Privacy Policy

Effective Date: July 31, 2025 · Last Updated: September 4, 2026

HYRE LABS PTE LTD, operating under the brand name "Connekt" ("Connekt", "we", "us", "our"), is committed to protecting your privacy. This Privacy Policy describes how we collect, use, share, and secure personal information across the Connekt CRM Platform, Connekt Mobile App, Connekt Extension, Connekt Notetaker, and related meeting, communication, and document-processing tools (together, the "Services").

1. Introduction and Scope

This Policy applies to personal information processed through:

  • The Connekt CRM Platform (web application)
  • The Connekt Mobile App (iOS and Android)
  • The Connekt Extension (Chrome, LinkedIn data sync)
  • Connekt Notetaker (Chrome extension and automated meeting assistant for meeting recording and transcription)
  • Connekt's communications sync, document processing, and data import tools

2. Google API Services — Limited Use Disclosure

Connekt's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2.1 Google Data We Access Directly

When you connect your Gmail account for email thread sync, Connekt requests the following Google OAuth scope:

https://www.googleapis.com/auth/gmail.readonly

This scope allows Connekt to read your email messages and settings in read-only mode. Specifically, we access:

  • Email thread content (subject, body, sender, recipient, timestamp)
  • Email metadata (folder labels, read/unread status)
  • Sender and recipient email addresses

When you connect Google Calendar in the Connekt Notetaker extension, we request this separate scope:

https://www.googleapis.com/auth/calendar.events.readonly

This scope allows Connekt to read your calendar events in read-only mode. Specifically, we access:

  • The title of the calendar event associated with the Google Meet call being recorded
  • The names and email addresses of that event's attendees

Through this direct integration, we do not request access to send emails, delete emails, modify emails, or access Google Drive or any other Google product. We do not create, modify, or delete calendar events, and we do not browse or store your calendar beyond the single event tied to the meeting being recorded.

2.2 How We Use This Google Data

Gmail data accessed via the read-only scope above is used exclusively to:

  • Synchronize email threads: we retrieve email threads involving your candidates' and contacts' email addresses and display them alongside the corresponding CRM record.
  • Match conversations: we match email senders and recipients against email addresses stored in your Connekt CRM. Only emails that match a known candidate or contact are stored; all other emails are discarded immediately.

This data is not used for advertising, profiling, training AI/ML models, or any purpose beyond displaying your own email history within Connekt.

Calendar data accessed via the read-only scope above is used exclusively to:

  • Enrich meeting notes: when you record a Google Meet call with Connekt Notetaker, we look up the matching calendar event and use its title and attendee list to fill in the title and attendees on the generated meeting notes.

Calendar data is looked up silently in the background only during an active recording — connecting your calendar never triggers a surprise sign-in prompt mid-meeting.

For Google Meet specifically, Connekt can also join a call as an automated meeting assistant using a dedicated, separately authenticated bot account, rather than the Gmail or Calendar APIs described above. This method does not access your personal Gmail or Calendar data.

Use of Google Data with AI/ML Models

The meeting title and attendee names sourced from Google Calendar are passed, together with your call's transcript, to a large language model (Google Gemini, accessed via the OpenRouter API) solely to generate the AI title and summary shown on your meeting notes. This data is not used to train, fine-tune, or improve any foundational or generalized AI/ML model. Our OpenRouter account is configured to route these requests only through providers under Google's paid Vertex AI terms, which do not use submitted data for model training, and first-party/free-tier endpoints that may train on data are disabled at the account level.

Limited Use Compliance: the use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.

2.3 Connekt Communications Sync (LinkedIn, Gmail, Outlook Messaging)

Separately from the read-only Gmail integration above, Connekt offers an optional Communications Sync feature that lets you connect your LinkedIn messaging account and your Gmail or Outlook mailbox to send and receive messages from within Connekt and keep a synced conversation history against your candidate and contact records. This feature is brokered through our messaging infrastructure provider, Unipile, which manages the connection and OAuth relationship with LinkedIn, Google, or Microsoft on our behalf and stores the resulting account tokens — Connekt's servers never receive or store your LinkedIn, Google, or Microsoft password, and this feature is only active for accounts you explicitly connect. Because this integration can send as well as receive messages, its scope is broader than the read-only Gmail sync described in Section 2.1; if you connect a Gmail or Outlook account for Communications Sync, treat that as a separate, explicit authorization distinct from the read-only email sync.

2.4 Sharing of Google User Data

We do not sell, rent, or trade Google user data. We do not share Google user data with third parties except in the following strictly limited circumstances:

  • Infrastructure providers: Supabase (database hosting) and our cloud infrastructure providers store and serve your data as data processors, contractually prohibited from using it for any purpose other than providing the service to us.
  • Legal obligations: we may disclose data if required by law, court order, or to protect the rights and safety of our users or the public.

No Google user data is shared with advertising networks, data brokers, or analytics platforms.

