (e.g., gender, veteran status, disability status) only if you choose to provide them for inclusion in applications; we never fabricate these
- Billing information, processed by our payment providers (see "Payment data" below); we never receive or store your full card number
Information created or collected when Talenry acts for you
- Applications we submit: a record of each application, including the employer, role, the exact field values submitted, generated documents, timestamps, and outcome status. We keep a copy of your profile as it was at the time of each attempt so your history stays accurate, and we cache your answers so repeated questions can reuse them.
- ATS accounts: some employer application systems (e.g., Workday, iCIMS) require an account. With your use of auto-apply you direct us to create one for you using your email address and a password we generate. The credentials are stored encrypted in Microsoft Azure Key Vault and are deleted when you delete your account.
- Sent outreach emails (only if you choose "Talenry sends it"): a copy of each recruiter email sent from your address, its recipient, its Gmail message ID, and when it was scheduled and sent, stored with the application. See Section 8A.
- Mock-interview records: the transcript, our AI's feedback and scores, and the job description used, stored with your account. Talenry never receives or stores your audio. See Section 8D.
- Recruiter contacts: business contact details (name, title, work email, company) of recruiters we look up for your outreach, saved to your private contacts.
- Push notification tokens: if you use our mobile app and allow notifications, a device push token.
- Reliability snapshots: when an automated application fails, we save the filled form (as HTML), a full-page screenshot, and a redacted summary to diagnose the failure. These contain the information that was on the form (name, contact details, self-identification answers). They are deleted automatically after 14 days, or immediately when you delete your account.
- Copilot reliability events: a small diagnostic record each time you click Fill in the Talenry Copilot extension. It contains no form content. See Section 8B.
- Browser session state: our cloud-browser provider keeps site cookies from your automated sessions between applications so later submissions work better. See Section 8C.
Information automatically collected
Server logs. Our servers record standard request logs (time, endpoint, status, IP address, browser details) to run and secure the Services. Logs are kept for 90 days.
Last active. We record when you last opened Talenry, at most once an hour. We use it only to decide whether to send you the reminder email described in Section 8I, and it is deleted with your account.
Location for pricing. We use your approximate location, derived from your IP address, to show prices in US dollars or, in India, in Indian rupees, and to offer the payment provider available where you are.
Usage analytics (PostHog). The Talenry web app, mobile app, Copilot extension, and our servers send usage events to PostHog, our product-analytics provider. Events are linked to your account ID and email and describe things like the feature used, screens viewed, buttons tapped (never the text you type), your plan, sign-up and sign-in, auto-apply outcomes, and Copilot fill results (the job site's hostname and field counts). Analytics never includes resume text, application answers, or form values. In the web app, analytics runs only after you accept it, and we send events without your IP address. In the mobile app, events currently include your IP address, from which PostHog may derive an approximate location; you can turn mobile analytics off in Settings. Events sent by our servers carry no IP address. Session replay, surveys, and heatmaps are switched off.
Website analytics (syphonlabs.com). Our marketing website uses Google Analytics to measure traffic and performance. It runs only after you accept analytics cookies in the banner, and you can change your choice at any time through the cookie preferences link in the footer.
We also use cookies and similar technologies; see our Cookie Notice and Section 5.
Payment data
Payments are processed by our payment providers: PayPal and, for payments in India, Razorpay. When you pay, the information needed to complete the transaction (your name, email address, billing details, and payment method) is shared with the provider handling your payment, which processes it under its own privacy policy. Your card details are handled by the provider; Talenry never receives or stores your full card number. For each payment we keep the amount, the date, what it paid for, and the provider's transaction ID. We do not keep the name or email address that PayPal or Razorpay include in their payment notifications. Checkout pages load the provider's script, which sets its own cookies.
2. HOW DO WE PROCESS YOUR INFORMATION?
In short: to run your job search for you, to run and improve the Services, to communicate with you, for security, and to comply with law.
