Kello Privacy Policy
Last updated: January 15, 2026
This Privacy Policy explains how XXV Century Private Limited, doing business as Kello (“Kello,” “we,” “us,” “our”), collects, uses, shares, and protects personal data when you:
- visit our websites (including kello.ai and guide.kello.ai),
- create an account or use our products and services (the “Services”), including TalentGPT, or
- communicate with us (sales, marketing, and support).
Contact (privacy requests, deletion requests, grievances):
Email: support@kello.ai
Company:
XXV Century Private Limited
4th Floor, SJR Primus, 5th Block, Koramangala, Bengaluru, Karnataka 560095, India
This Privacy Policy is incorporated into our Terms of Service.
Table of Contents
1. Key Definitions
- “Customer”: the company that signs up for and uses the Services (typically an employer/recruiting organization).
- “User”: an individual authorized by a Customer to use the Services (e.g., recruiters, hiring managers).
- “Candidate”: an individual whose data is processed in connection with recruiting.
- “Customer Data”: data submitted to or synced with the Services by a Customer/Users (e.g., ATS data, resumes, notes).
- “TalentGPT Data”: candidate profile data made available through TalentGPT.
- “Personal Data”: information relating to an identified or identifiable person (as defined under applicable law).
2. Our Role: Processor vs Controller (Important)
Kello can act as a processor or a controller depending on what is being processed and why:
2.1 When Kello is a Processor (Customer workspace)
For most workspace features involving Customer Data (e.g., ATS sync, resume parsing, pipeline management, notes/feedback, stage decisions), Customer is the controller/data fiduciary and Kello processes data on Customer's instructions.
2.2 When Kello is a Controller (TalentGPT + certain independent uses)
Kello acts as a controller/data fiduciary for:
- operating TalentGPT (TalentGPT Data),
- running consent-based outreach workflows for TalentGPT, and
- any processing we do for our own independent purposes described in this policy (e.g., security, fraud prevention, legal compliance, aggregated analytics).
If you are a Candidate and your data is in a specific Customer's workspace, that Customer generally controls that processing. If you are in TalentGPT, Kello handles requests as described in Section 12.
3. What Personal Data We Collect
3.1 Users (recruiters / customer admins)
We collect:
- name, work email, company name, role, account credentials/authentication information,
- workspace settings and permissions,
- usage data (e.g., feature usage, timestamps), and
- support communications.
3.2 Customer workspace data (Customer Data)
Customers may upload or sync:
- ATS data (currently Lever): candidate profiles, resumes/CVs, application history, pipeline stage decisions, and notes/interview feedback (as configured by Customer),
- uploads: resumes/CVs, spreadsheets (Excel), and recruiting documents,
- Google integrations (if enabled by Customer): Google Drive / Google Forms / Gmail data within the scopes granted (see Section 8).
3.3 TalentGPT candidate data (TalentGPT Data)
TalentGPT may include:
- professional history, skills, education, location (as available),
- links to public professional profiles (where available),
- derived attributes (e.g., normalized titles, role family, skill tags, inferred seniority bands),
- freshness metadata (e.g., last refresh timestamp, where available).
Contact details access (clear rule):
- TalentGPT does not provide Customers direct access to candidate personal email/phone by default.
- Customers cannot export TalentGPT data or access candidate contact details without candidate consent.
- Customers can initiate outreach through Kello. Only if the candidate consents (e.g., accepts being contacted or agrees to share contact details) do we facilitate a direct connection.
3.4 Website, analytics, and marketing data
We collect:
- device and usage data (IP address, browser type, pages viewed, timestamps),
- cookies and similar technologies (see Section 10),
- marketing engagement metrics (e.g., opens/clicks), where permitted.
4. Sources of TalentGPT Data and Vendor Vetting
TalentGPT profiles are sourced and refreshed using third-party data providers and other lawful sources. Providers represent that their data is obtained from public sources and handled under appropriate compliance programs (e.g., GDPR/SOC 2/ISO commitments).
Our due diligence: We vet providers, require contractual commitments around lawful sourcing, security, and compliance, and we periodically review data quality and handle suppression/deletion requests as described below.
We also use providers to refresh TalentGPT data periodically to improve accuracy and freshness.
5. How We Use Personal Data
We use personal data to:
5.1 Provide the Services
- create and administer accounts and workspaces,
- parse resumes and create structured fields,
- enable search, deduplication, analytics, and workflow features,
- sync data from Customer-connected sources.
5.2 Operate TalentGPT and run consent-based outreach
- provide candidate discovery and search,
- relay outreach on a Customer's behalf,
- manage candidate responses and consent-based connection.
5.3 Security, reliability, and support
- authentication, access controls, monitoring, logging, and abuse prevention,
- troubleshooting and customer support.
5.4 Service improvement and analytics
- improve performance, relevance, deduplication, and quality of user-facing features,
- create aggregated/de-identified metrics for internal analytics and benchmarking.
5.5 Marketing communications
- send marketing emails to prospects and Customers,
- measure campaign effectiveness (including opens/clicks), where permitted and subject to opt-out.
5.6 Legal compliance
- comply with laws and lawful requests,
- enforce our Terms and protect rights, safety, and security.
6. AI Features and Model Providers
Kello uses AI features for tasks like resume parsing, summarization, tagging, and search relevance.
We use paid enterprise offerings of AI providers (e.g., OpenAI and Google Gemini APIs) intended not to use our inputs/outputs to train their general-purpose models.
Human review: AI outputs may be inaccurate and should be reviewed by humans before use in decisions.
7. Data Contribution (Future Feature) and TalentGPT Enrichment
Our Terms of Service include a “Data Contribution” concept to improve the Services and enrich TalentGPT profiles using certain permitted subsets of Customer Data.
7.1 Status (as of this date)
As of January 15, 2026, Kello has not begun using Customer Data for Data Contribution in production.
If and when enabled, Data Contribution will operate as described in our Terms and this section, and we will update this Privacy Policy as needed.
7.2 How it will work when enabled (aligned to the Terms)
When enabled, Data Contribution is default-on (subject to opt-out). It is intended to use limited subsets of Customer Data to improve search relevance, deduplication, matching, and profile freshness.
Excluded from Data Contribution:
- internal recruiting notes, interview feedback, and evaluation comments,
- private communications between Customer and candidates,
- Customer-provided candidate personal contact details (where not already publicly available or independently sourced by Kello through TalentGPT vendors).
No customer attribution: When used for TalentGPT enrichment, Kello will not identify the Customer as the source and will not expose customer-specific signals.
7.3 Opt-out (when enabled)
Customers may opt out for future Data Contribution by emailing support@kello.ai. We will confirm the opt-out in writing.
7.4 Google-sourced data carve-out (required for Google API compliance)
If Customer connects Google Workspace APIs, we do not use Google-sourced data to develop, improve, or train non-personalized (generalized) AI/ML models, and we do not transfer Google-sourced data for that purpose. See Section 8.
8. Google Integrations (Gmail, Drive, Forms)
Customers may connect Google services after explicit authorization and granting of scopes.
8.1 Gmail (job-application emails only)
If a Customer connects Gmail, Kello uses read-only Gmail access (e.g., gmail.readonly) to identify and import only job-application emails.
How it works (limited scanning):
- We use Gmail's search capabilities (query-based filtering) to retrieve only messages that match job-application patterns—typically emails from personal/academic addresses that include a resume attachment (PDF/DOC/DOCX/ODT) or a Drive attachment/link, and contain application-related keywords.
- We exclude obvious non-recruiting categories (e.g., business pitches, investor messages, and reply chains) using filters.
- We do not scan or read your entire inbox. If an email does not match the job-application filters, we ignore it and do not import it.
What we do NOT do:
- We do not send email, create drafts, or create/modify labels.
- We do not edit, delete, or otherwise modify your mailbox.
What we store (and don't store):
- We store resume attachments (to parse/index for search) and the minimum candidate fields needed to create a candidate profile in Kello.
- We do not store your general/personal emails, non-recruiting messages, or full mailbox contents.
Visibility controls: For Gmail imports, the Customer can configure who in the workspace is allowed to view Gmail-imported items inside Kello.
8.2 Google API policy compliance (Limited Use)
Kello's use of information received from Google APIs complies with applicable Google API policies, including Limited Use requirements:
- we use Google-sourced data only to provide or improve user-facing features that are prominent in the product experience (e.g., indexing, extraction, summaries),
- we do not sell Google-sourced data or use it for advertising,
- we restrict human access and only allow it when necessary for support/security/legal compliance.
8.3 Google-sourced data and training
We do not use Google Workspace API data to develop, improve, or train non-personalized/general AI or ML models.
11. Data Retention and Deletion
We retain personal data only as long as needed for the purposes described in this policy, unless a longer period is required by law.
11.1 Customer workspace data (after termination)
- We typically make Customer Data available for export for a reasonable period (commonly up to 30 days) where technically feasible.
- After that period, we may delete Customer Data from active systems, except where retention is required for legal compliance, dispute resolution, fraud prevention, or security.
11.2 Backups (7-day retention)
Backups are retained for up to 7 days on a rolling basis. If Customer Data is deleted from active systems, it may persist in backups until those backups are overwritten (up to 7 days).
11.3 Logs and security records
We retain certain logs and related records to operate, secure, and troubleshoot the Services and to meet legal obligations. Retention may vary by category and jurisdiction, and may be longer where required by law.
11.4 TalentGPT candidate data
We may retain TalentGPT profiles on an ongoing basis to operate the product and keep data fresh, subject to:
- vendor refresh/removal events,
- do-not-contact suppression, and
- candidate deletion requests.
11.5 Do-not-contact suppression
If a candidate requests not to be contacted, we may retain minimal information necessary to honor that request (e.g., a suppression record), even if other data is deleted.
12. Your Rights and How to Exercise Them
12.1 How to submit a request
Email support@kello.ai with:
- your name,
- what you are requesting (access/correction/deletion/suppression),
- details to help us locate your data.
We may take steps to verify identity before fulfilling requests.
12.2 Candidates in TalentGPT
Candidates can request:
- access to their TalentGPT profile (where applicable),
- correction (where feasible),
- deletion, and/or
- do-not-contact suppression.
12.3 Candidates in a Customer workspace
If your data is processed inside an employer/customer workspace (e.g., via their ATS/imports), that employer/customer typically controls that processing. We may direct you to contact them, and we will assist as a processor where appropriate.
12.4 India DPDP requests and timelines
Where India's DPDP regime applies, individuals may have rights such as access, correction/updating, erasure, withdrawal of consent (where applicable), grievance redressal, and nomination.
Response timeline: We aim to respond typically within 30 days. Some requests may take longer depending on complexity and verification, but we will respond within the timelines required by applicable law (including where a maximum response period applies).
13. Data Processing Addendum (DPA)
If you are a Customer and need a Data Processing Addendum for compliance purposes (e.g., GDPR/UK GDPR, DPDP-aligned processor terms, SCCs where applicable), you can request one at support@kello.ai.
14. International Data Transfers and Data Residency
Kello's primary operations and hosting are currently in India. We may use service providers and support personnel in other jurisdictions as needed to provide the Services, subject to appropriate safeguards and applicable law.
15. Security
We maintain reasonable administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, and monitoring.
No system is perfectly secure; we continually improve safeguards.
16. Children
The Services are intended for business use and not directed to individuals under 18. We do not knowingly collect personal data from children.
17. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date and may provide additional notice.
18. Contact
XXV Century Private Limited (d/b/a Kello)
4th Floor, SJR Primus, 5th Block, Koramangala, Bengaluru, Karnataka 560095, India
Email: support@kello.ai