EchoTalent Privacy Policy
Applies to: the EchoTalent website, APIs, and the EchoTalent AI Job Assistant Chrome extension ("Extension").
Short version: we only process what's needed to help you apply to jobs faster (your login email, the resume you upload, job text from pages you open, and application notes you choose to track). We don't sell data or inject ads.
1) Who we are & scope
This Policy explains how EchoTalent ("we", "us") collects, uses, and protects information when you use our site, services, and the Extension. If you don't agree with this Policy, please don't use the services.
2) The data we process
A. Account & identity
Identifiers: name (optional), email address, profile image (if provided).
Auth data: OAuth tokens (Google/LinkedIn) and session cookies for echotalent.net.
We never receive your social login passwords.
B. Content you provide
Resume/CV & documents you upload for tailoring (PDF/DOC/DOCX).
Cover letters you create with our tools.
Application tracker data: company, role, status, notes, reminders, priorities.
C. Page content needed to function
Job posting text (title, company, description, requirements) from pages you open, to compute ATS score and generate tailored materials.
We do not collect your overall browsing history. We access only the page you're on when the Extension is active.
D. Product usage & diagnostics
Usage events: feature usage (e.g., "ATS Scored", "Resume Tailored"), performance metrics, error logs.
Device & app info: browser type/version, OS, language, approximate location inferred from IP (for security/abuse prevention).
Payments (Pro): we receive payment status and customer IDs from our payment processor (no full card numbers stored by us).
E. Support & communications
Emails or messages you send to support; feedback you submit.
Sensitive data: please don't include sensitive personal data (e.g., SSN, health info) in uploads or free-text fields. If you do, it will be handled according to this Policy but we strongly discourage it.
3) How the Chrome extension works & permissions
The Extension needs limited access to make its features work across job sites:
- activeTab & scripting — read the current job page and render the Floating Action Button (FAB), ATS score, tailoring modals, and email tools.
- webNavigation — detect single-page app navigation on job boards so the FAB updates without refresh.
- storage — store your preferences and application records.
- alarms — optional reminders for follow-ups/interviews.
- cookies (echotalent.net only) — keep your EchoTalent session signed in.
- Host permissions (job pages) — allow "works on any site": we access page content only to detect jobs, score ATS fit, and help prepare materials.
We do not inject ads, sell user data, or collect unrelated page content.
4) What we use your data for (lawful bases)
- Provide the service (contract): authenticate you, show the FAB, compute ATS scores, tailor resumes/cover letters, generate emails, and track applications.
- Improve reliability & security (legitimate interests): diagnostics, fraud/abuse prevention, service quality.
- Communicate with you (contract/consent): product updates, support replies, billing notices.
- Comply with law (legal obligation): respond to valid legal requests.
5) AI processing (LLM providers)
Some features send job text and your resume/notes to trusted AI service providers (e.g., OpenAI or similar) solely to:
- extract job fields,
- compute ATS-related metrics,
- generate tailored resumes, cover letters, and emails.
Controls & safeguards
- We minimize the text sent (only what's needed for the output).
- Data is sent over HTTPS.
- Where available, we configure providers so your data isn't used to train their models.
- Providers act as our processors under contract.
If you don't want any content processed by AI, you can avoid using those features or contact us for alternatives where possible.
6) Where data is stored & for how long
Location. Data is processed in the United States and, for sub-processors, in other regions subject to appropriate safeguards.
Retention (defaults):
- Account & uploaded documents: until you delete them or your account.
- Application tracker: until you delete records; local cache may persist until cleared.
- Generated outputs (resumes/letters/emails): stored for your convenience; delete anytime.
- Diagnostics/telemetry & error logs: typically 12–18 months.
- AI processing caches: short-lived (generally ≤30 days) or less, for reliability and abuse prevention.
We'll delete or anonymize data when it's no longer needed.
7) Sharing & disclosure
We do not sell your personal information. We share it only with:
- Service providers / processors who help us run the product (hosting, storage, logging, analytics, AI providers, email, payments). They're bound by contract to use the data only for our instructions.
- Payment processors (for Pro features) receive billing details and payment tokens.
- Legal & safety: if required by law or to protect our rights, users, or the public.
- Business transfer: in a merger/acquisition, your data may transfer with notice.
8) Security
We use technical and organizational measures to protect data, including HTTPS in transit, encryption at rest for stored documents, access controls, and monitoring. No method is 100% secure; if we learn of a breach, we'll notify you and authorities as required.
9) Your choices & rights
In-product controls
- Upload, download, and delete resumes and generated files.
- Edit or remove application tracker entries.
- Export data where available.
Privacy requests
Email [email protected] to:
- Access your data,
- Correct inaccuracies,
- Delete your data or close your account,
- Port your data (export),
- Object to or restrict certain processing,
- Withdraw consent where processing relies on consent.
We'll respond within the timelines required by law.
10) Region-specific disclosures
GDPR/UK GDPR (EEA/UK users)
- Controller: EchoTalent (contact below).
- Legal bases: contract, legitimate interests, consent, legal obligation.
- International transfers: protected by appropriate safeguards (e.g., SCCs) with our processors.
- Automated scoring: ATS "score" is an automated indicator for your convenience; it doesn't make hiring decisions. You can request human review of any EchoTalent decision that materially affects you.
California (CCPA/CPRA)
- Notice at collection – categories: identifiers (email), commercial info (subscriptions), internet activity (feature events), geolocation (coarse IP-based), inferences (ATS scoring about text you provide).
- Do we "sell" or "share" personal information? No.
- Your rights: know, delete, correct, opt out of sale/sharing (not applicable), limit use of sensitive information (we don't use sensitive categories).
- Non-discrimination: we won't discriminate for exercising your rights.
11) Cookies & local storage
- Session cookies on echotalent.net keep you signed in and secure the account area.
- Local storage in the Extension saves preferences and (optionally) application records for speed and offline support.
- We don't use third-party ad cookies.
12) Children
EchoTalent isn't for children under 13 (or under 16 in the EEA without parental consent). If you believe a child provided data, contact us and we'll delete it.
13) Changes to this Policy
We'll post updates here and revise the "Effective" date. For material changes, we'll provide additional notice (e.g., in-app or email). Continued use means you accept the updated Policy.
14) Contact
Questions, requests, or concerns: [email protected]
Appendix: Chrome Web Store "Data safety" mapping
Collected:
- Personal info: email (account)
- Files & docs: resume/cover letter you upload or generate
- App activity: feature usage events, diagnostics
- Web content: job posting text from the active page when the Extension runs
- Device/technical: browser/OS, IP (security)
Data handling:
- Not sold; not used for ads; data encrypted in transit; user deletion supported.
- AI processing uses providers as processors; configured (where available) so data isn't used for model training.
- Access limited to job pages and the active tab for core features.