Privacy & security

Your candidates stay yours.

Matching stays on Sonder’s servers. Your agency controls access, sharing and export. Here is how it works.

Configuration checked 3 October 2026. See our privacy policy for the full terms.

  • Inside Sonder Matching and scoring run on our servers. CVs are never sent to an AI provider for scoring.
  • Off by default Optional AI narration waits for a workspace owner's switch, and every call is logged.
  • Separate workspaces Every query is scoped to your workspace. Your pool never trains another agency's ranking.
  • Yours to take Download a full backup at any time. Deleting a candidate deletes their records.
The data path

Where a CV goes when Sonder scores it.

The scoring path never leaves Sonder. The only door to an AI provider is a narration switch that a workspace owner has to turn, and it never touches the score.

An illustration of what the switch in Team → Data path does. Try it: the wording path changes, the ranking does not.

Inspect the example data pathMatching model, fallback, wording and ranking
Data path readout Illustrative values
Matching engine
Local embeddings · bge-small-en-v1.5, in-process. CVs are never sent to an AI provider for scoring.
Inside Sonder
If the model can't load
Falls back to TF-IDF matching, still inside Sonder, with a banner on screen. Never to an API.
Inside Sonder
Narrative layer
Evidence-grounded templates · no language model in the loop.
Inside Sonder
Ranking
Arjun Mehta 82% · Vikram Rao 70% (sample). The same with narration on or off.
Unchanged

Example ledger · narration is off; no request goes to an AI provider.

At our 3 October 2026 review, optional AI narration had no provider configured. This is an interactive illustration. Your workspace shows the live data path for its current configuration. Changing this example does not change your workspace or send any data.

Ten clauses

Ten controls. Plainly explained.

Open a control to see how it works, what is recorded and where your workspace settings matter.

Scoring runs inside Sonder.

Matching and scoring run inside Sonder, on our servers, using a local embedding model and a skill vocabulary. CVs are never sent to an AI provider for scoring. No generative language model produces a score, so turning narration on or off changes the wording, never the ranking.

AI narration is optional, and off by default.

A separate narration layer can put the evidence into sentences. Only a workspace owner can switch it on, from Team → Data path. The workspace shows which path is active, and every switch and every cloud call is recorded in the decision ledger. No switch, no call. Where a provider is configured and the owner enables narration, the provider is Anthropic. Narration is currently off on sonderai.in.

  • Owner-only switch
  • Logged in the ledger
Your workspace is walled.

Every query is scoped to your workspace. Ask for a record that belongs to another workspace and the answer is “not found”. Your pool never trains another agency's ranking. Feedback adjusts the ranking in your workspace only.

  • Scoped queries
  • No cross-agency training
Clients see what you reveal.

Shortlist links and the client portal show no names, emails or phone numbers, and hide identifying employer and date lines. Clients see rank, title, years, fit, strengths and how many matched skills the CV backs up. Every link can be revoked, and rotating a portal link kills the old one.

Access is deliberate.

Teammates join as an owner or a member. The billing profile, logo, offer template, identity-document downloads and bulk document export are owner-only. Two-factor sign-in with an authenticator app is there for anyone who wants it, with one-time backup codes, and a code can't be replayed.

  • Owner and member roles
  • Optional two-factor
Sessions end when they should.

Sign-in uses HttpOnly cookie sessions with an idle timeout and a hard maximum. Changing your password ends every other session. Sign-in and code requests are rate-limited, and every change is CSRF-protected. Disabling a departing teammate ends their sessions and extension tokens straight away.

  • HttpOnly cookies
  • Idle and hard limits
  • Instant offboarding
Joining documents are encrypted before storage.

Joining documents (marksheets, degree, Aadhaar, PAN, bank proof, experience letters) are encrypted with AES-256-GCM before storage. Identity documents are owner-only to download, and every download is logged.

  • AES-256-GCM
  • Downloads logged
Consent is stored, not assumed.

Consent is captured at the moment of collection. Unreviewed inbound profiles are purged after 30 days, and documents of candidates who dropped out or declined are purged 30 days after their process ends. A candidate's WhatsApp opt-out is recorded and blocks WhatsApp Business API sends when that service is enabled. Messages you send from your own WhatsApp remain under your control.

  • DPDP Act 2023
  • Retention clock
You can leave with your data.

Download a full backup of your workspace at any time, even after a trial or plan lapses; bulk document export asks for your password again. Snapshots run automatically every week. Deleting a candidate removes their evaluations, notes, pipeline records and encrypted documents. A whole workspace is deleted on request, within 30 days.

