Privacy Policy
Tahoe is built for recruiter workflows that touch candidate data, Google sign-in, Gmail-native outreach, the optional Tahoe for LinkedIn browser extension, and optional publishing to your own LinkedIn profile. Tahoe also offers employers an optional AI phone pre-screen for job applicants, which records the call. This page explains what we collect, why we use it, how Google API data is handled, what the Chrome extension does, how the phone pre-screen works and what rights a job applicant has over their own recording, and what U.S. privacy rights users may have.
If you are a JOB APPLICANT who took, or was offered, an AI phone pre-screen, section 6.2 is written for you. It explains what is recorded, who can hear it, how long it is kept, and how to listen to or remove your own recording.
1. Scope and role
This Privacy Policy explains how WorkOnward ("Tahoe," "we," "us," or "our") collects, uses, stores, discloses, and protects personal information when you use tahoe.workonward.com, create an account, sign in with Google, connect a Gmail or Google Workspace mailbox, search for candidates, or otherwise interact with the Service. This Policy is written for U.S. business use and should be read together with the consent screens and in-product disclosures shown when you authorize Google access.
2. Information we collect
- Account and profile information, such as your name, work email address, password hash, organization details, and account preferences.
- Authentication information from Google Sign-In, such as your Google account identifier, basic profile details, and email address, to the extent you authorize them.
- Mailbox connection and Gmail API data if you connect a mailbox, including OAuth refresh tokens, mailbox address, send settings, message metadata, thread metadata, message content you instruct Tahoe to process, and reply status information needed to send or monitor outreach from your own inbox.
- LinkedIn publishing data if you connect a LinkedIn account, including the access token LinkedIn issues (stored encrypted), its expiry, your LinkedIn member identifier and display name, the permissions you granted, and the identifier and timestamp of posts published through Tahoe. See section 6.1.
- Recruiting workflow data, such as search prompts, filters, saved candidates, lists, notes, enrichment requests, campaign drafts, sequence content, mailbox health data, and usage history.
- Chrome extension data if you install the Tahoe for LinkedIn browser extension, including the LinkedIn profile sections visible on a page you choose to save (name, headline, location, profile photo, About, work experience, education, certifications, skills, projects, publications, patents, courses, honours, languages, volunteering, organisations, test scores and recommendations, together with any contact details LinkedIn already displays to you on that page) and the Tahoe authentication token used to make extension requests as you.
- Job application data when someone applies to a role hosted on Tahoe, such as name, email address, phone number, résumé file, answers to the employer’s application questions, and the application’s status history.
- AI phone pre-screening data if an applicant chooses to take the optional pre-screen call, including an audio recording of the call, a written transcript, structured answers extracted from that transcript, an AI-written summary and suggested next step, the phone number the call was placed from, call time and duration, and a record of the permission that was given. See section 6.2.
- AI app connection data if you connect an AI app to Tahoe, including the app’s identity, the workspace and permissions you chose, the requests the app makes on your behalf, the IP address they come from, and an audit record of each action. See section 6.4.
- Technical and device data, such as IP address, browser type, device information, approximate location inferred from IP, logs, timestamps, session identifiers, and security telemetry.
- Support and communications data, such as messages you send to support or legal contacts and related troubleshooting materials.
- Billing or payment-related data if paid features are enabled, typically through our payment providers rather than directly in Tahoe.
3. How we collect information
- Directly from you when you register, sign in, complete forms, configure campaigns, save candidates, request enrichment, contact support, or otherwise use the Service.
- From Google when you sign in with Google or connect a Gmail or Google Workspace mailbox using OAuth.
- From the Tahoe for LinkedIn browser extension, if installed, when you affirmatively choose to save, enrich, or act on a LinkedIn profile you are viewing.
- From third-party data providers and integrations that supply candidate, enrichment, or operational data that you request through the Service.
- Automatically through logs, browser storage, security monitoring, and similar technical means used to operate and secure the Service.
4. How we use information
- Provide, maintain, secure, and improve the user-facing features of Tahoe.
- Authenticate you, manage accounts and sessions, and prevent abuse, fraud, or unauthorized access.