- Account management — create and secure your account, authenticate you (email and password with email verification, or Google sign-in), and send you account and security emails (see Section 8I).
- Job matching — we compute AI representations (embeddings) of your profile and of job listings to rank roles by fit. We also use your home city and country, and whether you are open to relocating, to decide where Talenry looks for jobs and applies for you: your own city plus remote roles if you are not open to relocating, or anywhere in your country plus remote roles if you are.
- Application preparation — tailor your resume and cover letter to a role; draft answers to application questions from your profile and your previously approved answers.
- Application submission (auto-apply) — at your direction, fill and submit applications to employers' systems on your behalf. This includes operating cloud browser sessions, routing traffic through proxies, completing anti-bot challenges, and creating required ATS accounts for you. See Section 8C.
- Recruiter outreach — where you enable it, identify a relevant recruiter at a company you applied to and write an introduction; then either hand it to you to send ("I send it") or send it from your Gmail address 30 minutes after it is written unless you edit or stop it ("Talenry sends it"), whichever you have chosen in Settings. See Sections 8A and 8E.
- AI mock interviews — run voice interviews and generate feedback and scores.
- Reliability and diagnostics — diagnose failed applications (reliability snapshots), measure which application systems the Copilot extension works on (reliability events), and troubleshoot automated sessions (cloud-browser session recordings).
- Pricing and payments — show prices in US dollars or Indian rupees, based on your approximate location derived from your IP address, and take payment through PayPal or, in India, Razorpay.
- Analytics — understand how the Services are used so we can operate, secure, and improve them. Not used for advertising, not sold, and not used to train AI models.
- Notifications — send you emails about your account, your applications, and your job matches (see Section 8I), and push notifications about your applications (mobile app, if enabled).
- Support and feedback, security and fraud prevention (including making sure each email address receives only one free trial), and legal compliance.
We do not use your resumes, documents, messages, or interactions to train or fine-tune AI models. See Section 6.
3. WHAT LEGAL BASES DO WE RELY ON?
In short: consent, contract, legitimate interests, legal obligations, and vital interests, as applicable in your jurisdiction (GDPR/UK GDPR, Canadian law, and others).
If you are in the EU/UK: we process your information with your consent (for example, when you connect Gmail and choose "Talenry sends it," or accept analytics; you can withdraw consent at any time), for performance of a contract (most of Talenry's processing exists to deliver the service you asked for: applying to jobs on your behalf), for our legitimate interests (securing the Services, diagnosing failures, and understanding usage where consent is not required, balanced against your rights), to meet legal obligations, and to protect vital interests. If you are in Canada, we process with express or implied consent, with limited legal exceptions. We send account, security, and billing emails because they are needed to provide the Services you signed up for (contract). We send optional product emails, such as your weekly job matches and reminders, under our legitimate interest in helping you get value from the Services, and you can turn each one off at any time.
6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
In short: yes, AI is the core of our products. We do not train AI models on your data.
Our AI-powered features ("AI Products") include: job matching and ranking; resume and cover-letter generation and tailoring; application-answer generation; the auto-apply agent that fills and submits applications; recruiter-outreach drafting; AI insights; and AI mock interviews.
Language and embedding models run on Microsoft Azure OpenAI inside Talenry's own Azure tenant; Microsoft does not train on the data. Resume OCR uses Azure AI Document Intelligence. Mock-interview voice is provided by ElevenLabs. The inputs these providers see are your resume text, profile, job descriptions, application questions, interview transcripts, and chat messages, as described in Section 4. You must not use the AI Products in ways that violate an AI provider's policies.
AI training. We do not use your resumes, documents, messages, or interactions to train or fine-tune AI models. Our AI provider does not train on your data. If this ever changes we will tell you and ask for your consent first. Data obtained through Google APIs (including your connected Gmail mailbox) is never used to develop, improve, or train AI or machine-learning models, consistent with the Google API Services User Data Policy.
