Privacy Policy
Last updated September 21, 2026
WorkforceGPT is operated by TalentGuard, Inc. This policy covers the WorkforceGPT web application at this domain and the agent surface at /mcp. It says what we collect, who we send it to, how long we keep it, and how to have it removed. Where the answer is unflattering, it says that too.
What we collect
Information you give us
- Account details. Your email address, first and last name, and a password. The password is stored as a hash, never as text we could read. You can add a display name in settings.
- Job descriptions you upload. We extract the text and keep that text. We discard the original file (the PDF, the DOCX) once extraction finishes.
- Role details you enter. Role titles, company names, and any options you choose.
- Recipients you share with. If you email a role to somebody, we record their address and name so the sharing history is yours to see.
Information we generate
- Assessment results and role profiles. The scores, diagnostics, skills and content produced from your inputs.
- Account activity. When you signed up, when you last signed in, how many generations you have run, and their status.
Information from your use of the agent surface
If you authorize a third-party application over MCP, we record the shape of each call and never its contents: which account, which application, which tool, whether it succeeded, and how long it took. We do not log the job description you sent or the profile that came back.
What we do not collect
- No analytics cookies, no advertising pixels, no third-party trackers. There are none on any page of this application.
- No payment details. There is nothing to buy here yet.
- No original uploaded files, once the text has been extracted.
Cookies
One cookie, for your login session. It is what keeps you signed in between pages. There is no tracking cookie to opt out of because we do not set one.
Who we send your information to
We do not sell your information, and we do not share it for anyone else's marketing. We do send it to the services that make the product work:
| Who | What they get | Why |
|---|---|---|
| OpenAI | The text of a job description you upload; role content when you generate a job posting | Scoring the description and drafting the posting
(gpt-4o-2024-11-20 for assessment) |
| TalentGuard WorkforceGPT API | The role title, company name, and the job description when you attach one | Generating the role profile |
| SendGrid (Twilio) | Your email address and the message | Sending verification, password reset, notification and campaign email |
| Neon | Everything stored in the database | Hosting the database |
| Microsoft Azure | Everything the application processes | Hosting the application |
Each of these providers has its own terms governing what it may do with what it receives. We do not send your content to anyone for model training.
The public role library
Publishing a role is opt-in and per role. When you publish, that role profile becomes a public web page at a stable URL, and search engines can index it. This is the one part of the product that deliberately makes your content public, so it is worth reading twice.
- Your name appears only if you choose a byline. Publishing anonymously is the default.
- We remove the company name you entered in the company field. We do not remove company names that appear inside the description text, and the publish dialog says so before you confirm.
- Taking a role down stops it being served immediately and returns "gone" to search engines so they drop it. The record stays in your account so you can republish it.
- TalentGuard staff accounts publish automatically and always anonymously, with an opt-out in settings.
Connected applications
Authorizing an application over MCP gives it a token scoped to what you approved on the consent screen: reading your account, running assessments, or generating roles. It cannot publish anything publicly and it cannot reach anything administrative, because those permissions do not exist on that surface.
Applications register themselves, so the name one shows you is its own claim rather than something we vouched for. Check the address the consent screen shows you, which is where your authorization is actually delivered. You can see and revoke every connected application in settings.
How long we keep it
| What | How long | Can you remove it yourself? |
|---|---|---|
| Job description assessments, and the text extracted from your upload | Until you delete them | Yes, from the assessments list |
| Generated role profiles | Until your account is deleted | No. Write to us |
| Published public pages | Until you take them down | Yes, from the role |
| Agent call records | 30 days, then deleted automatically | Not applicable, they expire |
| Account details | Until your account is deleted | No. Write to us |
Your choices
- Delete an assessment. Any time, from the assessments list.
- Unpublish a role. Any time, from the role.
- Stop marketing email. Use the unsubscribe link in any campaign message, or the toggle in settings. This does not stop verification, password reset or "your role is ready" mail, which is your own account talking back to you.
- Revoke an application. Any time, from settings.
- Delete your account. Email privacy@talentguard.com.
Account deletion is by request, not a button. There is no self-serve delete in the product yet, so deleting your account means writing to us and waiting for a person. We would rather say that plainly than imply a control that is not there. If you have published public pages, tell us whether you want those taken down as well, because they are separate.
Security
Passwords are hashed. Traffic is encrypted in transit, and the database requires an encrypted connection. Repeated failed sign-ins lock an account temporarily. Verification and password reset links expire after an hour.
No system is perfect, and we are not going to claim otherwise here. If you find a security problem, write to privacy@talentguard.com and we will take it seriously.
Children
This is a product for people doing hiring and HR work. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has created an account, write to us and we will remove it.
Where your information is processed
TalentGuard is based in the United States and the services above process information in the United States and other countries. Using the product means your information is handled there.
How the AI features work
Both features are AI-generated and neither is reviewed by a person before you see it. An assessment score is a prediction about how cleanly a description can be transformed, not a judgment about the job or whoever wrote it. A generated role profile is a draft. Skills come from public labor-market data or from the description you uploaded, never invented by a language model.
We keep a fuller algorithmic transparency document covering the models, inputs, outputs, known limitations and human oversight. Ask support@talentguard.com for a copy.
Changes to this policy
We will update this page when what we do changes, and we will move the date at the top when we do. If a change is significant, we will say so rather than relying on you to notice a date.
Contact
Privacy questions, deletion requests and anything else about this policy: privacy@talentguard.com
Everything else: support@talentguard.com
TalentGuard, Inc.
7600 N. Capital of Texas Hwy, Building B, Suite 230, Austin, TX 78731