Privacy Policy

Last updated August 14, 2026privacy@reyndex.com

Overview

Reyndex is a candidate intelligence platform. It connects the Gmail mailboxes you authorize, identifies candidate-related email, turns resumes and application context into structured candidate records, and enriches those records with AI.

This Privacy Policy explains how Reyndex (“Reyndex,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you use our website, application, integrations, and related services (the “Service”). It covers the Service available today and closely related features we may add over time — we only collect and process the information needed for the features you use or authorize.

At a glance

  • We do not sell personal information or use it for advertising
  • Reyndex does not train AI models on your data
  • Gmail access follows Google’s Limited Use requirements
  • Disconnect Gmail at any time — we revoke our access
  • Connector credentials and API keys are encrypted at rest
  • Request deletion of your data at any time

This summary is for convenience — the full sections below govern

Information we collect

We collect information in the following general categories.

Account and workspace information. Information used to create and manage your account and workspace, such as your name, email address, and profile picture from Google sign-in, plus workspace name, workspace settings, team members, roles, permissions, invitations, and referral activity.

Candidate and application information. Candidate emails, resume and cover-letter files, application context, candidate contact details, profile fields, links, and structured fields generated by the Service (such as skills, experience, and education), plus file metadata, source information, and related candidate records. Candidate information may relate to people who are not direct Reyndex account users.

Gmail and integration information. If you connect Gmail or another integration, we collect the information needed to operate that connection. For Gmail, this may include mailbox identity, permission information, message and attachment data needed to identify candidate-related emails, sync status, and connector metadata. For other integrations, this may include connection metadata, destination settings, and information exchanged with the connected service.

AI processing information. When you use AI-assisted features, we may process candidate files, extracted text, email context, candidate metadata, and related prompts or outputs to parse, classify, enrich, or organize candidate records.

Billing information. If your workspace uses paid features, we collect billing and subscription information such as plan status, credits, invoices, payment status, billing profile details, and Stripe customer or subscription identifiers. Payment method details are handled by Stripe.

Usage, device, and operational information. Information needed to operate and secure the Service, such as session information, feature usage, sync status, connector health, error events, logs, audit records, and security metadata.

We also use cookies and browser storage as described in Cookies and browser storage.

How we use information

We use personal information to provide, secure, and improve Reyndex. This includes using information to:

  • authenticate users and maintain sessions
  • manage workspaces, teams, roles, and permissions
  • connect authorized Gmail mailboxes and other integrations
  • identify candidate-related emails and attachments
  • create, enrich, search, and manage candidate records
  • provide AI-assisted parsing, classification, enrichment, and workflow features
  • sync or send data to integrations you authorize
  • support connected client access when you approve it
  • process billing, subscriptions, credits, invoices, and paid-plan access
  • respond to support, privacy, security, and legal requests
  • monitor reliability, debug errors, prevent abuse, and protect the Service

We do not sell personal information. We do not use Gmail data, candidate data, or workspace data for third-party advertising.

Our roles

For account, workspace, billing, and usage information — and for visitors to our website — Reyndex acts as the data controller (in some US states, a “business”).

For candidate and application information that a workspace brings into the Service — for example, by connecting a Gmail mailbox — we generally process that information on behalf of the workspace. The workspace is responsible for its own obligations to candidates, such as providing any required notice and having a lawful basis for its recruiting activity.

If you are a candidate whose information was processed by a Reyndex customer, see Your choices and rights.

Google and Gmail data

Reyndex uses Google APIs, including Google sign-in and the Gmail API, only to provide and improve user-facing features that you authorize.

Reyndex’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

For Gmail data, this means:

  • we use Gmail data to connect authorized mailboxes, identify candidate-related messages and attachments, sync candidate intake, and support visible Reyndex features
  • we do not sell Gmail data
  • we do not use Gmail data for advertising or retargeting
  • we do not use Gmail data to create, train, or improve generalized AI or machine-learning models
  • we transfer Gmail data only as needed to provide or improve user-facing Reyndex features, comply with law, protect security, or complete a business transfer with any required consent
  • we limit human access to Gmail data to circumstances such as user-authorized support, security, debugging, abuse investigation, legal compliance, or internal operations permitted by applicable policy and law

You can disconnect a Gmail mailbox from Reyndex at any time. When a mailbox is disconnected or a workspace is deleted, Reyndex disables the connector and attempts to revoke or remove the stored credential material associated with that connector.

AI and model providers

Reyndex uses AI and model providers to help parse resumes, classify candidate-related documents, extract structured profile fields, and enrich candidate records.

Depending on the feature and your workspace configuration, candidate information is processed by third-party model providers: either providers Reyndex manages or a provider you connect with your own API key (BYOK). The providers and models available are shown in the product when you configure AI features, and we may add or remove providers over time. If you use your own key, candidate information is sent to the model-provider account associated with that key, and your provider agreement governs that processing.

The information sent to a provider depends on the feature and can include resume files and extracted text, email context, candidate profile fields, and the prompts you configure. Providers process this information to return results for your workspace and may retain and process it according to their own terms and privacy policies.

Reyndex does not use your workspace data, candidate data, Gmail data, or candidate files to train, fine-tune, or improve AI models owned by Reyndex.

How we disclose information

We disclose personal information only as needed to provide, secure, operate, and improve Reyndex, or as otherwise described in this Policy.

Service providers. We use service providers for hosting, database and file storage, email delivery, authentication, billing, payment processing, infrastructure monitoring, security, support, and AI/model processing. This includes cloud infrastructure and storage providers, payment processing by Stripe, and the model providers described above.

