Skip to main content

"The Pilot" Free

Claim Now
Privacy & Data Protection

Privacy Policy

Your privacy matters. This policy explains what data we collect, how we use it, and how we keep it safe. No legal jargon where we can avoid it.

Last updated: February 2, 2026 | Effective: February 2, 2026

The Short Version

• We collect data necessary to run AI interviews and detect fraud

• We encrypt everything and follow industry security standards

• We never sell your data to third parties

• You can request your data or ask us to delete it anytime

• We comply with GDPR, CCPA, and other privacy regulations

1. Information We Collect

Account Information

When you sign up, we collect your name, email address, company name, and job title. If you use SSO, we receive basic profile information from your identity provider.

Interview Session Data

During AI-powered interviews, we process audio/video streams (when enabled), code submissions, chat messages, screen activity, and behavioral signals. This data powers our assessments and fraud detection.

Integrity Verification Data

Our 13-Signal Forensic Engine analyzes patterns to detect cheating, proxy candidates, and AI-assisted responses. This includes keystroke dynamics, audio-visual sync, and behavioral consistency metrics. We do not collect biometric templates or create permanent identity databases.

Usage & Technical Data

We collect standard analytics: pages visited, features used, session duration, browser type, and IP address. This helps us improve the platform and troubleshoot issues.

Payment Information

Payment processing is handled by Stripe. We never see or store your full credit card number. We only receive confirmation of successful payments and basic billing details.

2. How We Use Your Data

Providing Our Services

We use your data to conduct AI interviews, generate assessment reports, verify candidate integrity, and deliver the features you signed up for. This is the core purpose—everything else is secondary.

Improving Our AI

We use aggregated, anonymized data to improve our AI models, reduce bias, and enhance fraud detection accuracy. Individual interview recordings are not used for training without explicit consent.

Communication

We send transactional emails (interview reports, account notifications) and occasional product updates. Marketing emails require your consent and include easy unsubscribe options.

Legal & Safety

We may use data to comply with legal obligations, enforce our terms, prevent fraud, and protect our users, employees, and the public.

3. How We Protect Your Data

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Interview recordings are stored in isolated, encrypted cloud storage with customer-specific keys for enterprise plans.

Access Controls

We implement role-based access control (RBAC) and the principle of least privilege. Only authorized personnel can access sensitive data, and all access is logged and auditable.

Infrastructure Security

We use industry-leading cloud providers with SOC 2 Type II certification. Our infrastructure includes firewalls, intrusion detection, DDoS protection, and continuous security monitoring.

Incident Response

We maintain incident response procedures and will notify affected users within 72 hours of discovering a data breach, as required by GDPR and other regulations.

4. Data Retention

We retain data based on your subscription tier and business needs:

PlanInterview RecordingsAssessment Reports
Pilot7 days30 days
Starter30 days90 days
Engine90 days1 year
FortressCustom (up to 3 years)Custom

You can request early deletion anytime. Account data is deleted within 30 days of account closure, except where legal retention is required.

5. Your Privacy Rights

Access & Portability

You can request a copy of your personal data in a machine-readable format. We'll provide it within 30 days.

Correction

You can update your account information anytime through settings, or contact us to correct other data we hold about you.

Deletion ("Right to be Forgotten")

You can request deletion of your personal data. We'll comply within 30 days, except where we're legally required to retain certain information.

Opt-Out & Consent Withdrawal

You can opt out of marketing communications anytime. You can also withdraw consent for specific data processing activities, though this may limit your ability to use certain features.

Complaint

If you believe we've mishandled your data, contact us first—we want to make it right. You also have the right to lodge a complaint with your local data protection authority.

6. International Data Transfers

TalentLyt is based in the United States. If you're located outside the US, your data may be transferred to and processed in the US or other countries where our cloud providers operate.

For transfers from the European Economic Area (EEA), UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. We also implement supplementary technical measures where required.

Enterprise customers can request data residency in specific regions (US, EU, or APAC) for an additional fee.

7. Third-Party Services

We work with carefully vetted third-party processors:

  • Cloud Infrastructure: AWS, Google Cloud (SOC 2 certified)
  • Payment Processing: Stripe (PCI DSS Level 1)
  • Email Services: Resend (for transactional emails)
  • Analytics: Vercel Analytics (privacy-focused, no cookies)

All processors are contractually bound to protect your data and only use it for the services we've engaged them to provide. We do not sell your data to advertisers or data brokers.

8. Cookies & Tracking

We use minimal cookies:

  • Essential cookies: Required for the platform to function (authentication, session management)
  • Analytics: Privacy-focused analytics that don't track individuals across sites

We do not use third-party advertising cookies or cross-site tracking. You can manage cookie preferences through your browser settings.

Contact Us

For privacy questions, data requests, or to exercise your rights:

Email: privacy@talentlyt.cloud

Data Protection Officer: dpo@talentlyt.cloud

Address: Rigour Labs Inc., Delaware, United States

We aim to respond to all privacy requests within 30 days.

GDPR Compliant
CCPA Compliant
SOC 2 Ready
Privacy by Design