- Process recruiter workflows, including candidate search, list management, enrichment, Gmail-native outreach, reply detection, and related operational analytics.
- Provide support, troubleshoot problems, communicate service updates, and respond to legal or security issues.
- Enforce our Terms, protect our rights, protect users and third parties, and comply with applicable law.
- Operate billing, credits, payment processing, and service administration if paid features are enabled.
5. Google Sign-In, Gmail API data, and Google limited-use commitments
When you use Google Sign-In or connect a Gmail or Google Workspace mailbox, Tahoe requests only the scopes needed for the features you choose to use. Tahoe’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google account data to authenticate you and manage your Tahoe account.
- We use Gmail API data only to provide user-facing recruiting features that are prominent in Tahoe, such as sending outreach from your mailbox, monitoring replies, and displaying mailbox status or thread context.
- We do not sell Google user data, use it for advertising, use it to determine credit-worthiness, or transfer it to data brokers or information resellers.
- We do not use Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine learning models.
- We limit human access to Google data except where necessary for support you request, security investigation, legal compliance, or other circumstances allowed by Google policy and applicable law.
- If Tahoe changes how it uses Google data in a materially different way, we will update this Policy and, where required, obtain updated consent before that new use begins.
6. Tahoe’s Chrome extension ("Tahoe for LinkedIn")
Tahoe offers an optional Chrome browser extension, "Tahoe for LinkedIn," that lets a signed-in Tahoe user save and enrich LinkedIn profile information from within LinkedIn’s own website. The extension only operates on linkedin.com and tahoe.workonward.com, and only acts on a profile you are actively viewing or an action you affirmatively take, such as clicking Save, Reveal Email, Reveal Phone, or Request Connection.
- The extension reads the Tahoe authentication token already stored in your browser for tahoe.workonward.com so that extension requests are made as you, the signed-in user, subject to the same account permissions as the main Tahoe product.
- When you choose to save a LinkedIn profile, the extension captures the profile sections that page displays to you and sends them to Tahoe’s backend over an encrypted connection, where they are stored as a candidate or contact record in your Tahoe workspace, the same as if you had entered or imported them yourself. That includes the top card (name, headline, location, profile photo, current company and title, connection and follower counts, and pronouns where shown), the About text, and the profile’s sections: work experience, education, certifications, skills, projects, publications, patents, courses, honours and awards, languages, volunteering, organisations, test scores and recommendations. Recommendations include the name, headline, stated relationship and profile link of the person who wrote them. It also captures any contact details LinkedIn already displays to you for that person, which can include email addresses, phone numbers, websites, an X/Twitter handle and a birthday. To complete sections LinkedIn truncates, the extension may open that profile’s own “Show all” pages in the background, exactly as you could by clicking them.
- The extension does not read or transmit LinkedIn data beyond the profile described above, it captures only profiles you choose to save, and it does not run on any site other than linkedin.com and tahoe.workonward.com. Nothing is inferred or fabricated to fill a gap: a section LinkedIn does not show you is not captured, and a section that comes back incomplete is recorded as incomplete.
- The extension requests two Chrome permissions — storage, to keep your session token, settings and a small local list of saved profiles on your own device, and scripting, used solely to load the extension’s own bundled scripts into a linkedin.com or tahoe.workonward.com tab that was already open before the extension was installed, updated or enabled. It also requests host access to linkedin.com, tahoe.workonward.com and Tahoe’s backend API domain. It does not request or use broader browsing history, other open tabs, or other websites, and it does not download or execute any code that is not shipped inside the extension package.
- We do not sell, rent, or transfer LinkedIn or extension-collected data to third parties, and we do not use it for advertising, cross-context behavioral advertising, determining creditworthiness, or training generalized artificial intelligence or machine learning models.
- Data captured through the extension becomes part of your Tahoe workspace data and is subject to the same retention, security, and deletion practices described elsewhere in this Policy. Uninstalling the extension stops future data capture; it does not delete records already saved to your Tahoe workspace, which you can delete from within Tahoe.
6.1 LinkedIn publishing (optional connected LinkedIn account)
Tahoe can draft a hiring post for you without any LinkedIn account connection: the draft is text you copy and publish yourself. Separately, you may choose to connect your personal LinkedIn account so that Tahoe can publish a post to your own LinkedIn profile. Connecting is optional, is initiated by you, and uses LinkedIn’s standard OAuth consent screen.
