Privacy Policy
1. Introduction & Overview
TalentOS ("we," "our," or "us") provides an executive career enablement platform and AI orchestration suite designed to help professionals track opportunities, tailor career documents, synthesize accomplishment narratives, and rehearse interviews.
We take your professional confidentiality seriously. This Privacy Policy outlines our transparent data handling practices, detailing how your personal data, career records, and voice inputs are collected, processed, secured, and retained when using TalentOS. It forms part of, and should be read together with, our Terms of Service.
TalentOS is a service operated by TalentOS Technologies Limited (NZBN: 9429053964885), a registered New Zealand company based in Auckland, New Zealand (in this policy, "we," "our," or "us"). We handle personal information in accordance with the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs, including Principle 3A regarding indirect collection from third-party sources), which serves as our primary privacy framework.
2. Changes to This Policy
This policy was last updated on 1 October 2026 (version 2026-10-01.5). We may update it from time to time. When we do, we will publish the updated policy on this page with a new version identifier and "Last Updated" date, record the change in the Revision History at the end of this policy, and, for significant changes, give you notice in the app before the change takes effect. Your continued use of the Service after the effective date constitutes acknowledgment of the revised policy.
3. The Data We Collect & Collection Sources (IPPs 1–3, 3A)
We collect and process the following categories of information to provide, maintain, and optimize the Service:
- Account & Identity Data (Direct & Indirect / IPP 3A): When you sign in with Google (through Firebase Authentication, our only sign-in method), we collect and store your verified email address, full name, profile avatar URL, and an internal unique identifier (
uid). - Career Profile & Master CV Data (Direct / IPP 2 & 3): Master resume/CV content, base cover letter templates, career trajectory goals, target salary/role preferences, and employment history inputted directly into your profile or uploaded as documents.
- Job Pipeline Data (Direct / IPP 2 & 3): Target company names, job titles, ingested or pasted job descriptions, recruitment stage notes, and tailored application materials.
- Accomplishment Stories (STAR Framework): Situations, Tasks, Actions, Results, and XYZ metrics synthesized into your personal narrative vault.
- Real-Time Voice Audio: Live microphone audio streams during Voice AI Interview Rehearsal and Question Drill sessions, streamed to Google's Gemini Live API (or, for typed-answer dictation, your browser's own speech recognition service), plus short on-device replay recordings kept only in your browser (see Section 5).
- Billing & Transaction Metadata (Indirect / IPP 3A): When you purchase an access pass, our Merchant of Record and payment processor (Dodo Payments) collects and processes your payment card details directly. TalentOS does not receive or store full card numbers; we receive only the transaction metadata we need (for example customer ID, pass type, payment status, and pass expiry date) via signed server webhooks.
- Technical & Security Data: Device metadata, browser type, approximate network location, IP address, and security logs. IP addresses are used for security operations such as rate limiting and abuse prevention: they are used in short-lived rate-limit counters, which are kept in server memory or stored in our database under a one-way hash rather than the raw IP address; stored counters are set to expire 1 hour after each rate-limit window and are then deleted automatically (usually within a day) and in our server request logs, which are kept for 30 days. Client-side telemetry redacts personal identifiers (emails and auth tokens) before log ingestion.
- Feedback & Public Posts: When you send feedback we store your message, rating, any screenshot you attach, your browser type and the page you sent it from, with your account email. We publish feedback on our website only if you tick the box allowing it, under the name you give (or "TalentOS beta user" if you give none), and you can ask us to remove it at any time. Feature ideas you choose to post to the Community Idea Board are shown to other signed-in users without your name or email.
- Beta Waitlist & Referral Codes: If you join the beta waitlist we store your email address, name and any note you add, so we can review your request. If you share a referral code, you can see a masked version of the email address of each person who joins with it (for example, j*@example.com), and they are linked to your code in our records.
- TalentOS Browser Extension (Optional): If you install the optional TalentOS Job Copilot extension, it reads a job posting page on a supported job site (such as LinkedIn, Seek, Indeed, Greenhouse, Lever, Ashby or Workday) only when you click to capture it. Captured job details are kept in the extension's local storage on your device until you import them into TalentOS, where they are saved to your job pipeline like any other job you add, and are then removed from the extension. The extension does not read your browsing history, other tabs, or pages you do not capture, and does not send data anywhere except your TalentOS account.
4. Artificial Intelligence & Zero Model Training Commitment
TalentOS uses Google Gemini large language models, through Google's paid Gemini API, to tailor documents, evaluate interview responses, and draft briefing memos.
