Privacy Policy
Effective date: July 15, 2026
Controller: The Support Lab, United States
Contact: support@jeshe.co
This Policy explains how The Support Lab handles personal information across our websites, applications, Transcription Lab, Offerward, and related scheduling, communications, reporting, and automation services. We do not sell personal information or use it for behavioral advertising.
1. Our role
We generally act as controller for account data, individual Offerward workspaces, saved voice profiles, and direct support interactions. For organization-managed workspace content, the organization may be the controller and The Support Lab may process information on its instructions.
2. Information we collect
- Account data, including email, account-wide profile name, tenant memberships, roles, preferences, and legal acceptance records.
- Career and interview data, including resumes, profile facts, stories, role targets, job descriptions, research, prep material, live-session notes, and outcomes.
- Meeting and transcription data, including audio you choose to capture or upload, transcripts, speaker labels, summaries, action items, and review edits.
- Communications and integration data needed for connected features, such as OAuth tokens and provider configuration.
- Operational data, including timestamps, usage metering, provider status, latency, errors, device and browser details, and general IP-derived location.
- Optional saved voice profile data described below.
3. Audio, transcription, and AI processing
When you start a recording, upload audio, request transcription, or use live assistance, we and the selected speech or AI providers process the audio and related text needed to perform that request. Local-only audio remains on the recording device unless you explicitly approve a cloud audio operation. Realtime transcript text, session metadata, and generated outputs may still be sent to and stored by the Service according to the selected feature and workspace policy.
4. Optional saved voice profile
A saved voice profile is a mathematical representation derived from your voice and may be considered biometric or sensitive information in some jurisdictions. It is used only to estimate whether speech in an authorized Transcription Lab or Offerward session matches the enrolled account user. It is not used to authenticate your account, establish legal identity, infer emotions or protected traits, or identify unrelated people.
Creating a persistent profile requires a separate affirmative consent. Guided enrollment audio is held in browser memory, sent over an encrypted connection to an authenticated Support Lab server, and processed in memory to create and quality-check the profile. Short excerpts from an authorized live session may be processed the same way to estimate a match. The voice matcher does not store those raw enrollment or matching excerpts. Any separately approved session-audio retention remains governed by that workspace's audio policy. The mathematical profile is encrypted before database storage. Your account-wide profile name is used as the default label. Other speakers remain generic or manually named unless a separate, authorized matching basis exists.
You may use core features without saving a voice profile. You may disable future matching or delete the stored profile from Preferences. We delete it after a deletion request or account closure, subject to short-lived backup and security processing, and in any event no later than three years after your last interaction with us unless a shorter period is required by law. Consent and deletion audit records may be retained as required to demonstrate compliance.
5. How we use information
- Provide, personalize, and maintain requested features.
- Transcribe audio, separate and label speakers, generate reviewed outputs, and support interview preparation.
- Authenticate accounts, isolate tenant data, enforce settings, meter usage, and prevent abuse.
- Diagnose errors, monitor provider performance, recover interrupted sessions, and improve reliability and quality.
- Respond to support requests, communicate material service changes, enforce terms, and comply with law.
6. Legal bases
Where applicable, we rely on contract to provide requested services, legitimate interests for security and service operations, legal obligation for compliance, and consent where required. We rely on separate consent to create and retain an optional saved voice profile. Withdrawing that consent does not affect processing that was lawful before withdrawal.
7. How we disclose information
We disclose information only as needed to operate the Service, including to hosting and database providers, speech-to-text and AI providers selected for a feature, authentication and email providers, operational monitoring services, and integrations you enable. Providers receive only the information reasonably needed for their task and are subject to contractual or platform restrictions. We may also disclose information for lawful requests, safety, fraud prevention, or a protected business transaction.
8. Google and other connected accounts
If you connect Google or another provider, we request only permissions needed for the selected feature and store tokens only to maintain that connection. Our use and transfer of Google user data complies with the Google API Services User Data Policy, including Limited Use. You can disconnect in the Service or revoke access through the provider.
9. Retention
Retention depends on the data and workspace policy. Account data is generally retained while an account is active and deleted or anonymized within 12 months after closure unless law requires longer. Technical and security logs are generally retained up to 12 months; support and compliance records up to 24 months or as legally required. Audio retention follows the session's local or cloud policy. Transcript content and generated outputs remain until deleted or the applicable workspace retention rule runs. Saved voice profiles follow the shorter schedule in Section 4.
10. Security
We use reasonable safeguards such as encryption in transit, encryption at rest where supported, additional application-layer encryption for saved voice profiles, role-based access, tenant isolation, and audit events. No system can guarantee absolute security.
11. International processing
Primary processing occurs in the United States. Where required, international transfers use recognized legal safeguards, including provider Standard Contractual Clauses.
12. Your rights and choices
Depending on your location, you may request access, correction, deletion, portability, restriction, or an appeal, and may object to or withdraw consent for certain processing. Manage profile and saved voice settings in Preferences or email support@jeshe.co. For organization-controlled content, we may direct the request to that organization. We do not discriminate for exercising privacy rights.
13. Children
The Service is not intended for anyone under 18, and we do not knowingly collect their information.
14. Cookies
We use cookies and similar storage needed for authentication, security, preferences, and service operation. We do not use advertising cookies in the authenticated Service. Blocking required cookies may prevent sign-in.
15. Changes and contact
We may update this Policy and will post a new effective date. Material changes may require a renewed acknowledgement or consent. Questions and privacy requests may be sent to support@jeshe.co.