Privacy Policy
Last updated: 2 September 2026 Effective: 2 September 2026
This Privacy Policy explains how RecruitingMonk ("TAbuddy", "we", "us") collects, uses, stores, shares, retains and deletes information when you use the TAbuddy platform at https://tabuddy.co and related applications, APIs and integrations (together, the "Service").
TAbuddy is a talent-acquisition decision intelligence platform. Recruiters and hiring teams use it to structure job descriptions, understand role requirements against a skill graph, and rank and review candidate resumes with traceable reasoning.
1. The two kinds of people in this policy
TAbuddy handles personal data about two distinct groups. Your rights and our role differ depending on which you are.
| Users | Candidates | |
|---|---|---|
| Who | Recruiters, hiring managers, agency staff, interviewers and administrators who hold a TAbuddy account | Job applicants whose resumes or profiles are uploaded to the Service by a User |
| Our role | Controller (we decide how your account data is used) | Processor, on behalf of the User's organisation, which is the Controller |
| Relationship | Direct — you signed up | Indirect — an employer or agency uploaded your information |
If you are a Candidate and want your data corrected or deleted, the fastest route is the employer or agency that received your application. You may also contact us at privacy@tabuddy.co and we will route your request to the relevant customer and assist them in fulfilling it. See Section 11.
2. Information we collect
2.1 Account and identity information
Collected when you create an account or are invited to a workspace:
- Name, email address, profile photo (where supplied)
- Employer or agency name, job title, and work email where you choose to verify it
- Workspace and team membership, role and permission level
- Authentication identifiers, including a Google account identifier if you sign in with Google
- Billing contact details and subscription tier
We do not collect or store your Google password. Payment card details are collected and stored by our payment processor, not by TAbuddy.
2.2 Google user data
When you choose to connect a Google Account, we request only the narrowest scopes needed for the features you use. The table below is exhaustive: we do not request, access, or store any Google data outside it.
| Google scope | What we access | Why we need it | How we use it | Retention |
|---|---|---|---|---|
openid, .../auth/userinfo.email, .../auth/userinfo.profile | Your Google account ID, email address, name, profile picture | To create and authenticate your TAbuddy account without a separate password | Populating your account identity, signing you in, showing you to teammates in a shared workspace, and sending service email | For the life of your account; deleted within 30 days of account deletion |
.../auth/gmail.send | Send-only access. We cannot read your mailbox with this scope. | To send candidate outreach and interview correspondence from your own address at your explicit instruction | Sending only the messages you compose or approve in the Service. A record of what was sent and when is kept in the audit trail. | Send metadata retained for the life of the associated job record |
What we never do with Google user data:
- We do not access Google data on a background schedule. Every access is triggered by an action you take in the interface.
- We do not sell it, rent it, or use it for advertising, ad targeting, or credit assessment.
- We do not transfer it to data brokers or information resellers.
- We do not use it to build, enrich or expand our skill graph, role taxonomy, company directory or any other shared dataset. See Section 4.
- We do not use it for any purpose other than providing and improving the user-facing features described above.
You can disconnect your Google Account at any time from Settings → Integrations in TAbuddy, or revoke our access directly at https://myaccount.google.com/permissions. Revoking access stops all further Google data access immediately. Content already imported into your workspace remains until you delete it.
2.3 Customer Content
Content you or your collaborators upload or create in the Service:
- Job descriptions, role briefs, hiring-manager intake responses, notes and comments
- Candidate resumes and CVs, and the structured data extracted from them — contact details, employment history, education, skills, and dates
- Recruiter and hiring-manager decisions: shortlists, rejections, scores, overrides and stage transitions
Resumes frequently contain more information than a hiring decision requires, including dates of birth, photographs, marital status, nationality, gender or identity numbers — particularly in some regional resume conventions. We do not require, request or use any of this. We advise Users to redact it before upload. Where it is present in an uploaded document, it is stored as part of the source document but is not extracted into structured fields and is not used in scoring.
2.4 Usage and technical data
- IP address, browser and device type, operating system
- Pages and features used, actions taken, timestamps
- API request logs, error logs and performance telemetry
- Cookies and similar technologies (Section 13)
3. Limited Use — Google API Services User Data Policy
TAbuddy's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we affirm that:
- We use Google user data only to provide or improve user-facing features that are prominent in the TAbuddy interface, and only with your consent.
- We transfer Google user data only where necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets after obtaining your explicit prior consent.