Under those terms, Google keeps prompts and responses for 55 days solely to detect and prevent violations of its Prohibited Use Policy and for any required legal or regulatory disclosures. If Google's automated safety systems flag a prompt or response, authorised Google employees may review it. Google may store or cache this data transiently in any country where it or its agents have facilities (see Section 7).
5. Real-Time Voice Audio & Biometric Disclosures
When you use Voice AI Interview Rehearsal (/interviews), Question Drills (/coach), or embedded rehearsal sessions, TalentOS accesses your device microphone to capture live audio.
- Real-Time Streaming: Your microphone audio is sent directly from your browser, in real time over encrypted WebSockets, to Google's Gemini Live API to run the rehearsal conversation, transcribe your answers, and generate feedback on their content and structure.
- Question Drills also let you dictate a typed answer using your browser's built-in speech recognition. That audio is handled by your browser's own speech service, not by TalentOS or the Gemini Live API: Chrome sends it to Google, Edge to Microsoft and Safari to Apple, under that browser's own privacy terms. Only the resulting text reaches TalentOS. You can type your answer instead if you prefer not to use dictation.
- No Server-Side Audio Storage: TalentOS does not store your raw audio on its servers. Google processes live audio under the same Gemini API terms as other prompts, including the 55-day abuse-monitoring retention.
- On-Device Replay Recordings: So you can replay your own answers, a copy of each of your rehearsal turns is kept only in this browser's storage (IndexedDB). It never leaves your device, is deleted automatically after 7 days, and is removed immediately when you sign out or delete your account. Deleting a saved rehearsal also deletes its recordings.
- No Biometric Voiceprints (Biometric Processing Privacy Code 2025): We do not create, extract, or retain biometric identifiers, voiceprints, or voice geometry, and we do not use your voice to verify or identify you or to infer your emotions, personality, health, or other personal characteristics. Our features evaluate the content, structure, and pacing of your answers. New Zealand's Biometric Processing Privacy Code 2025 sets rules for using biometric information to verify or identify people or to infer their characteristics; TalentOS does not use your voice for any of those purposes.
- Derived Transcripts: Text transcripts and performance scorecards derived from a session are stored in your private vault and can be reviewed or deleted by you at any time.
6. Data Retention & Account Deletion
We keep personal information only for as long as we need it for the purposes described in this policy:
- Active Account Data: Your profile templates, active job pipeline, and STAR repository are securely retained in Google Cloud Firestore for as long as your account remains active to provide continuous service.
- Document Exports (Not Stored): PDF and Word documents you export from Document Studio are generated on demand and sent straight to your browser. We do not keep a copy of the exported file; the temporary working file is deleted once the download has been sent.
- Account Deletion: You can delete your account at any time via Settings. Doing so deletes your Firebase authentication profile and the content held in your account (profile, CVs, job pipeline, STAR stories, transcripts, and settings) from our active systems, and removes your details from records held outside your account, such as feedback you posted and billing event logs.
- Backups: Copies of deleted data can remain in our encrypted disaster-recovery backups until those backups expire: point-in-time recovery data after 7 days, daily database backups after 14 days, and database export archives after 90 days. Backups are kept only so we can recover the Service after an incident.
- Server Logs: Request and security logs, which include IP addresses, are kept for 30 days and then deleted automatically.
- Our Cloud Provider's Deletion: When we delete data, Google Cloud then deletes it from its own systems under its data processing terms, which allow Google up to 180 days to complete deletion. Separately, Google keeps Gemini API prompts and responses for up to 55 days for abuse monitoring (see Section 4).
- Records We Keep: Deleting your account does not delete records we need to keep: we keep records we are required by law to keep (such as tax and accounting records) and records we reasonably need to establish, exercise, or defend legal claims. We keep these only for as long as that purpose requires. Dodo Payments, as Merchant of Record, keeps its own transaction and invoice records under its own legal obligations.
7. Third-Party Sub-Processors, Payments & International Transfers
We share personal data with a limited set of sub-processors and service providers only to operate the Service. We do not sell your data.
- Google (Google Cloud, Firebase and the Gemini API): Sign-in (Firebase Authentication), our Firestore database and its backups, the Cloud Run servers that run TalentOS, server request logs, Cloud Text-to-Speech for spoken coach questions, Maps geocoding of job locations, and the Gemini API (document tailoring, evaluation, and live voice rehearsal). Your profile, documents and job data are stored in our Firestore database and backups in Google Cloud's Sydney, Australia region, where our servers also run. Sign-in (Firebase Authentication), which holds your email address, name and profile photo, is processed in the United States. Server request logs are kept in Google Cloud's global logging location, and Gemini API prompts and responses may be processed, stored transiently, or cached in any country where Google or its agents have facilities.
