Privacy Policy
Last updated 24 August 2026
1. Who we are
Telos is a career search tool operated from the United States and reachable at support@usetelosapp.com. This policy covers usetelosapp.com and the application at app.usetelosapp.com.
2. What we collect
What you give us
- Account details. Your email address and a password, which is stored only as a one-way hash by our authentication provider. We never see your password.
- Resume content. The text of any resume you upload, plus the file name and the label you give the version.
- Job records. Companies, roles, links, locations, salary figures, status, dates, notes, and any job description text you paste or upload.
- Anything you type into the advisor. Chat messages are kept so the conversation has memory across sessions.
What the app generates
- Match scores, matched and missing requirements, recommended certifications and actions.
- Employer legitimacy verdicts and the flags behind them.
- Career roadmaps, milestones, and your progress against them.
What we record automatically
- Usage counts. Which AI action ran and when, so monthly limits can be enforced and costs tracked. This is a count and a timestamp, not the content of the call.
- Sessions. If you choose "keep me signed in", we store a hash of a random token and its expiry date. The token itself is only ever held by your browser.
- Server logs. Standard web server records, including IP address, kept briefly for security and debugging.
We do not use advertising cookies, analytics trackers, session recording, or third party marketing pixels on this site or in the app.
3. Why we hold it
Every category above exists to deliver a feature you actively used: to score a resume we need the resume, to build a roadmap we need your history, to enforce a monthly limit we need a count. We do not collect data speculatively in case it is useful later.
4. AI processing
Telos uses the Anthropic Claude API to generate scores, employer checks, roadmaps, and advisor replies. When you run one of those actions, the relevant content, which may include your resume text and the job description, is sent to Anthropic to produce the result.
Your content is not used to train Anthropic's models. Anthropic processes it to return the response and retains it only as long as its own commercial API policy requires. You do not need your own AI account, and you are not charged per call.
If you would rather no AI ever see a particular document, do not upload it. Tracking, pipeline metrics, and notes all work without any AI call.
5. Who else touches your data
Only the services required to run the product:
- Supabase for authentication and the PostgreSQL database.
- Amazon Web Services for hosting, storage, and content delivery.
- Anthropic for AI processing, as described above.
We do not sell personal information, we do not share it for cross context behavioural advertising, and there is no advertising business here to sell it to. If Telos is ever acquired or shut down, you will be told before your data moves anywhere, with enough notice to export it.
6. How long we keep it
- Account content is kept until you delete it or delete your account.
- Session tokens expire after 30 days, and expired ones are purged.
- Usage counts are kept for billing and capacity planning. When you delete your account they are removed with the rest of your records.
- Cost records for AI calls are kept as financial records, with your identity stripped off them at deletion so the money is still accounted for but you are not in the ledger.
7. Your rights
Two of these are buttons rather than requests, which is the point:
- Export. Profile, then Account, then "Prepare my data export" gives you a JSON file containing everything Telos holds about you.
- Delete. The same tab erases every record. It is immediate and it cannot be undone. Export first if you want a copy.
- Correct or object. Email support@usetelosapp.com and we will respond within 30 days.
If you are in California, the EEA, or the UK, the rights your law grants you, including access, portability, correction, erasure, and the right to complain to a supervisory authority, are honoured through the same channels. We do not discriminate against anyone for exercising them.
8. Security
Traffic is encrypted in transit with TLS. Passwords are hashed by our authentication provider and never stored by us. Session tokens are stored only as hashes, so a copy of the database does not let anyone sign in as you. The admin view requires an owner account plus a second password.
No system is perfect. If we discover a breach affecting your data, we will tell affected users by email without unnecessary delay and describe what happened plainly.
9. Children
Telos is not directed at anyone under 16 and we do not knowingly collect their data. If you believe a child has created an account, email us and it will be removed.
10. Changes
If this policy changes in a way that materially affects your rights, the date above changes and account holders are emailed. Continuing to use Telos after a change means you accept it.
11. Contact
Questions, requests, or complaints: support@usetelosapp.com.