  • Full backup
  • Weekly snapshots
  • Deletion that deletes
Learning stays yours, and reversible.

Your thumbs up and thumbs down, and your clients' verdicts, nudge per-skill weights for your workspace only. The nudge is capped at ±5 points per candidate, shown on your dashboard, and undone if the feedback is cleared.

  • Per workspace
  • Capped
  • Undoable

Under the DPDP Act 2023, your agency is the data fiduciary for the data in your workspace, and Sonder processes it on your instructions.

Clause 04, in the product

What a client actually sees.

A ranked shortlist with strengths and evidence. Names, contact details and your private notes stay out of the client’s view.

Candidate shortlist · Cedar Labs (sample)sonderai.in
The client's anonymised shortlist: candidate one appears as Senior Java Developer, 7 years, 82% Strong match, with strengths, an evidence count and Yes, Maybe or Pass buttons, and no name or contact details (sample data)
Real Sonder screen · sample people and roles
  1. A title, never a name.

    Candidates appear as rank, title and years. No name, email or phone number reaches the page.

  2. Strengths and an evidence count.

    “3 of 3 matched skills verified from the CV.” Your notes and the gaps you plan to probe stay with you.

  3. Yes, Maybe or Pass.

    The client answers with an optional note, and the verdict lands back in your pipeline.

  4. Revocable at any time.

    Revoke the link and it stops working. Your own preview never counts as the client opening it.

Boundaries

What Sonder deliberately does not do.

The lines the product holds on your behalf, whichever plan you are on.

You send recruiting outreach yourself.

Messages are drafts you read and edit. Sending happens one candidate at a time, on your click. There are no bulk blasts and no automated sequences.

It does not scrape job boards.

The Resdex side panel assists inside a tab you opened, on searches you run, on your own account. Every step is your click.

It does not decide who to reject.

Scores order your attention. There is no auto-reject, no auto-advance and nobody hidden. Every call about a person stays human.

Who else handles your data

The services Sonder runs on.

A hosted app depends on a few providers. Here is each one, what it does for Sonder, and when it is involved.

View the service providersPurpose and when each one is used
Sonder's service providers, what each does, and when it is involved
ProviderWhat it does for SonderWhen it is involved
RailwayHosting and the databaseAlways
S3-compatible storageEncrypted joining documents; workspace backupsAlways
ResendEmail sent from Sonder's own domainAlways
SentryError reports, so problems get fixedAlways
GoogleSign in with GoogleIf you sign in with Google
RazorpayListed for payments in our privacy policyWhere enabled
Meta · WhatsApp BusinessWhatsApp messagesOnly if used
AI provider · AnthropicNarration wording, never scoringWhen configured and owner-enabled

Our providers may store or process data outside India.

No advertising or tracking cookies, only the sign-in cookie that keeps you signed in.

Questions

What agencies ask us about data.

Does candidate data go to an AI provider?

Not for matching or scoring. Both run inside Sonder, on our servers. A separate, optional AI narration layer is off by default; only a workspace owner can switch it on, and every switch and cloud call is logged in the decision ledger.

Where is our data kept?

Sonder runs on Railway for hosting and the database, with S3-compatible storage for joining documents and workspace backups. Our providers may store or process data outside India. The full list of providers is above.

Who is responsible for candidate data under the DPDP Act?

Your agency is the data fiduciary for the data in your workspace, and Sonder processes it on your instructions. Consent is captured at the moment of collection, and unreviewed inbound profiles are purged after 30 days.

What happens when a recruiter leaves?

Disable them in Team. Their sessions and extension tokens end straight away. If they come back, re-enabling restores their account and history.

Can we take everything with us?

Yes. Download a full backup of your workspace at any time, even after a trial or plan lapses. Bulk document export is owner-only and asks for your password again. Whole-workspace deletion is done on request, within 30 days.

Can candidates opt out of WhatsApp?

Yes. Sonder records opt-outs and blocks WhatsApp Business API sends when that service is enabled. Today, Sonder opens a draft in your own WhatsApp; you review and send it yourself. An opt-out in Sonder cannot block messages sent separately from your own WhatsApp.

Questions, data requests or a grievance?

Write to shourya@sonderai.in. A person reads every message, and we usually reply within one working day.

Bring your next role into Sonder.

Start a fresh workspace. Add a requirement. See the whole process in one place, with the data path in plain view.

14 days free. No credit card required. Sign up with Google or email.