AI request monitoring. We may use Langfuse to monitor AI requests. It is currently switched off. If enabled, it receives metadata only (model, timing, token counts, hashed fingerprints), never prompt or response text.
8A. GOOGLE API SERVICES & GMAIL DATA (TALENRY)
Talenry's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What Talenry connects to Gmail for. One thing: sending recruiter-outreach emails from your own Gmail address, when you have turned that on. Talenry does not read your inbox, does not read or label your messages, and does not access your contacts or drafts.
Scopes. When you connect Gmail on the web, we request openid, email, profile, and https://www.googleapis.com/auth/gmail.send. gmail.send is the only Gmail scope we request. It allows Talenry to send email on your behalf and nothing else; it does not permit reading your mailbox. The mobile app's Google sign-in requests basic identity only and never touches Gmail.
How sending works.
- Two controls, both yours. In Settings under Recruiter outreach, "Write recruiter emails" decides whether Talenry composes anything at all. "Who sends the email" is a choice between "I send it" and "Talenry sends it." "I send it" is the default: Talenry hands you every email to send yourself from your own mail app, so nothing is sent through Gmail. You can change either setting at any time.
- What "Talenry sends it" does. You confirm this choice before it takes effect. After you apply to a job, Talenry writes the first email to the recruiter and sends it from your connected Gmail address 30 minutes later. During those 30 minutes the email is shown in Outreach, where you can edit it (which restarts the 30 minutes), send it immediately, or stop it. If you do nothing, it is sent without further approval from you. An email is sent this way only when you applied within the previous two hours; otherwise it waits for your approval.
- What is never sent automatically. Follow-up emails, emails you ask Talenry to write by hand, and any email that existed before you chose "Talenry sends it" are sent only when you approve them. Talenry cannot see replies, so it never follows up on its own.
- Limits and stopping. Talenry sends at most 20 recruiter emails from your Gmail in any 24 hours. Switching to "I send it," turning "Write recruiter emails" off, or disconnecting Gmail immediately stops every email still waiting to be sent.
- Who receives it. A recruiter or hiring contact at a company you have applied to, found through our business-contact providers as described in Section 8E.
- What the email contains. An introduction stating your interest in joining the company, your name, the role you applied for, the company name, your LinkedIn link if you have added one, and your resume and cover letter attached as PDFs.
- What we keep. A copy of each sent email (its contents, recipient, Gmail message ID, and when it was scheduled and sent) is stored with the application record in your account so you can see what was sent and to whom. It is deleted when you delete your account.
- Daily summary. On any day Talenry sends recruiter emails from your Gmail, we email you one summary at your account address listing them: the recruiter's name and company, the job, and when each was sent. It comes from noreply@talenry.com, not from your Gmail. You can turn it off in Settings under Notifications ("Recruiter emails sent") or with the unsubscribe link in the email.
Token storage. Your Gmail refresh token is stored in Microsoft Azure Key Vault, encrypted at rest, as a separate secret per user. It is used only to send the emails described above.
We do not: read your mailbox; use Gmail data for advertising; sell Gmail data; use Gmail data to train AI models; or allow humans to access your Gmail account except with your explicit consent for support, for security and abuse investigation, or where required by law. You can disconnect Gmail at any time in Settings, which removes our token, revokes Talenry's access in your Google account, and stops any email still waiting to be sent. You can also review or revoke access at myaccount.google.com/permissions.
8B. BROWSER EXTENSIONS
Draft extension
When you explicitly click "Save," the Draft extension extracts the job title, company, location, description, and URL of the active job posting and syncs it to your Draft dashboard for resume tailoring and career insights. It stores a secure access token locally to maintain your session and may collect technical logs for stability. Its broad site access is used solely to detect and extract job listings when you trigger a save; we do not track your browsing history and do not collect data from pages you do not save.
