TalentReach

Privacy Policy

Last updated 16 August 2026

This describes what TalentReach stores, why it stores it, and how to have it removed. It covers the app itself — not the third-party providers whose keys you supply, each of which has its own policy.

1. What we store

  • Your account — the name, email address and profile picture your Google account returns at sign-in.
  • Your profile — what you enter in onboarding and settings: company name, city, years of experience, the services you offer, and any portfolio or LinkedIn URL you add.
  • Your API keys — encrypted at rest with AES-256-GCM. They are never displayed back to you in full and never sent anywhere except the provider they belong to.
  • Your Gmail authorisation — an OAuth token, stored encrypted, limited to creating and sending mail. It grants no ability to read your mailbox.
  • Your work — leads found, branding audit reports, drafted emails and their send status.
  • Operational records — search runs, token usage and error diagnostics, used to make failures debuggable and to show usage in the app.

2. Information about other people

Leads contain business contact information about companies and their founders — names, work email addresses, company URLs and public social profiles — collected from publicly accessible sources. It is stored so you can review and act on it.

When you email a lead, you are the sender and the data controller for that contact. If a recipient asks you to delete their details, delete the lead; ask us and we will remove it too.

3. Where it is stored

Data is held in Google Cloud Firestore. Access is restricted to the application server; the browser never talks to the database directly.

4. Who we share it with

We do not sell your data and we do not sell your leads. Data leaves the app only:

  • to the AI provider you chose, when a prompt is sent to draft or classify something;
  • to the search and scraping provider, when a lookup runs;
  • to Gmail, when you save a draft or send an email;
  • where the law requires it.

Those providers process the data under their own terms. Your API keys mean the relationship for AI and scraping is between you and them.

5. Cookies

A session cookie keeps you signed in and a preference cookie remembers your light/dark theme. No advertising or cross-site tracking cookies are used.

6. How long we keep it

Your account and work are kept while your account is active. Cached research results expire on their own after about seven days. Delete a lead or an email in the app and it is removed from your workspace.

7. Your choices

  • Correct your profile at any time in Settings.
  • Remove an API key by clearing the field and saving.
  • Disconnect Gmail in Settings, which revokes the stored token.
  • Delete leads and emails individually.
  • Ask for your account and all associated data to be deleted.

8. Security

Secrets are encrypted at rest, traffic is served over HTTPS, and access is approval-gated. No system is perfect; if you believe your account has been compromised, revoke TalentReach in your Google account settings and contact us.

9. Changes

We may update this policy. The date at the top shows the current version.

10. Contact

For access, correction or deletion requests, reach out through the contact details published on the TalentReach site.