Integrations you authorize. If you connect Gmail, your own model-provider account, a connected AI client, or another integration destination, Reyndex may send or receive information needed to operate that integration. Some integrations may not be available in every workspace; this applies only when you use or authorize them.

Workspace members. Candidate and workspace information may be visible to workspace owners, administrators, and members according to their roles and permissions.

Connected AI clients. If you authorize a connected AI client (for example, an MCP client), that client receives read-only access to authorized workspace and candidate data through Reyndex approval and permission checks. Data returned to a connected client may be processed by that client according to its own terms and privacy practices.

Billing and payments. Stripe processes hosted checkout, payment-method update, customer portal, invoice, subscription, and fraud-prevention information according to Stripe’s own terms and privacy policy.

Legal, safety, and business transfers. We may disclose information when reasonably necessary to comply with law, enforce our terms, protect rights or safety, prevent abuse, or complete a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.

Deidentified or aggregated information. We may use and share deidentified, aggregated, or anonymized information for internal operations, analytics, security, product improvement, or reporting.

Retention and deletion

We retain personal information for as long as needed to provide the Service, maintain your workspace, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and operate billing or accounting records.

Workspace members can view and download candidate files in the application, subject to their roles and permissions.

If a paid subscription is canceled, the workspace moves to limited access; workspace and candidate data are retained unless the workspace is deleted. On the Free plan, live mailbox sync pauses when the 7-day live-sync trial window ends unless the workspace upgrades, while existing candidate-table access and remaining credits stay available under the product rules in effect.

When you delete your account, access is removed immediately and the account cannot be restored. Any workspace included because you solely own it also becomes non-restorable immediately, and its content will be permanently deleted from our active systems. If you have no active workspace memberships, contact us to request account deletion.

When a workspace is deleted, Reyndex removes member access immediately and disconnects its integrations. Deleted workspaces enter a 30-day recovery window, during which you can contact us to restore the workspace. After the recovery window ends, or after an approved earlier deletion request, workspace content is permanently deleted from our active systems and can no longer be restored. Deleted content includes workspace settings, memberships, integration connections and credentials, candidate records and files, and dashboard data.

Limited records are retained after deletion where the law requires or permits it. Billing records — including subscriptions, credits, invoices, payments, and records processed by Stripe — are kept for accounting, tax, fraud prevention, dispute resolution, audit, and legal purposes. We also keep minimal security and audit records, such as email delivery and MCP access logs. These retained records can include personal information, and we use them only for those restricted purposes; they are not used to restore a workspace or for product, AI, analytics, or marketing purposes. Residual copies in backups are removed as backups rotate, and backups are not used to restore deleted workspaces.

You can request earlier deletion as described in Your choices and rights.

Deleting a connector stops future syncing for that connector. It does not automatically delete candidate records that were already created unless those candidate records or the workspace are also deleted.

Because third-party services may process information under their own systems when you authorize or use them, deletion from Reyndex may not automatically delete copies held by those services.

Security

We use technical, administrative, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.

These safeguards include authentication, role and permission checks, server-side access controls, encryption of stored credential material, encrypted transport, limited logging practices, connector revocation flows, and operational monitoring.

No system is completely secure. You are responsible for maintaining the security of your Google account, workspace member access, connected provider accounts, and API keys you choose to connect.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, receive a copy of, or restrict the use of personal information. You may also have the right to object to certain processing, withdraw consent where processing is based on consent, opt out of certain sales or sharing (we do not sell personal information), or appeal a denied privacy request.

You can manage much of this directly in the Service — including workspace settings, members, integrations, candidate records, and connected apps — depending on your role and permissions.

To make a privacy request, contact us at privacy@reyndex.com. We may need to verify your identity and your authority to act for a workspace or candidate before fulfilling a request. We will not discriminate against you for exercising your privacy rights.

If you are a candidate whose information was processed by a Reyndex customer, we may direct your request to the relevant customer or workspace owner where that customer is responsible for the data.

International transfers

Reyndex is operated from the United States. Our primary databases and file storage are hosted in United States data centers, and some processing — such as edge request handling by our infrastructure providers — can occur in other locations. If you use the Service from outside the United States, your information is processed in countries whose privacy laws may differ from the laws where you live.

Where required, we use appropriate safeguards for international transfers, such as contractual protections or other transfer mechanisms recognized by applicable law.

Cookies and browser storage

We use cookies and browser storage to keep you signed in, protect against request forgery, remember your active workspace, and show short-lived product messages.

We do not use third-party advertising cookies, analytics trackers, or tracking pixels on the Service or our public website, and we do not track you across third-party sites.

Children’s privacy

Reyndex is not directed to children and is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Reyndex, contact us at privacy@reyndex.com.

Third-party services

The Service may link to or integrate with third-party services such as Google, Stripe, AI and model providers, connected AI clients, or other providers you authorize. Those services are governed by their own terms and privacy policies.

Reyndex is not responsible for the privacy practices of third-party services that you choose to connect or use, except where those providers process information on our behalf under our instructions.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law, which may include posting the updated Policy, updating the “Last updated” date, or sending notice to the email address associated with your account.

If we materially change how we access, use, store, or share Google user data, we will update our disclosures and obtain any consent required before using that data for a new purpose.

Contact

If you have questions or requests about this Privacy Policy or Reyndex privacy practices, contact us at privacy@reyndex.com.

For general product help, contact support@reyndex.com.

Our Terms of Service describe the agreement that governs your use of the Service.