Talenry Copilot extension
Talenry Copilot helps you complete job applications that Talenry's cloud agent could not finish (for example, forms behind strict anti-bot checks). It is distributed through the Chrome Web Store and works on your command:
- Access. At install it can access only Talenry's own sites (talenry.com, app.talenry.com, and api.talenry.com). It asks for access to a job site the first time you use it there, or to all sites if you choose "Enable on every job site." You can revoke either at any time at
chrome://extensions. - What it does when you click Fill. It fetches your profile, generated answers, resume, and cover letter from talenry.com over HTTPS and fills the form in front of you. It never clicks Submit. You review, complete anything missing, solve any captcha, and submit yourself.
- Reading the form. It reads the values already in the form so it does not overwrite what you typed. Those values stay in your browser and are never sent anywhere.
- Sign-in pages. It refuses to fill pages whose address indicates sign-in, registration, or password reset, and never fills password fields anywhere.
- Job understanding (Save, Match, Draft answers). When you ask it to, it sends the posting's title, company, location, description text, and page address to talenry.com so our AI can parse the role, score the match against your profile, and draft answers. On pages without structured job data the description may be the page's visible text, up to 20,000 characters. When drafting answers, only the unanswered questions' text and options are sent. No screenshot or page HTML is ever sent.
- Matching on panel open. When you open the panel on an application page, it asks talenry.com for your fill data using that page's address so we can match it to the right application. This is not added to analytics.
- Confirmation detection. After a fill you started, it checks locally whether the page is a confirmation page and asks talenry.com to mark the application as applied. If the application is not already in your dashboard, the page address and title are sent to create it. No page content is sent.
- Badge and job-page detection. Runs entirely in your browser and sends nothing.
- Linking a board job to the employer's page. When you go from a job-board posting (such as LinkedIn) to the employer's application page in the same tab, the Copilot sends both page addresses to talenry.com so the application page is recognized as the job you saved. Talenry keeps the link only when the posting is a job you saved; otherwise nothing is stored. To do this, the extension remembers each tab's last page address for the current browser session only, and forgets it when the tab closes.
- Signing in with Google. If you choose Continue with Google, the Copilot opens Google's own sign-in page and receives your name and email address from Google, which it sends to talenry.com in exchange for a session. It asks Google for nothing else. It signs in only to an existing Talenry account; it never creates one.
- Reliability event. Each time you click Fill, the Copilot sends Talenry a small reliability event so we can see which application systems work and which do not. It contains the website's hostname (never the page address), whether the fill succeeded, a fixed error category if it failed, how many fields were filled, skipped, or left for you, the number of frames on the page, how long the fill took, and the extension version. It never contains field names, the values on the form, or anything about your browser or device. Our servers forward these events, linked to your account, to our analytics provider PostHog. The extension itself contains no analytics code and never contacts PostHog. You can turn off reliability events in the Copilot settings; the extension works the same either way.
- Cookies. It reads only Talenry's own session cookie, on app.talenry.com and api.talenry.com. It reads no cookies on any other site and sets no cookies.
- Storage. Chrome's local extension storage holds your Talenry session token, whether you signed out of the Copilot (so it stays signed out), whether you turned off reliability events, and your answer to the all-sites prompt. For the current browser session only, it also holds which saved application each tab is working on, the IDs of tabs awaiting a confirmation page, and each tab's last page address (see above). Nothing syncs through your Google account.
- No copy of your profile at rest. Your profile, answers, and resume are held in memory while the panel is open and discarded when it closes. The session token is removed when you sign out. Uninstalling removes all extension storage.
- No other code. No crash reporting, advertising, or third-party analytics; no remote scripts or fonts. It communicates only with talenry.com, and with Google's sign-in page when you choose Continue with Google.
We do not sell extension data, do not use it for advertising, and do not use it for creditworthiness or lending. We do not transfer it to third parties other than the employer page you are actively filling and PostHog, which receives only the reliability event described above.
8C. AUTOMATED APPLICATIONS (AUTO-APPLY)
When you enable auto-apply or approve an application, Talenry submits it for you in a cloud browser operated by Browserbase in the United States (Oregon). To make submissions work reliably, the browser's traffic exits through a residential proxy matched to the country in your profile (United States by default), and Browserbase keeps your browser session state (site cookies) between applications.