- We do not use or transfer Google user data for serving advertisements of any kind, including retargeting, personalised advertising or interest-based advertising.
- Humans do not read Google user data unless (a) we have your affirmative agreement for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymised and is used for internal operations.
4. Artificial intelligence and machine learning
This section is central to how TAbuddy works, and we state it precisely.
We affirm that Google Workspace APIs are not used to develop, improve, or train generalised or non-personalised AI and/or ML models. No data obtained through Google Workspace APIs is used to develop, improve, train, fine-tune, calibrate, evaluate or benchmark any generalised or non-personalised AI or ML model, whether ours or a third party's. We do not permit any third-party AI provider to do so either.
Our skill graph is built without customer or Google data. TAbuddy's canonical skill graph, role taxonomy, responsibility (KRA) canon and company directory are generated from structured role research and public labour-market information. They are not derived from, seeded by, or improved using candidate resumes, job descriptions or any other content in customer workspaces, and never from data obtained through Google APIs.
How AI is used at inference time. When you rank a resume or generate a role brief, the relevant text is sent to third-party large language model providers to extract structured facts. We use providers under agreements that prohibit them from retaining the content or using it to train their models. Scoring itself is deterministic and runs on our own infrastructure.
Human-in-the-loop. TAbuddy produces rankings, evidence maps and recommendations. It does not make hiring decisions. Every recommendation carries a Decision Trace so a human can inspect and override it. See the Terms of Service, Section 8.
5. How we use information
| Purpose | Data used | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Providing the Service — parsing, ranking, workspace collaboration | Account data, Customer Content, Google user data | Performance of a contract |
| Authenticating you and securing accounts | Account data, technical data | Performance of a contract; legitimate interests |
| Billing, credit accounting and collections | Account data, usage counts | Performance of a contract |
| Service email — onboarding, invitations, incident and change notices | Account data | Performance of a contract; legitimate interests |
| Marketing email about TAbuddy | Name, email | Consent, withdrawable at any time |
| Debugging, uptime, capacity planning | Technical data, aggregated usage | Legitimate interests |
| Fraud, abuse and security investigation | All categories as needed | Legitimate interests; legal obligation |
| Legal compliance and defence of claims | As required | Legal obligation; legitimate interests |
We do not sell personal information and we do not share it for cross-context behavioural advertising.
6. When we share information
We share personal data only in the following circumstances.
Within your workspace. Content you add is visible to members of your workspace and to collaborators you invite to specific jobs — hiring managers, interviewers and agency partners — according to the room-level permissions you set. Invited collaborators can see the candidates and job data for the roles they are invited to.
Sub-processors. We use vetted vendors under written data-processing terms that bind them to confidentiality, purpose limitation and security obligations at least as protective as those in this policy:
| Category | Purpose | Example |
|---|---|---|
| Cloud hosting and storage | Running the Service | Google Cloud Platform; Microsoft Azure Blob Storage |
| Database and search | Storing workspace data | MongoDB Atlas |
| LLM inference | Extracting structured facts from documents, under zero-retention / no-training terms | Microsoft Azure OpenAI |
| Document parsing | Converting PDFs and DOCX to structured text | Internal parsing services on our infrastructure |
| Payments | Subscription billing | Razorpay |
| Transactional email | Service notifications | Your connected mailbox (Gmail / Outlook) and transactional email providers |
| Product analytics and error monitoring | Reliability and usability | Application logs on our hosting providers |
A current sub-processor list is maintained in this section and updated when vendors change. Material changes will be notified by email or in-product.
Legal and safety. Where required by law, valid legal process, or to protect the rights, property or safety of TAbuddy, our users or the public. We will notify you unless legally prohibited.
Business transfer. In a merger, acquisition, financing or sale of assets, data may transfer to the successor entity under the same protections. Google user data will be transferred in such a transaction only after we obtain your explicit prior consent.
We never share Google user data with third parties for their own purposes, for AI/ML model development, or for marketing.
7. Where we process data
We process data on infrastructure located in India and other regions operated by our cloud providers (Google Cloud Platform and Microsoft Azure). Where personal data is transferred out of the EEA, the UK, or another jurisdiction with transfer restrictions, we rely on European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or another valid transfer mechanism. A copy of the relevant safeguards is available on request.