- Dodo Payments: Our Merchant of Record: Dodo sells passes to you, collects your payment card and billing details directly at checkout, and handles tax, invoices, and refunds. With your authorisation at checkout, we share your email address and account identifier with Dodo so a purchase can be linked to your account, and receive transaction metadata back. Dodo handles your payment information as an independent controller under its own privacy policy, and processes it outside New Zealand. TalentOS does not receive or store full card numbers.
- Google: Comparable Safeguards by Contract (IPP 12(1)(f)): Google processes personal information for us under the data processing terms for each service: the Cloud Data Processing Addendum (Firestore, Cloud Run, Cloud Logging, Cloud Text-to-Speech and Maps), the Firebase Data Processing and Security Terms (Firebase Authentication), and the Data Processing Addendum for Products Where Google is a Data Processor (the paid Gemini API). These contractually require Google to protect the information with safeguards comparable to those in the Privacy Act 2020.
- Dodo Payments: Your Express Authorisation (IPP 12(1)(a)): Before you check out, we tell you that Dodo Payments processes your email address and account ID outside New Zealand and may not be required to protect them in a way that, overall, provides safeguards comparable to those in the Privacy Act 2020. You authorise that disclosure by continuing to checkout, and we record when you did so. Payment details you enter at checkout are collected by Dodo directly.
9. How & Why We Collect and Use Your Information
New Zealand (Privacy Act 2020): We collect personal information only for lawful purposes connected with providing the Service and only what is necessary for those purposes (IPPs 1–4). Where practicable, we collect information directly from you (IPPs 2 & 3); where we collect information from third-party sources such as your OAuth identity provider or payment processor, we do so with notice under IPP 3A. We use and disclose personal data consistently with the purpose for which it was collected (IPPs 10–11). You can ask to access and correct your personal information (IPPs 6–7), subject to the exceptions in the Privacy Act described in Section 11. You can do this directly in-app or by contacting our Privacy Officer.
10. Security Architecture & Tenant Isolation
We use technical and organisational safeguards designed to protect your personal data, including:
- Per-Account Isolation: Your data is stored under your own account record, and our backend checks your authenticated Firebase user ID (
uid) on every request so that one account cannot read or change another account's data. Our database security rules block all direct access from browsers, so every request goes through those backend checks. - Encryption in Transit & at Rest: Web and API traffic is encrypted in transit using HTTPS (TLS). Google Cloud encrypts stored data, including database records and backups, at rest using AES-256.
- Least-Privilege Access: Our backend runs under a dedicated service account that is granted only the cloud permissions it needs. Authorised TalentOS staff can see account details (your name and email address, plan and credits, sign-up and last-active dates, and how many jobs, stories and practice sessions you have, but not their content) in an internal admin console, along with feedback and waitlist requests you send us, and use them only to provide support, manage beta access and investigate abuse.
- Notifiable Breach Notification: Where a privacy breach is likely to cause serious harm, we will notify the New Zealand Privacy Commissioner and affected individuals as soon as practicable after becoming aware of it, as required by Part 6 of the Privacy Act 2020.
11. Your Privacy Rights
Under the New Zealand Privacy Act 2020 you can ask us for access to the personal information we hold about you (IPP 6) and ask us to correct it (IPP 7). These rights are subject to exceptions: the Privacy Act sets out grounds on which we may refuse an access request, for example where releasing the information would involve the unwarranted disclosure of another person's affairs, where the information is legally privileged, or where it does not exist or cannot be found. We may need to verify your identity before acting on a request. If we refuse a request, we will tell you why and that you can complain to the Privacy Commissioner. If we do not agree to correct information, you can ask us to attach a statement of the correction you asked for, and we will take reasonable steps to do so.
You can also manage much of your information yourself in the app:
- Access: Request a copy of the personal data we hold about you.
- Correction: Edit or correct any inaccurate career or profile data directly in the Settings or Document Studio interfaces.
- Deletion: Delete your account and the career and pipeline data held in it (see Section 6 for how backups expire and the limited records we are required to keep).