- Session recordings. Browserbase records each automated session (video replay, console logs, and network traffic) for troubleshooting. Because the session includes the form as it is filled, the recording contains the information on the form. Browserbase deletes recordings after 30 days.
- Anti-bot challenges. Captchas may be solved by Browserbase's own solver, or by 2Captcha or CapSolver (integrated but not currently in use). They receive the challenge and page address only, never your profile data.
- ATS accounts. Where an employer's system requires an account, we create one with a password we generate and store it encrypted in Azure Key Vault. It is deleted when you delete your account.
- Reliability snapshots. When an application fails, we save the filled form (HTML), a full-page screenshot, and a redacted summary to diagnose the failure. They contain the information on the form. They are deleted automatically after 14 days, or immediately when you delete your account.
- Your history. We keep a copy of your profile as it was at each attempt with the application record, and we cache your answers so repeated questions reuse them.
You can pause auto-apply or stop using the Services at any time; doing so does not retract applications already submitted to employers.
8D. AI MOCK INTERVIEWS
Your microphone audio streams directly from your device to ElevenLabs, which runs the interview voice; on mobile, LiveKit carries that audio for ElevenLabs. Talenry does not receive or store audio. To run the interview, ElevenLabs receives your name, the role, the company, the job description (up to 4,000 characters), and a summary of your profile (up to 4,000 characters).
ElevenLabs does not record or store your audio. It keeps the interview transcript, together with the name, profile summary, and job description we sent it, for 30 days so we can investigate a broken interview, then deletes them. We store the transcript, our AI's feedback and scores, and the job description with your account. Feedback and scores are practice signals, not assessments used by employers.
8E. RECRUITER OUTREACH AND CONTACTS
Finding a recruiter. Where you enable outreach, we send the employer's company name or domain, and job-title filters, to Hunter.io or Apollo to find a relevant recruiter. Nothing about you is sent. The results are stored as contacts in your account.
Sending outreach. Under "Who sends the email" in Settings you choose who sends: with "I send it" (the default), every email is handed to you to send yourself and Talenry does not use Gmail; with "Talenry sends it," which you confirm before it takes effect, Talenry sends the first email to a recruiter from your own Gmail address 30 minutes after you apply, unless you edit, send, or stop it in Outreach during that time. Follow-up emails are never sent automatically: each is sent only when you approve it. Either way the email contains an introduction stating your interest in joining the company, your name, the role, the company, your LinkedIn link if added, and your resume and cover letter as PDFs. When Talenry sends it, we keep a copy with the application record. You can change either setting, or turn off "Write recruiter emails" entirely, at any time. See Section 8A.
Recruiter discovery. We do not currently offer any feature that indexes your profile or makes it visible or searchable to recruiters or employers. We may in future offer an opt-in recruiter discovery feature; if we do, we will update this Notice and ask for your consent before enabling it.
8F. MOBILE APP
The Talenry app for iOS and Android uses the same account and backend as the web app. It requests microphone access only for live mock interviews. It does not access your contacts, location, camera, or photos. It uses PostHog for usage analytics (app open and close, screens viewed, taps without the text you type, linked to your account ID and email; events include your IP address) and contains no advertising SDKs. You can turn analytics off in Settings. Push notifications are optional and delivered through Expo's push service, which receives your device token and the notification text. Your session token and preferences are kept in the device's secure storage (Keychain or Keystore) and removed when you sign out or uninstall the app.
8G. AI ASSISTANTS YOU CONNECT
You can connect an AI assistant such as Claude or Codex to Talenry with our connector. It runs on your own device with your Talenry credential and, at your direction, can read your profile, jobs, and applications and take actions you allow, including updating your profile, submitting an application through auto-apply, and preparing outreach you approve. We do not host the connector, and we do not share your credential with the assistant's provider. The assistant provider processes what it accesses under its own privacy policy.
