Your data, in plain English.
Here's what we keep, what we don't, and how to delete it. The legal version is below if you need it — every clause maps to something concrete you can do from your settings page.
1. Who we are
Tevos is an AI-matched job platform operated by Tevos Labs ("we", "us", "Tevos"). We are registered at Gurgaon, Haryana, India. Questions about this policy can be sent to [email protected].
2. What data we collect
- Account information — name, email, password hash, role (candidate or recruiter), optional username.
- Profile data — skills, work experience, education, CV/resume uploads, location, salary expectations, portfolio links.
- Usage data — job matches generated, applications submitted, messages exchanged, pages viewed, search queries.
- Device and browser data — IP address (derived country/city), user-agent string, referrer, timestamps.
- OAuth data — if you sign in with Google or Microsoft, we receive your basic profile (name, email, avatar) under the scopes you approve. We do not read your email or calendar.
- Analytics — we use Cloudflare Web Analytics, which is cookieless and shows us aggregated page-view and feature-usage metrics. No third-party ad trackers.
3. Why we collect it
We use your data to match candidates to jobs, authenticate sessions, prevent fraud and abuse, and improve the platform under legitimate interest. We never sell personal data to advertisers.
4. Legal basis (GDPR)
- Consent — for optional features such as marketing emails and weekly digests.
- Contract — to deliver the matching service you signed up for.
- Legitimate interest — fraud prevention, security, and platform improvements.
5. How we share data
- Recruiters — see only what a candidate explicitly publishes on their Tevos profile. Candidates can hide fields, lock their profile, or delete it at any time.
- Third-party processors — hosting (AWS), email delivery (SMTP provider), and the AI providers listed in section 5a below.
- Aggregated statistics — we publish anonymized market data (e.g. median salary by role) that cannot be tied to any individual.
- Legal requests — we disclose data only when required by a valid legal order.
5a. AI processing — what runs where
Two kinds of AI run on your data, and they are not the same:
- Local, on Tevos servers — CV parsing and match narratives run on a model we host ourselves. That data does not leave our infrastructure.
- Third-party LLM APIs — when you generate a cover letter or a job brief, parts of your profile may be sent to one of these providers: Cerebras, Mistral AI, Google Gemini, or Groq. The fields sent are: your name, current role, city, and profile headline/summary (plus the job description, which is not your data). We do not send your email, phone number, CV file, or salary figures to these providers.
If every third-party provider is unavailable, the same generation falls back to our local model.
5b. WhatsApp notifications
If you add a phone number, we send transactional messages (interview confirmations, application status) and — only if you opt in — job alerts over WhatsApp. Delivery is handled by MSG91 or Twilio, who process your phone number and the message content to deliver it. You can switch alerts off in Settings at any time; transactional messages stop when you remove your number or delete your account.
5c. Crawled job-market data
Tevos crawls publicly posted job listings from company career sites and ATS endpoints to power matching and market statistics. This corpus is about jobs, not people — it contains no candidate personal data. Aggregates derived from it are published only under our k ≥ 12 anonymity floor (see section 6a).
5d. Staff access
Authorised Tevos administrators can access uploaded documents (e.g. your CV) for support and moderation purposes. This access is being audit-logged.
6. How long we keep data
Your profile is retained for as long as your account is active. After you delete your account, we retain a minimal record for up to 12 months for legal, audit, and fraud-prevention purposes, then purge it. Anonymized statistics (with no personal identifiers) may be retained indefinitely.
6a. Aggregated benchmarks after deletion
When you delete your account, we may retain a single de-identified, bucketed snapshot of your role and compensation for the sole purpose of publishing anonymised salary benchmarks (think Levels.fyi, AmbitionBox, or Glassdoor's pay tab). The snapshot contains only: role family (e.g. "data engineer"), level (entry / mid / senior / lead / principal), city tier (tier-1, metro-eu, etc., never the exact city), country code, years-of-experience bucket (0–2, 3–5, 6–9, 10–14, 15+), current and expected CTC bands (e.g. "20–30 LPA", never the raw number), broad industry, and a one-way hashed cohort identifier so we can deduplicate re-signups. We do not retain your name, email, employer name, exact city, exact CTC, or any other identifier that can be linked back to you.
We never publish a benchmark cell smaller than k = 12 contributors, so no individual can be re-identified from the bucket they fall into. The legal basis for this retention is GDPR Article 6(1)(f) (legitimate interest in publishing aggregated market intelligence) read with Recital 26 (anonymous data is outside the scope of the GDPR), the research/statistical-purposes exemption under §17(1)(c) of India's DPDP Act 2023, and the de-identified-data exemption at §1798.140(m) of the CCPA/CPRA.
Opt out at any time. You can disable benchmark contribution for future deletion in Settings → Data & benchmarks, or request full erasure including the anonymised snapshot by emailing [email protected] and citing GDPR Article 17 (or your local equivalent). We will honour the request within 30 days.
7. Your rights
You can exercise all of the following rights at any time:
- Access — request a copy of the data we hold about you.
- Correction — edit your profile directly in the app.
- Deletion — delete your account via Profile → Delete account.
- Portability — export your profile as JSON from settings.
- Opt out — unsubscribe from marketing or alert emails using the link at the foot of any such email.
- Complaint — lodge a complaint with your local data protection authority (for EU/UK residents).
8. Cookies
We use a single essential session cookie to keep you signed in. Page views and feature usage are measured with Cloudflare Web Analytics, which is cookieless — it sets nothing on your device. We do not set third-party advertising cookies.
9. Children's privacy
Tevos is only for users aged 16 and over. We do not knowingly collect data from anyone younger. If you believe a minor has registered, email [email protected] and we will delete the account.
10. International transfers
Tevos is hosted in India. When the AI features in section 5a use a third-party provider, the named profile fields may be processed outside India: Cerebras and Groq in the United States, Mistral AI in the European Union, and Google on its global infrastructure. Each transfer is governed by that provider's data-processing terms.
10a. India — DPDP Act 2023
Tevos processes personal data of users in India under the Digital Personal Data Protection Act, 2023.
- Grievance Officer — write to [email protected]. We respond within 30 days.
- Escalation — if you are not satisfied with our response, you have the right to complain to the Data Protection Board of India.
- Consent withdrawal — withdraw consent at any time from your account settings, or by writing to the grievance address above. Withdrawal does not affect processing that already happened.
11. Updates to this policy
If we make a material change, we will notify you by email at least 30 days before the new policy takes effect. The effective date at the top of this page always reflects the current version.
12. Contact
Questions, data-subject requests, or complaints: [email protected] · Gurgaon, Haryana, India