- If you connect LinkedIn, we store the access token LinkedIn issues to us in encrypted form, its expiry date, your LinkedIn member identifier (the person URN), the permissions you granted, your LinkedIn display name, and, where LinkedIn provides it, the email address on that LinkedIn account.
- We request only the permissions needed to sign you in and to post as you (currently openid, profile, email, and w_member_social). We do not request or use permissions to read your LinkedIn connections, messages, invitations, or feed.
- Tahoe publishes only the exact text you have reviewed and confirmed in the Tahoe interface. Nothing is posted automatically, on a schedule, or without that confirmation. We record the identifier and timestamp of posts published through Tahoe so you can see what was sent.
- We do not sell or rent LinkedIn account data, do not use it for advertising or cross-context behavioral advertising, and do not use it to train generalized artificial intelligence or machine learning models.
- You can disconnect at any time in Tahoe, which deletes the stored token from our systems. LinkedIn keeps its own record of the authorization, so to remove Tahoe on LinkedIn’s side as well, use LinkedIn Settings and Privacy, Data privacy, Other applications, Permitted services.
- LinkedIn access tokens expire, and Tahoe cannot renew them silently without you, so you may be asked to reconnect periodically. If you never connect an account, none of the data in this section is collected.
6.2 AI phone pre-screening of job applicants
Some employers using Tahoe offer an optional AI phone pre-screen. An applicant calls a published number from the phone they applied with, enters the Job ID, and — if they agree — is connected to an AI assistant that asks the employer’s screening questions. The call is recorded. It is always optional: an applicant can apply, and be considered, without taking it, and declining is not reported to the employer as a negative signal. Tahoe provides this feature to the employer; the employer decides whether to use it and is the party that keeps the resulting application records.
- BEFORE ANY RECORDING STARTS, the caller is told — aloud, in full — that the call will be recorded, that the interview is conducted by an AI and not a person, that an AI will score the answers and give the employer a written summary and a suggested next step, that the result affects where they appear in the employer’s list of applicants, that a person at the employer makes every hiring decision, who can access the recording, which service providers handle it, how long it is kept, and that they will be emailed a link to hear it or ask for its removal.
- Permission is then asked for explicitly. The caller may press 1 or say that they agree to continue, press 2 to decline, or press 3 to reach a person and answer the same questions in writing instead. Nothing is recorded unless permission is given. Applicants may also give this permission in writing on the application form before they call, in which case the disclosure is still read aloud but no keypress is required — a keypress cannot be the only way to agree, because it is not reachable for a caller using a telephone relay service.
- WHAT IS CAPTURED: an audio recording of the interview, a written transcript, structured answers extracted from that transcript, and an AI-written summary with a suggested next step. Tahoe records the permission itself as a separate, dated evidence record, including the version of the script that was read.
- WHO CAN ACCESS IT: recruiters at the employer that posted the role, and the platform operators who run the hiring board (WorkOnward and, for boards it operates, DHD). It is not published, not sold, not shared with other employers, and not used for advertising.
- SERVICE PROVIDERS involved in the call: Twilio (telephony, and the SMS verification code used when someone asks for a removal), ElevenLabs (the conversational voice AI that conducts the interview), OpenAI and Anthropic (extracting structured answers from the transcript and writing the summary), and DigitalOcean (hosting and encrypted storage). Recordings, transcripts, and answers are encrypted at rest.
- MODEL TRAINING: Tahoe does not use recordings, transcripts, answers, or summaries to train generalized artificial intelligence or machine-learning models. Our voice provider’s own training practices are governed by our agreement with that provider. Where we have confirmed an opt-out and its effective date, we will state that date here; until we have, we do not claim it, and the disclosure read to callers does not claim it either.
- AUTOMATED PROCESSING: the summary and the suggested next step are produced by an AI system and are advisory. They do not by themselves reject an applicant, and Tahoe does not make hiring decisions. Employers are separately responsible for any bias-audit, notice, or record-keeping duties that apply to automated employment decision tools in their jurisdiction — see our Terms.
