Privacy
Last updated 2026-10-09
Who runs this
TheTalentDesk is built and run by one person, Ashwani Bhat, trading under that name. There is no company behind it. Where data protection law applies, that makes Ashwani Bhat the controller for the waitlist on this site, and your processor for everything inside your workspace.
For anything about your data — a question, a correction, or a deletion — write to ashwani@thetalentdesk.io. It reaches a person, not a queue.
What we collect
When you join the waitlist, we store the first name, company, job title, and email address you enter, along with the date you signed up and whether you have confirmed your email.
If you apply for a job through a company's TalentDesk job page, a different set of information is involved, described under "If you apply for a job through a TalentDesk page" below.
Why we collect it
Solely to manage the waitlist and email you about TheTalentDesk. We do not sell or share this data with third parties for marketing.
Where it's stored
Waitlist entries are stored in a managed Redis database (Upstash). Emails from this site are sent through Resend. Both act as data processors on our behalf and do not use your data for their own purposes.
The product itself
Once you have a workspace at app.thetalentdesk.io, a different and larger set of data is involved: the candidates you add, their resumes, and the feedback your team writes. That data is yours. We process it to run the service and for nothing else — we do not sell it and we do not use it to train anything.
Candidates usually have not signed up for anything themselves. If you are somewhere with data protection law, you are the controller of their data and we are your processor. If you are a candidate and want to know what a company holds about you, ask them first — they control it, not us — and write to us if they cannot help.
If you apply for a job through a TalentDesk page
Companies that use TheTalentDesk can publish their open roles at app.thetalentdesk.io/jobs. If you apply there, the form asks for your name, your email address and a resume (a PDF or Word .docx file, up to 4 MB), and optionally a phone number. We also record that you agreed to the notice beside the form, when you agreed, and which link or site brought you to the page where we can tell, for example a LinkedIn share link.
The company you apply to decides what happens to your application and is the controller of it. We store it for them and process it only for them. Your application waits in a holding area until someone on the company's team next opens their workspace. It then becomes a candidate record in the first stage of that job's hiring process, and the copy in the holding area is deleted. From then on it is treated like any other candidate record: the company keeps it until it deletes it, or deletes its workspace.
To see, correct or delete your application, ask the company first. If they cannot help, write to ashwani@thetalentdesk.io and we will pass your request to them.
To stop automated abuse we count applications per IP address and per job. The address is kept only as a one-way scramble that expires within an hour. Our hosting provider, Vercel, also logs IP addresses, as described below.
The job pages show only what the company chose to publish about the role. They contain nothing about any candidate. A company can also have its listings sent to search engines and job sites, as structured data on the page, in a sitemap and in an XML feed. When a company closes a role it leaves our pages, sitemaps and feeds within about an hour. Once a search engine or job site has copied a listing we cannot delete it from their systems, and how soon it disappears there depends on how often each one re-reads ours.
Who else sees it
These are every service the code actually sends data to, and what each one receives:
- Vercel — runs this site and the app. Receives every request, so IP addresses and request logs.
- Cloudflare — the app's database (D1) and resume storage (R2). Holds workspaces, accounts, candidates, feedback and uploaded files.
- Upstash — the waitlist on this site, before a workspace exists.
- Resend — email from this site: the confirmation and anything about the waitlist.
- Our email provider — email from the app itself: your welcome message and access notices. Sent over SMTP.
- Dodo Payments — checkout, subscriptions and invoices. Receives your billing details and takes the payment; as merchant of record it is the seller. We never see your card.
- An AI provider you choose — only if you turn AI resume parsing or ratings on. Resume text and the job criteria needed for that task are sent to the provider you select, including a custom provider if you configure one. You connect your own account with your own API key, so the arrangement is between you and that provider. You choose your budget and pay that provider directly; the app shows estimated spending. We store the key encrypted and decrypt it only to make the requests you enable. Leave it switched off and no resume ever leaves our infrastructure.
There is no analytics or session-recording tool in the app. This marketing site uses Vercel Analytics, which counts page views without cookies and without identifying you.
The app uses essential cookies for sign-in and session security. These are not advertising or tracking cookies. We do not use cookies to follow you across other websites.
How long we keep it
Waitlist information stays until you ask us to remove it, or until we convert the waitlist into product accounts, whichever comes first.
Active workspace and candidate records stay while you use the service, until you delete them or request their removal. They are not automatically deleted after two years.
An application made through a job page waits in a holding area until the company's team next opens their workspace, then becomes a candidate record like any other and is deleted from the holding area. If nobody opens the workspace it waits until they do, or until the workspace is deleted, when it is deleted with it.
Backup copies, active security audit records and audit exports have a maximum retention period of 730 days (no more than two years). Backup retention is measured from the copy's creation; security record retention is measured from the recorded event. Copies may be removed sooner. Removed workspace data may remain in restricted backups until those copies expire and is not used for ordinary product processing.
Removing your data
Every email we send includes a "Remove me from this list" link that deletes your waitlist entry immediately — no reply needed and no confirmation step.
For a workspace, email ashwani@thetalentdesk.io from the address on the account and say what you want removed. We will confirm within 30 days, and sooner in practice. If you are a candidate rather than a customer, the company that added you controls your data — ask them first, and write to us if they cannot help.
Questions
Write to ashwani@thetalentdesk.io, or reply to any email you have had from us. Both reach the same person.