Trust

How we protect your data.

Your Talent works inside your tools, with your permission, under your approvals. Your private conversations stay private. Here is exactly how, in plain English: what we collect, who can see it, where it lives, and how to get it back.

The short version

Private by default

Your chats, memory, runs, connections, and approvals are readable by you alone. No admin setting opens them. This is enforced in code, not in a policy paragraph.

Admins see the bill, not the work

Workspace admins can see what a job cost and that a teammate has a Talent. They never see what was said or produced.

Nothing acts without permission

Sending mail, changing a calendar, or publishing something can require your approval first. Money movement and irreversible actions always ask.

Shared knowledge needs a human yes

What enters your company's shared knowledge is proposed by the teammate and approved by a person before it spreads. Private memory never joins it automatically.

Credentials stay unreadable

Connected tools are reached with per-person credentials that are encrypted, scoped to one person and one Talent, and never displayed back after you connect.

You can leave with your data

Download your documents and artifacts at any time. Deletion and retention terms are spelled out below.

We do not train AI models on your work, and we do not let our model providers train on it. Your work is not a training set.

Who can see what

Roles exist to run the company, not to read people's work.

WhatWho can see it
Your private conversations with your TalentOnly you
Your personal memory, the context your Talent keeps about your workOnly you
Your private runs, approvals, and suggestionsOnly you
What a job cost, when it ran, and which model it usedWorkspace admins (billing only)
That a teammate has a Talent, its name and statusWorkspace admins (identity only)
Company knowledge and shared workflowsThe team, after a human approves the promotion

There is no admin switch that opens a member's private chats. The queries that read private data are owner-scoped in the database itself, so a misconfigured role cannot widen them. Personal data and shared company knowledge are separate systems with a human approval in between. The full legal version lives in our Privacy Policy.

Controls, approvals, and limits

Your Talent can read, draft, and prepare work freely; those actions are reversible. Actions that leave your workspace are treated differently, and the system applies controls before they happen.

Approval gates

Sending an email, posting as you, writing to your calendar, or publishing a document can park and wait for your yes, your no, or a yes for this conversation only.

The tier that always asks

Money movement, irreversible actions, and calendar writes always ask. No setting turns those off.

Allowlists

Not every tool is reachable. Each connector exposes a deliberately small set of actions, and the platform enforces it.

Budgets and brakes

Credits and turn budgets cap what one task can consume, and a loop guard stops a stuck job instead of letting it run all night.

Receipts

Every action leaves a record: what ran, what it touched, and what it cost. You can always see why something happened.

Grounded, not guessing

If a connection is missing or broken, your Talent says so instead of improvising. It reaches only the tools you connected and authorized.

Data privacy and sovereignty

Where your data lives, who legally controls it, and the commitments that apply on every plan.

Your organization is in control

Your organization is the data controller for workspace data. TalentOS acts as a processor and handles data only on your instructions.

Stored and processed in the United States

Workspace data is stored and processed in the United States on the providers named below. For customers in the EEA or UK, transfers are covered by Standard Contractual Clauses.

Encrypted in transit and at rest

Data is encrypted in transit, and stored credentials are encrypted at rest.

Limited internal access

Access to customer data by our team is limited to what you ask us to do, and to what security, abuse prevention, or the law requires.

No sale, no advertising, no training

We do not sell customer data or use it for advertising, and your content is not used to train models, ours or our providers'.

Google data commitments

For data from connected Google services, we comply with the Google API Services User Data Policy, including its Limited Use requirements.

Where your data lives

We run on established infrastructure, and we name every company that touches your data. This list is kept current, and Enterprise customers hear from us before a material change.

CompanyWhat it does for usWhat it can touch
ClerkSign-in, sessions, and workspace membershipAccount identity
ConvexApplication database and backendYour workspace data at rest
RailwayHosting and delivery of the web appServes the application; no separate data store
StripePayments and billing for paid plansBilling details; never your conversations or documents
Anthropic, OpenAI, and GoogleAI models for drafting, research, analysis, and summaries (accessed through OpenRouter)The content needed for the task you asked for
GroqVoice transcription for voice notesThe audio you record, at the moment you record it
FirecrawlFetching public web pages for researchPublic URLs only; never password-protected pages
E2BThe isolated sandbox that runs your Talent's workFiles for the task at hand, in a per-session sandbox
Fly.ioRuns our iMessage bridgeiMessage messages you send to your Talent
SentryError monitoring so we can fix breakage fastDiagnostic and error data
PostHogProduct analyticsUsage events
Google FontsTypography deliveryNothing about you

Customer conversations and documents are processed to do the work you asked for. They are never sold, and they are not used to train models. Slack, Google (Gmail, Calendar, Docs, Sheets), Microsoft, GitHub, Notion, and the other tools you connect are your accounts, not ours. You connect them, you choose what each can reach, and you can disconnect them at any time.

Retention, export, and deletion

Retention

We keep workspace data for as long as the workspace is active. When a member leaves, their private conversations and personal memory are removed with the account. Workflows and knowledge they published to the workspace stay, because those belong to the organization. When a workspace closes, we delete or anonymize its data within 90 days, except where the law requires us to keep records.

Export

Your documents and artifacts can be downloaded from your Library at any time. For a full export of your workspace data, email support@talentos.so and we will prepare it.

Deletion

Ask us to delete your account or workspace at any time. We delete what we are not legally required to keep and confirm in writing when it is done.

Compliance, stated precisely

We would rather be precise than impressive.

SOC 2

Not done yet. It is on our roadmap, and we will publish it when it is real. We will never show a badge we have not earned.

DPA

Available today for Enterprise agreements. Ask us and we will send ours.

Security reviews

Enterprise includes a security review with our team.

Subprocessors

Every company that processes data for you is named on this page, and Enterprise customers are notified before a material change.

Report a vulnerability

If you find a security issue, tell us at support@talentos.so. We will confirm receipt within one business day, keep you posted, and credit you if you would like. Please do not test against other customers' workspaces or run automated scans that degrade the service.

Questions this page did not answer? Ask us directly.

A founder reads every message. Bring your compliance reviewer.

support@talentos.so

Last updated: September 17, 2026 · Privacy Policy · Terms