- VOICE DATA: Tahoe uses the recording to transcribe what was said and to produce the summary described above. Tahoe does not use it to identify a caller biometrically, does not build a voiceprint for recognition, and does not match a caller’s voice against other recordings. Laws on voice and biometric data vary by state; if you have a question about how your recording was handled, contact us using section 14.
- AGE: the pre-screen is offered to applicants who are 18 or older.
6.3 Your recording: listening to it, and having it removed
If you took a pre-screen call, the recording is yours to hear and yours to withdraw from the employer. After the call we email you a link to listen to your own recording, transcript, and extracted answers, and a second link to have it removed. Both choices also remain available on your application status page after those emailed links expire, so losing the email does not cost you the right. In the uncommon case where two applications to the same role share one phone line, we deliberately send no email at all and the choices appear only on each application’s own status page — a link that could reach the wrong person is worse than no link.
- REMOVAL IS IMMEDIATE AND UNCONDITIONAL. As soon as you confirm, the employer and the platform operators lose access to the recording, the transcript, the extracted answers, and the AI summary; our voice provider’s copy is deleted; and the emailed links stop working. Your written application is unaffected and stays under review.
- The employer is told nothing that identifies the removal as your choice. Where a recruiter had already opened the screening, they see a neutral note that there is no pre-screening on file and that the application should be evaluated on the written materials — with no date and no attribution.
- BECAUSE THE REQUEST IS IRREVERSIBLE, we check it is you. We text a short code to the number the call was placed from. If that number cannot receive a text, that is never a refusal: removal from the employer still happens immediately and a person completes the identity check. You can also simply email us and we will do it for you.
- YOU CAN UNDO IT. Every removal is followed immediately by an email telling you it happened, with a link to restore the recording. Nothing is destroyed during that window.
- WHAT WE MUST KEEP, AND WHY. U.S. employment law requires employers to preserve application records — generally at least one year, longer for federal contractors, and up to four years for automated-decision-system data where California rules apply, and for as long as any discrimination charge or legal hold relating to the role remains open. So after removal we keep one encrypted copy that nobody at the employer can access, and destroy it automatically when that period ends. We also keep the dated record that you gave permission to be recorded, because it is the evidence the recording was lawful, and a log of the request itself. If a legal hold delays destruction we tell you, and give you a reference you can quote.
- A recruiter’s own written notes about an interview are the employer’s record rather than a copy of your recording, and are retained by the employer. Your phone company keeps its own record that a call took place, which we cannot delete.
- If an AI mis-heard you, tell us and we will pass your correction to the employer alongside the screening. We do not alter the transcript itself, because changing a record of what was said is not a correction.
6.4 AI apps you connect to Tahoe
Tahoe lets you connect an AI app, such as Claude, ChatGPT, Gemini, Microsoft Copilot, Cursor, VS Code, or Meta Muse, to your Tahoe account, so that you can ask the app to search, read, and make changes in Tahoe on your behalf, within the permissions you approve. This feature is called Tahoe MCP. Connecting is optional and is started by you. You sign in on Tahoe’s own pages using OAuth, choose one workspace for the connection, and approve the permissions the app may use. The AI app never receives your Tahoe password. Workspace owners and admins decide whether members may connect AI apps, which apps are allowed, and what those apps may do. If no AI app is connected to your account, Tahoe collects none of the connection data described in this section.
- What the AI app receives: only the results of the requests you make through it, limited by the permissions you approved, your role in the workspace, and your workspace’s settings. Depending on what you ask, results can include, for example, candidate profiles, job and applicant details, and, when you ask for them and have permission, contact details or phone-screen transcripts. By connecting an AI app, you direct Tahoe to provide those results to it.
- How the AI app handles that data: the app processes the results it receives under its provider’s own terms and privacy policy and any agreement between you or your organization and that provider. Tahoe does not control how the app stores, uses, shares, or deletes that data, and this Policy does not cover it. To find out how an app handles your conversations, or to delete data it holds, use that app’s settings or contact its provider.