8. Retention and deletion
| Data | Retained | Deleted |
|---|---|---|
| Account and profile data | While your account is active | Within 30 days of account deletion |
| Google user data (all scopes) | While the Google connection is active and the account exists | Within 30 days of you disconnecting the Google Account, revoking access, or deleting your account |
| Customer Content — resumes, JDs, decisions | While your organisation's workspace is active, or until a User deletes it | Within 30 days of workspace deletion, subject to your export window under the Terms |
| Audit and Decision Trace logs | 24 months, to support defensibility of hiring decisions | Automatically after the retention window |
| Billing and tax records | 8 years, as required by Indian tax law | After the statutory period |
| Backups | 35 days on a rolling cycle | Overwritten automatically; deleted records do not survive a restore beyond this window |
Deleting your data. You can delete individual candidates, jobs or documents at any time from within the Service. To delete your whole account and all associated data, use Settings → Account, or email privacy@tabuddy.co. We will confirm completion. Deletion is irreversible.
Disconnecting Google. Disconnecting your Google Account deletes stored Google OAuth tokens immediately and triggers deletion of Google-derived identity data within 30 days. Documents you previously imported remain in your workspace as Customer Content until you delete them separately, because they are now part of your hiring record.
9. Security
- TLS 1.2 or higher for all data in transit; encryption at rest for databases, object storage and backups
- OAuth tokens encrypted at rest with keys held in a managed secrets service; tokens never logged
- Role-based access control and workspace-level tenant isolation
- Least-privilege internal access, granted on need, logged and reviewed
- Mandatory two-factor authentication for staff with production access
- Dependency scanning, vulnerability management and periodic penetration testing
- Documented incident response; we notify affected users and regulators within the timeframes required by applicable law
No system is perfectly secure. If you believe your account has been compromised, contact security@tabuddy.co immediately.
10. Your choices
- Access, correct, export or delete your account data from Settings, or by contacting us
- Withdraw Google access at any time, from Settings → Integrations or from your Google Account permissions page
- Opt out of marketing email using the unsubscribe link; service email is not optional while your account is active
- Cookie preferences through the cookie banner or your browser settings
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. You may also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
On automated decision-making: TAbuddy is designed so that a human makes the hiring decision. Certain optional customer-configured filters can automatically exclude candidates before human review. Where a Candidate is excluded by such a filter, they may request human review by contacting the employer or agency, or by contacting us so we can route the request.
Exercising rights. Users: email privacy@tabuddy.co. Candidates: contact the employer or agency you applied to, or email us and we will identify the relevant customer and assist them in responding. We respond within 30 days, or sooner where the law requires.
India (DPDP Act, 2023). Our Grievance Officer is: Ashfaq Ahmed, Founder grievance@tabuddy.co #1, 5th Cross, 17th Main Road, Aicobonagar, near Udupi Garden Park, BTM Stage 1, Bengaluru, Karnataka 560068, India We acknowledge grievances within 7 days and resolve them within 30 days.
EEA/UK. You may lodge a complaint with your local supervisory authority.
California. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. You may exercise access, deletion, correction and non-discrimination rights by contacting us.
12. Candidates: how your data got here
If you applied to a role, or a recruiter uploaded your resume, an employer or agency using TAbuddy holds your information. They decide what to do with it; we process it on their instructions.
We use your resume to extract structured facts — skills, employment history, education, responsibilities — and to produce a ranking and an evidence map against a specific role. Every conclusion is linked back to the line in your resume that supports it, so a recruiter can check it.
We do not use your resume to train AI models. We do not sell your data. We do not add you to a searchable database that other employers can browse without your involvement. Contact us at privacy@tabuddy.co with any question about your data.
13. Cookies
We use strictly necessary cookies for authentication and session management, and — subject to your consent where required — functional and analytics cookies to understand feature usage. We do not use advertising or cross-site tracking cookies. Manage preferences through the cookie banner or your browser.
14. Children
The Service is for professional use by people aged 18 and over. We do not knowingly collect personal data from children. If we learn we have, we delete it. Contact privacy@tabuddy.co if you believe a child's data has been submitted.
15. Changes to this policy
We may update this policy. Material changes will be notified by email and in-product at least 15 days before they take effect. If we change how we use Google user data, we will notify you and obtain your consent to the updated policy before using Google user data in the new way. The "Last updated" date at the top always reflects the current version. Prior versions are available on request at privacy@tabuddy.co.
16. Contact
RecruitingMonk #1, 5th Cross, 17th Main Road, Aicobonagar, near Udupi Garden Park, BTM Stage 1, Bengaluru, Karnataka 560068, India Privacy: privacy@tabuddy.co Security: security@tabuddy.co Grievance Officer (India): grievance@tabuddy.co
TaBuddy