- Data Export: Export your tailored documents in PDF, DOCX, or raw Markdown formats, and your account archive (your profile, settings, jobs, documents, stories and other data held in your account) as JSON. Records held outside your account, such as feedback you sent, your referral code or a waitlist entry, are not in the archive; ask our Privacy Officer for a copy.
- No Sale or Sharing of Personal Information: We do not sell, rent, or monetize your personal data or application history to recruiters, third parties, or data brokers.
Children: The Service is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to someone under 18, we will close it and delete the content held in it, except for records we are required by law to keep, such as billing and payment records.
12. Contact, Privacy Officer & Complaints
The Service is operated by TalentOS Technologies Limited (NZBN: 9429053964885), Auckland, New Zealand, which has appointed a designated statutory Privacy Officer under Section 201 of the Privacy Act 2020. If you have questions about this Privacy Policy, wish to access or correct your information, or want to exercise any privacy right, contact the Privacy Officer at privacy@talentos.nz (general enquiries: admin@talentos.nz) or through your account dashboard. We will respond within the timeframes required by the Privacy Act 2020 (generally within 20 working days for access and correction requests).
If you are not satisfied with our response, you have the right under the Privacy Act 2020 to complain to the New Zealand Office of the Privacy Commissioner (OPC) online at privacy.org.nz or by post at PO Box 10094, The Terrace, Wellington 6143, New Zealand. If you live outside New Zealand, you may also be able to complain to the privacy regulator in your country.
13. Revision History
| Version | Effective Date | Summary of Changes |
|---|---|---|
| 2026-10-01.5 | 1 October 2026 | Disclosed the beta waitlist, referral codes, the shared interview question bank (questions generated from your own profile or CV are no longer added to it, and erasure unlinks your shared questions), the optional browser extension, and browser dictation in Question Drills. Corrected live voice audio, sign-in method, rate-limit counter, cookie and data export wording, and described what authorised staff can see in the admin console. |
| 2026-10-01.4 | 1 October 2026 | Where data is processed: sign-in (Firebase Authentication) runs in the United States and server logs in Google Cloud's global location, while the database and backups stay in Sydney. Cited the data processing terms for each Google service. Added feedback and public posts: feedback is published on our website only with your permission. Deletion wording matches our backup retention. |
| 2026-10-01.3 | 1 October 2026 | Removed Plausible Analytics: our public pages no longer load any third-party analytics, so Plausible is no longer a sub-processor and no visit or sign-up data is sent to it. |
| 2026-10-01.2 | 1 October 2026 | Plausible Analytics: disclosed that it records whether a visit to a public page ended in a sign-up. |
| 2026-10-01.1 | 1 October 2026 | Cross-border disclosures (IPP 12): Dodo Payments now relies on your express authorisation at checkout, and Plausible Analytics' data processing agreement (which applies automatically) is cited. Server log retention is now fixed in our infrastructure configuration. |
| 2026-09-30.2 | 30 September 2026 | Grounded every factual statement in our code, infrastructure, or providers' published terms: corrected Google's Gemini API retention to 55 days and disclosed that flagged content may be reviewed by Google staff; removed "enterprise" provider wording; listed Plausible Analytics and Google Maps geocoding as providers; disclosed server log retention; removed subscription wording (passes are one-off purchases); restated security safeguards precisely. |
| 2026-09-30.1 | 30 September 2026 | Legal review update: moved "Changes to This Policy" to Section 2; removed references to overseas privacy regimes; referenced New Zealand's Biometric Processing Privacy Code 2025; corrected retention statements (exports are not stored, backup expiry periods, cloud provider deletion, records we must keep); clarified that access and correction rights are subject to Privacy Act exceptions; corrected IPP 12 references. |
| 2026-09-29.1 | 29 September 2026 | Disclosed on-device rehearsal replay recordings (kept only in your browser, deleted after 7 days or on sign-out/account deletion) and clarified that no raw audio is stored on TalentOS servers. |
| 2026-09-16.1 | 16 September 2026 | Formalized NZ Privacy Act 2020 IPP 12 cross-border disclosure (contractual safeguards via Google Cloud enterprise DPA/SCCs and informed user authorization), and disclosed upstream 30-day automated platform security buffer under Google Prohibited Use Policy. Designated TalentOS Technologies Limited (NZBN: 9429053964885) as statutory data controller and appointing body for Privacy Officer. |
| 2026-09-15.1 | 15 September 2026 | Initial public launch privacy policy, Privacy Act 2020 Information Privacy Principles (IPPs), zero-training commitments, and ephemeral voice audio handling. |