- What Tahoe receives: the requests the app makes on your behalf, the app’s identity, and the IP address each request comes from. Tahoe also keeps a record of the connection itself: the app, the workspace, the permissions you approved, and when the connection was last used. Changes the app makes at your request, such as a search it runs or a note it adds, are stored in your workspace like any other Tahoe data and are covered by the rest of this Policy.
- Audit records and logs: Tahoe keeps an audit record of each action an AI app takes, showing the app, the person, the workspace, the type of action, its result, any credits used, the IP address, and the people whose contact details, résumés, or phone screens were returned. An audit record keeps identifiers, counts, and categories from the request rather than its full content. Audit records are kept for 400 days, and workspace owners and admins can review them in Tahoe. Tahoe also keeps operational logs for 14 days; they leave out access credentials and request contents, and mask email addresses and phone numbers.
- How long access lasts: the access an AI app holds is valid for 15 minutes and is renewed automatically while you use the connection. The app can no longer renew it after 30 days without use, or 90 days after you approved the connection, whichever comes first. After that, you must sign in and approve the connection again.
- No training, sale, or advertising: Tahoe does not use data from AI app connections, including the requests an app makes and the results Tahoe returns, to train artificial intelligence or machine learning models. We do not sell that data, and we do not use it for advertising or cross-context behavioral advertising.
- Disconnecting: you can disconnect an AI app at any time in Tahoe under Settings, Connected apps. Access stops within about 30 seconds. You can also remove Tahoe in the AI app’s own settings, but not every app tells Tahoe when you do, so disconnecting in Tahoe is the way to be sure access has ended. Workspace owners and admins can disconnect members’ connections and can turn off AI apps for the workspace. Tahoe also ends all of your connections when you change or reset your password or change your email address, and ends your connections to a workspace when you are removed from it. Disconnecting does not delete data an AI app has already received, and does not delete the audit records described above.
- If you are a candidate or job applicant: a recruiter at an employer that uses Tahoe may use an AI app to view information that employer holds about you in Tahoe, such as your profile, your application, or a phone-screen transcript. The employer chooses that app, and the app handles the information under the employer’s agreement with the app’s provider. If you remove your phone-screen recording under section 6.3, AI apps can no longer retrieve it from Tahoe, but Tahoe cannot delete a copy that an app received before the removal.
- Questions and deletion requests: for questions about AI app connections, or to ask us to delete data described in this section, contact [email protected] with the subject line "Privacy Request." Section 10 explains how we handle these requests.
7. How we disclose information
Tahoe does not sell personal information and does not share personal information for cross-context behavioral advertising.
- Service providers and subprocessors that help us host, secure, support, or operate the Service, subject to contractual confidentiality and security obligations.
- Telephony, voice-AI, and language-model providers used to deliver the optional AI phone pre-screen, currently Twilio, ElevenLabs, OpenAI, and Anthropic, as described in section 6.2.
- The employer that posted a role, and the platform operators who run the hiring board, for applications and pre-screening results submitted to that role.
- Third-party integrations or providers you direct us to use, such as Google, enrichment vendors, analytics providers, or payment processors.
- AI apps you connect to Tahoe, which receive the results of the requests you make through them, as described in section 6.4.
- Professional advisors, corporate affiliates, or transaction counterparties in connection with financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.
- Law enforcement, regulators, courts, or other parties where disclosure is required to comply with law, enforce our rights, investigate abuse, or protect users, third parties, or the public.
8. Data retention
We retain personal information for as long as reasonably necessary to provide the Service, maintain account functionality, satisfy security and fraud-prevention needs, resolve disputes, comply with legal obligations, and enforce our agreements. Retention periods vary by data type and business need. Where feasible, we delete, anonymize, or de-identify data when it is no longer needed.
- Pre-screening recording, transcript, extracted answers, and AI summary: kept for the period published on the applicant’s own removal page, and longer where the law requires an employer to preserve application records — generally at least one year, two years where the employer is a federal contractor, up to four years for automated-decision-system data where California rules apply, and until final disposition of any discrimination charge or legal hold covering the role.
- The dated record that an applicant gave permission to be recorded is kept separately from the recording and outlives it, because it is the evidence the recording was lawful.
- Encrypted database backups roll off on their own schedule after a removal, which is why a removal takes effect on the live service immediately rather than waiting for backups to expire.