8H. INFORMATION ABOUT PEOPLE WHO ARE NOT OUR USERS
- Recruiters. To prepare outreach for your application, we obtain a relevant recruiter's business-contact details (name, title, work email) from business-contact data providers. We process this business contact information under our legitimate interest in delivering the outreach you requested. A recruiter may contact admin@syphonlabs.com to have their details removed from our records.
- Referrals. If you use referral features and enter a friend's name or email address, those details are used to provide the referral feature. Only refer people you know and who would want to hear from you.
8I. EMAILS WE SEND YOU
We send email from noreply@talenry.com through Microsoft Azure Communication Services. To reply or ask a question, write to admin@syphonlabs.com.
Always sent. These are needed to run and secure your account:
- Email verification and password reset.
- A welcome email when you finish setting up your profile.
- Security notices when your password changes, when Google sign-in is added to your account, and when your contact email address changes (this one is sent to your previous address).
- One confirmation after you delete your account.
- Usage notices when you reach 80% and 100% of a monthly limit on your plan.
- Billing emails, once payments are available: receipts, and notices when a payment fails or your plan changes or ends.
Optional, on by default. You can turn any of these off in Settings under Notifications, or with the one-click unsubscribe link at the bottom of each email:
- Waiting for you — a daily email when applications need your approval, an answer, or a sign-in.
- Application sent — an email when Talenry submits an application for you.
- Recruiter emails sent — a daily summary of the recruiter emails Talenry sent from your Gmail.
- Weekly best matches — a Monday email with your strongest new job matches.
- Tips and reminders — a guide to using Talenry after you finish setup, up to two reminders if your profile is missing details that applications need, and one note if you have not used Talenry for 14 days.
What these emails use. Your name, email address, profile details, job matches, and application activity.
No marketing, no tracking. We do not send marketing emails. We do not track whether you open our emails or click their links: they contain no tracking pixels, and links are not rewritten. The Talenry logo in each email loads from our website, and like any request to our website, that request is recorded in our standard server logs (see Section 1).
Our send record. We keep a record of which of these emails we have sent you and when (the kind of email and the date, not its contents), so you never receive the same one twice. It is deleted with your account.
9. HOW LONG DO WE KEEP YOUR INFORMATION?
As long as needed for the purposes above, typically for as long as you have an account. The table below lists the specific periods. When there is no ongoing legitimate business need, we delete or anonymize your information, or isolate it from processing until deletion is possible (e.g., backups).
| Data | Retention |
|---|---|
| Account, profile, applications, documents, contacts, interview transcripts | Life of the account |
| Sent outreach emails (copy, recipient, Gmail message ID) | Life of the account |
| Record of emails we sent you (kind and date) | Life of the account |
| When you last opened Talenry | Life of the account |
| Credit history (credits granted, spent, and refunded, and what each was spent on) | Life of the account |
| Payment records (amount, date, plan or credit pack, the payment provider's transaction ID; unlinked from you when you delete your account) | As long as tax and accounting law requires |
| Free-trial fingerprint (a one-way, keyed fingerprint of the email address that received a free trial; never the address itself) | Kept after account deletion, to prevent repeat free trials |
| Reliability snapshots | 14 days, or immediately on account deletion |
| Analytics events and profile (PostHog) | Up to 7 years (our plan's retention setting); deleted when you delete your account |
| Interview transcript and context at ElevenLabs | 30 days, then deleted; audio never stored |
| Cloud-browser session recordings (Browserbase) | 30 days |
| Cloud-browser session state (site cookies) | Until you delete your account |
| ATS accounts created for you | Until you delete your account |
| Server logs | 90 days |
| Database backups | 14 days |
| Deleted files (storage soft-delete) | 14 days |
| AI call records (model, tokens, cost; unlinked from you on deletion) | Kept for accounting |
10. HOW DO WE KEEP YOUR INFORMATION SAFE, AND WHERE IS IT PROCESSED?
We use appropriate technical and organizational measures: encryption in transit (TLS) everywhere, encrypted storage of secrets, tokens, and ATS credentials in Microsoft Azure Key Vault, access controls, and isolation of production data. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security; use the Services in a secure environment.