2.5 Storage and Protection of Google User Data

  • Encryption in transit: all data transferred between your browser, our servers, and Google APIs is encrypted using TLS 1.2 or higher.
  • Encryption at rest: email content stored in our database is encrypted at rest.
  • Access controls: only authenticated users can access their own Gmail data within Connekt; our engineers access production data only when required for support or incident resolution, under strict access controls.
  • OAuth tokens: Gmail read-only OAuth tokens are stored securely via Nylas (our email API infrastructure provider) and are never exposed in logs or client-side code. Calendar OAuth tokens are managed entirely by Chrome's built-in Identity API on your device and are never transmitted to or stored on Connekt's servers. Communications Sync tokens (Section 2.3) are held by Unipile.
  • Minimal data principle: we only store email threads that match a candidate or contact in your CRM. For Calendar, we only retain the event title and attendee list of the specific meeting you recorded.

2.6 Retention and Deletion of Google User Data

Retention period: synced email data is retained for as long as your Connekt account is active and the Gmail integration is connected. Email threads older than 90 days that no longer match active CRM records are automatically purged.

Disconnecting Gmail: you can revoke Connekt's access at any time by:

  • Going to Settings → Integrations → Gmail → Disconnect within Connekt, or
  • Visiting Google Account Permissions and revoking access for Connekt.

Upon disconnection, we immediately invalidate your OAuth token. All previously synced Gmail data associated with your account is deleted within 30 days.

Disconnecting Calendar: you can disconnect Google Calendar at any time from the Connekt Notetaker extension's settings. Disconnecting immediately revokes the OAuth grant directly with Google, not merely hiding the permission from Connekt's UI.

Account deletion: when you delete your Connekt account, all associated Google user data is permanently deleted within 30 days. To request deletion, email privacy@letsconnekt.com or use the account deletion option in your settings.

3. Information We Collect

From the CRM Platform and Mobile App

  • Account information: name, email address, company details, and billing information.
  • Recruitment data: candidate and contact records, resumes and attachments, employment/education history, compensation details, company and job data, notes, and internal HR/leave records you or your team enter.
  • Communication records: messages, notes, and interaction history you create within the platform, plus synced LinkedIn/email conversations where you enable Communications Sync.
  • Meeting data: audio/video recordings, transcripts, AI-generated summaries, and action items from meetings you record with Connekt Notetaker.
  • Device and usage information: browser type, operating system, IP address, device identifiers, and push-notification tokens.

From the Connekt Extension (LinkedIn)

  • Profile information: names, job titles, company names, contact information, and other professional details from LinkedIn profiles you choose to extract.
  • Usage data: pages visited on LinkedIn and extraction activity within the extension.
  • Authentication data: session tokens used to sync with your Connekt CRM account.
  • Supplementary enrichment data: when a LinkedIn page doesn't fully load the fields we need, the extension asks our backend to fill the gaps using a third-party data provider, passing the LinkedIn URL you're viewing.

4. How We Use Your Information

  • Provide and operate the CRM platform, mobile app, extensions, and meeting tools
  • Sync extracted LinkedIn data and connected email/messaging conversations with your CRM account
  • Generate AI-assisted meeting summaries and extract structured data from resumes and job postings
  • Process payments and manage your subscription
  • Send service-related communications, push notifications, and support responses
  • Improve our services and develop new features
  • Ensure security, detect abuse, and prevent fraud
  • Comply with legal obligations

5. AI and Automated Processing

Certain features rely on third-party AI, machine-learning, and speech-processing providers to function, including:

  • AI chat, summarization, and extraction: meeting summaries and titles, resume and job-posting field extraction, and in-app AI chat are generated using large-language-model providers accessed through a model-routing gateway. Content sent may include meeting transcripts, resume text, job descriptions, and chat prompts.
  • Speech-to-text: a speech-processing provider transcribes meeting audio into text during recording.
  • Document parsing: a document-processing provider extracts structured data (and performs OCR where needed) from uploaded resumes, contracts, and job postings.

We configure our AI providers, where the option is offered, to not use your content to train their general-purpose models. AI-generated output may contain errors; you are responsible for reviewing it before relying on it. See Section 2 for the specific AI provider and no-training terms that apply to Google Calendar and meeting data.

6. Service Providers

We use third-party service providers to operate the Services. Each acts as a data processor under contract and is prohibited from using your data for any purpose other than providing services to us. These fall into the following categories:

  • Hosting, database, and file storage — for application hosting, our database, authentication, and stored files/attachments.
  • Cloud object storage — for documents and meeting recordings.
  • Search infrastructure — for in-app search across your CRM records.
  • Payment processing — for subscription billing; we do not store your full card details.
  • Transactional email delivery — for account, invite, and billing notifications.
  • Messaging and calendar integrations — the infrastructure providers that broker your optional LinkedIn, Gmail, Outlook, and Calendar connections, described in Section 2.
  • Webhook delivery infrastructure — for reliable event delivery between our own services.
  • AI, speech-to-text, and document-parsing providers — described in Section 5.
  • Contact and company data enrichment providers — used to supplement LinkedIn profile and company data the Connekt Extension couldn't fully read from the page, and to improve or fill in candidate/company contact details and firmographic data you request within the product.
  • Error tracking and product analytics — to diagnose bugs and understand product usage (web and mobile).
  • Bot and abuse protection — for forms and account security.
  • Push notification delivery — for the mobile app.
  • Customer support tooling — for in-app support chat in the mobile app.