- Call metadata such as the time, duration, and outcome of a call is retained after the recording itself is destroyed, with the caller’s phone number redacted.
9. Security
We use administrative, technical, and physical safeguards designed to protect personal information in transit and at rest. Those safeguards may include encryption, access controls, authentication controls, environment segregation, logging, vendor oversight, and incident response procedures. No system is perfectly secure, and we cannot guarantee absolute security.
10. Your choices and U.S. privacy rights
Depending on where you live and the nature of our processing, you may have rights to request access, correction, deletion, portability, or information about how we use your personal information. You may also have the right to appeal certain decisions or opt out of certain processing where applicable law provides that right. To exercise privacy rights, contact us at [email protected] with the subject line "Privacy Request." If we are required to verify your identity, we will use the information you provide only for verification and request-handling purposes.
- For California residents, this Policy is intended to support disclosures commonly associated with CalOPPA and the CCPA/CPRA, including categories of personal information collected, sources, purposes, sharing practices, and how to submit requests.
- If Tahoe is subject to a law requiring a response timeline, we will respond within the timeline required by law, which for certain U.S. state requests is commonly 45 days with extensions where permitted.
- If you are an authorized agent submitting a request on someone else’s behalf, we may ask for proof of authorization and identity verification as permitted by law.
- If you took an AI phone pre-screen, you do not need to make a formal request to hear or remove your recording — sections 6.2 and 6.3 describe the self-service route, and it works whether or not a privacy law gives you the right. Where retention of one encrypted copy is necessary to comply with an employer’s record-keeping obligations, we may keep it after removal; U.S. privacy laws expressly allow a deletion request to be limited on that basis.
- Applicants who need a non-telephone alternative, an accommodation, or help from a person at any point can reach us at the address in section 14, and doing so will not disadvantage an application.
11. Cookies, local storage, and similar technologies
Tahoe uses browser storage, session storage, local storage, and similar technologies to maintain sessions, preserve workflow state, secure the Service, and improve reliability. On Tahoe’s public pages, our consent manager stores consent state in the `tahoe_cookie_consent` cookie and allows users to turn optional analytics on or off. Tahoe uses Google Analytics across the site, including the signed-in product, to measure visits, engagement, and sign-up intent. Until a user turns analytics on, that measurement runs in a cookieless mode: no analytics cookie or device identifier is written or read, so measurements cannot be linked across visits or back to an individual. Turning analytics on allows Google Analytics cookies (`_ga` and `_ga_*`) and the linked-session measurement they enable. Tahoe may also store authentication tokens, temporary workflow state, and feature-related settings in your browser. We do not currently use these technologies to build advertising profiles for cross-context behavioral advertising, and users can reopen Tahoe’s public-page preferences through the site’s “Cookie settings” control.
12. Children’s privacy
Tahoe is intended for recruiters, employers, and other business users and is not directed to children under 13. If we learn that we collected personal information from a child in violation of applicable law, we will take reasonable steps to delete it.
13. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date on this page and, where required, provide additional notice or obtain consent before material new uses of personal information begin.
14. Contact
Questions, privacy requests, Google-data questions, extension-related questions, and legal notices relating to this Privacy Policy may be sent to [email protected] or by mail to WorkOnward, 124 E 14th St, New York, NY 10003. If Tahoe later designates a dedicated privacy or legal contact address, that address will control for future requests once posted here.
Relevant standards and policies
Tahoe’s disclosures are informed by Google’s OAuth and Gmail API requirements, FTC security guidance, and California privacy transparency requirements. You can review those materials here:
AI in hiring: the rules we build against
The pre-screening disclosures in sections 6.2 and 6.3 are written against the U.S. rules that govern recorded interviews, employment record-keeping, and automated employment decision tools. Employers using the feature have their own duties under several of these — see the Terms.
- EEOC: employment record-keeping requirements (29 C.F.R. §1602)
- NYC Local Law 144: automated employment decision tools
- EEOC guidance on AI and the ADA in hiring
- California Civil Rights Department: automated-decision systems in employment
- Illinois Biometric Information Privacy Act (740 ILCS 14)
- FCC guidance on call recording and consent