Where your data is processed. Talenry is operated by Syphon Labs LLP, based in India. Our systems run on Microsoft Azure in the United States. Your data is therefore transferred to and processed in the United States, and by our service providers in the countries where they operate (see Section 4). The data-protection laws of these countries may differ from those of your own.
International transfers. If you are in the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (supplemented by the UK Addendum or International Data Transfer Agreement where applicable) in our contracts with service providers, or, where a legal derogation applies, on your explicit consent or because the transfer is necessary to perform the contract you asked for (for example, submitting your application to an employer in another country). Contact admin@syphonlabs.com for more information about the safeguards used.
11. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly collect data from or market to anyone under 18 (or the equivalent age of majority in your jurisdiction). If we learn we have collected such data, we will deactivate the account and delete it promptly. Contact admin@syphonlabs.com if you believe this has occurred.
12. WHAT ARE YOUR PRIVACY RIGHTS?
Depending on your location (EEA, UK, Switzerland, Canada, various US states, India, and others), you may have rights to access, correct, delete, restrict, or port your personal information; to object to processing; to withdraw consent at any time; and not to be subject to solely automated decisions with legal or similarly significant effects. If such a decision is made, we will tell you, explain the main factors, and offer human review. Note that Talenry's automated application submission acts on your instructions; you choose what is applied to, and the review settings in the product let you approve or stop it. To exercise rights: syphonlabs.com/contact or admin@syphonlabs.com. EEA/UK/Swiss users may also complain to their data-protection authority. You can review, update, or delete your data in your account settings, or request an export (see Section 18).
13. DO-NOT-TRACK AND GLOBAL PRIVACY CONTROL
No uniform Do Not Track standard exists, so we do not respond to DNT browser signals. California law requires us to say so. The Talenry app honors the Global Privacy Control signal: if your browser sends it, analytics stays off. On syphonlabs.com, use the cookie banner or the cookie preferences link in the footer to accept or reject non-essential cookies.
14. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In short: residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with comprehensive privacy laws have rights of access, correction, deletion, portability, and opt-out.
Categories of personal information we collect (last 12 months)
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email, IP address, account ID | YES |
| B. Personal information (CA Customer Records) | Name, contact info, education, employment history | YES |
| C. Protected classification characteristics | Race, gender, veteran status, etc. | Only if you voluntarily provide them (e.g., in resumes or self-identification questions you choose to answer) |
| D. Commercial information | Transactions, subscriptions | YES |
| E. Biometric information | Fingerprints, voiceprints | NO |
| F. Internet / network activity | Usage of the Services, Copilot reliability events, when you last opened Talenry | YES |
| G. Geolocation data | Approximate location derived from IP (server logs; mobile analytics; choosing the currency for prices) | YES |
| H. Audio, visual, sensory info | Interview audio (streamed to our voice provider, not stored by us) and transcripts | YES (only if you use the AI interview feature) |
| I. Professional / employment info | Work history, roles, skills, applications submitted, work-authorization status you provide | YES |
| J. Education information | Schools, degrees | YES |
| K. Inferences | AI-generated match scores, drafted answers, interview feedback | YES |
| L. Sensitive personal information | Government IDs, health, religion | NO (but may appear in content you upload or answers you choose to provide) |
We disclose personal information to service providers under written contracts, and to employers/ATS providers at your direction when you apply. We do not use personal information to train AI models. We have not sold personal information and will not sell it. Your state-law rights (know, access, correct, delete, portability, opt out of targeted advertising/profiling, limit sensitive-data use, non-discrimination, and state-specific rights such as third-party disclosure lists) can be exercised via syphonlabs.com/contact or admin@syphonlabs.com; authorized agents may act with valid proof of authorization. We verify requests against information we hold and may ask for more identification. Appeals: email admin@syphonlabs.com with subject "Privacy Rights Appeal"; if denied, you may contact your state attorney general. California "Shine The Light" requests are honored as described in that statute.
15. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
India: we process personal data in accordance with the Digital Personal Data Protection Act, 2023. You may request access, correction, or erasure, withdraw consent, and file grievances with our Grievance Officer at admin@syphonlabs.com (attn: Grievance Officer, Syphon Labs LLP, Sarjapur road, Kaikondrahalli, Bangalore, Karnataka 560035); if unresolved, you may complain to the Data Protection Board of India.
Canada: we process personal information with your express or implied consent under PIPEDA and applicable provincial laws (including Quebec's Law 25); you may request access or correction, withdraw consent (subject to legal or contractual restrictions), and complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner (in Quebec, the Commission d'accès à l'information).
Brazil: we process personal data under the legal bases of the Lei Geral de Proteção de Dados (LGPD); you may request confirmation, access, correction, anonymization, portability, or deletion, and may complain to the ANPD.
Australia / New Zealand: this Notice satisfies the notice requirements of the Privacy Act 1988 (AU) and Privacy Act 2020 (NZ); you may request access or correction, and may complain to the OAIC or the NZ Privacy Commissioner respectively.
South Africa: you may request access or correction, and may contact the Information Regulator (enquiries@inforegulator.org.za) with POPIA complaints.
Other countries: where your local law grants you rights over your personal information, you can exercise them by contacting admin@syphonlabs.com, and we will honor them as the law requires.
16. DO WE MAKE UPDATES TO THIS NOTICE?
Yes, as needed to stay compliant with relevant laws and to reflect changes in the Services. The "Last updated" date at the top will change, and material changes will be prominently posted or notified directly.
17. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
Email admin@syphonlabs.com (privacy-specific requests: subject line "Privacy Request"), or write to:
Syphon Labs LLP
Sarjapur road, Kaikondrahalli
Bangalore, Karnataka 560035
India
18. HOW CAN YOU REVIEW, UPDATE, EXPORT, OR DELETE YOUR DATA?
You can review and update your profile in your account settings. To get a copy of your data, email admin@syphonlabs.com with the subject "Data export" and we will send it to you. To delete your account, use "Delete account" in Settings on the web or in the mobile app, or contact us.
Deletion is immediate and irreversible. After your account is deleted we send one confirmation email to the address that was on the account; we do not keep the address afterwards. If the account used a free trial, we keep a one-way fingerprint of its email address so the same address cannot start a second free trial. The fingerprint cannot be turned back into your address and is used for nothing else. It removes your profile, applications, documents, connected-account tokens, and all database records, and deletes your resume and document files from storage. Deletion also removes your analytics profile and events at PostHog, any accounts we created for you on employer systems, your stored browser session state, and any reliability snapshots. Copies in backups expire within 14 days and server logs within 90 days. Records we must keep for fraud prevention, dispute resolution, or legal compliance are retained only as long as those purposes require.
Deletion does not affect applications already submitted to employers, which they hold under their own policies. You can also submit a request at https://www.syphonlabs.com/contact.
7. SIGN-IN, SESSIONS, AND GOOGLE SIGN-IN
You can register with an email address and password (we send a verification email) or sign in with Google on the web, natively in the mobile app, or in the Talenry Copilot extension (which signs in only to an existing account; see Section 8B). We do not offer Apple sign-in or magic links. When you sign in with Google we receive basic profile information (name, email address, profile picture) and use it only as described in this Notice. Google sign-in in the mobile app and the Copilot requests basic identity only and never accesses Gmail. Connecting Gmail so Talenry can send outreach from your address is a separate, optional step on the web, covered in Section 8A.
Sessions last 7 days. Signing out clears the session cookie. We email you when your password changes, when Google sign-in is added to your account, and when your contact email changes, so you can act quickly if it was not you (see Section 8I).