7. Information Sharing

We do not sell your personal information.

We may share information in these limited circumstances:

  • Service providers: the sub-processors listed in Section 6, each contractually bound to protect your data.
  • Legal requirements: when required by law, legal process, or to protect our rights and safety.
  • Business transfers: in connection with mergers, acquisitions, or a sale of assets, with advance notice to affected users.
  • With your consent: when you explicitly authorize us to share specific information.

8. Data Security

We implement industry-standard security measures, including:

  • Encryption: data encrypted in transit (TLS 1.2+) and at rest.
  • Access controls: secure authentication and restricted, need-to-know access to personal information.
  • Monitoring: regular security review and continuous monitoring.

9. Data Retention and Deletion

  • Active accounts: we retain your data for as long as your account is active or as needed to provide the Services.
  • Meeting recordings and transcripts: retained for as long as your account remains active, or until you delete a specific meeting note; we permanently delete associated recordings and transcripts within 30 days of account closure or a specific deletion request.
  • Account deletion: when you delete your account, all personal data is permanently deleted within 30 days, except where retention is required by law.
  • Gmail integration data: deleted within 30 days of disconnecting your Gmail account or deleting your Connekt account — see Section 2.6.
  • Calendar integration data: only the event title and attendee list of meetings you actually recorded are retained, as part of that meeting's notes — see Section 2.6.
  • To request deletion: email privacy@letsconnekt.com with the subject line "Data Deletion Request." We will confirm and complete deletion within 30 days.

10. Your Rights and Choices

You have the right to:

  • Access: request a copy of your personal information.
  • Correct: update or correct inaccurate information.
  • Delete: request deletion of your personal information.
  • Export: download your CRM data in a portable format.
  • Opt-out: unsubscribe from marketing communications.
  • Revoke: disconnect Google, LinkedIn, or email/messaging integrations at any time.

To exercise these rights, contact us at privacy@letsconnekt.com.

11. Browser Extension Disclosures

Connekt Extension

  • Single purpose: extracts candidate, contact, and company information from LinkedIn pages you're viewing and creates or updates the matching record in your Connekt CRM account, including checking for duplicates against existing records.
  • LinkedIn-specific scraping and CRM sync only activate on linkedin.com and its subdomains, using the page's own LinkedIn session — the extension does not collect or store your LinkedIn login credentials.
  • When a LinkedIn page doesn't fully load the fields we need, the extension asks our backend to supplement the record using a third-party data provider, passing the LinkedIn URL you're viewing — see Section 6.
  • A lightweight script also runs on other pages you visit, solely to install a Trusted Types security policy that lets the extension's own code run on sites that enforce Trusted Types; it does not read or transmit content from those pages, and the extension's LinkedIn-specific logic stays inactive outside linkedin.com.
  • Reads your existing Connekt session cookie (from letsconnekt.com only) so you stay signed in without repeated logins; it does not access or read LinkedIn's session cookie through this mechanism, and no cookie value is shared with third parties.
  • Can be uninstalled at any time through Chrome's extension management.

Connekt Notetaker

  • Only captures meeting audio/video while you actively start a recording on Google Meet, Zoom, or Microsoft Teams.
  • Streams audio to our meeting service for live transcription (Deepgram) and uploads the final recording to secure cloud storage.
  • Can be uninstalled at any time through Chrome's extension management; disconnecting Google Calendar revokes that grant directly with Google.

12. Mobile Application Disclosures

  • Device permissions: the app may request camera, microphone, and photo library access for profile photos, document scanning, and meeting recording. You can manage these in your device settings at any time.
  • Push notifications: delivered via Firebase Cloud Messaging and Notifee using a device token; you can disable notifications in your device settings.
  • Crash and error reporting: Sentry collects crash diagnostics, which may include your user ID and email address, to help us fix bugs.
  • In-app support chat: if you use the in-app support widget, your messages and basic account details are shared with Crisp to provide customer support.
  • Sign-in: you may sign in with Google via Google Sign-In; we receive your name, email address, and profile photo from Google for account creation.

13. Children's Privacy

Our Services are intended for business use by adults and are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at privacy@letsconnekt.com so we can delete it.

14. International Data Transfers

Connekt is operated by HYRE LABS PTE LTD from Singapore, and our infrastructure and sub-processors listed in Section 6 may store or process data in other countries, including the United States. Where we transfer personal data internationally, we rely on the safeguards required by applicable law (such as standard contractual clauses) to protect your information.

15. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected and how it's used
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising privacy rights

16. European Privacy Rights (GDPR)

If you are in the European Economic Area, you have additional rights under the General Data Protection Regulation:

  • Legal basis: we process your data based on contract performance, legitimate interests, and consent.
  • Privacy contact: reach us at privacy@letsconnekt.com for privacy-related inquiries.
  • Supervisory authority: you may file complaints with your local data protection authority.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email, a notice on our website, or an in-service notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

18. Contact Us

This Policy is provided by HYRE LABS PTE LTD, operating as Connekt. If you have questions about this Privacy Policy or our data practices, contact us: