Privacy and Security
What happens to the information you put into this tool, which companies touch it, where it lives, and who can see it.
Login
Open this part of the privacy information.Expand or collapse the explanation under this heading.
Choose how to set up your passkey
A passkey lets you sign in without creating a Recruiter password. Choose where to set it up.
Use this device
Save a passkey using this device. Confirm with your fingerprint, face, or device password.
Use another device
Scan a QR code with your phone and follow the prompts to save your passkey.
What happens next
Your browser opens a window to finish setup. You may see Passwords, 1Password, or another password manager. Your selection determines where the passkey is saved.
The screens vary by browser and device. The QR code may appear under More options. You may also see a security-key option, which is for a separate physical device.
Signing in again
Enter your email and choose to sign in with a passkey. Follow the prompts to use your saved passkey.
If your passkey is on another device, you may need that device nearby to approve sign-in.
How this protects your account
Your passkey is created for your Recruiter account. Your device or passkey manager, such as Apple Passwords or Google Password Manager, keeps the private part.
We store the public part, which lets us verify your sign-in. Recruiter does not receive your fingerprint, face scan, or device password.
Keep a way back in
Confirm your email to enable email sign-in if your passkey is unavailable. You can also add another passkey in Account settings.
What we do with your data
Open this part of the privacy information.Expand or collapse the explanation under this heading.
Résumés and notes stay on our server. Before any résumé text is sent to a model, the application removes names, email addresses, phone numbers, street addresses, links, and social handles. The model sees the experience and skills, not the person. Candidate names and file names stay on our server and are shown to you only.
Where data is stored
Open this part of the privacy information.Expand or collapse the explanation under this heading.
You can delete your Recruiter account from Account settings.
You can delete your Recruiter account from the Account page.
When you create an account, we store your name, company, email, and sign-in details. A passkey’s private key stays with your device or passkey provider. Confirm your email to enable email sign-in.
Signup details also go to Alaïa, Assad’s business system, for follow-up. Unreviewed details are removed after 180 days, or when you delete your Recruiter account. If Assad has used them to create an approved business relationship, that relationship follows Alaïa’s normal retention rules.
Data lives in a single database on a server we run at Fly.io. Backups stay on that same server. Connections use HTTPS. Deleting your account removes the roles you own and your access to roles shared with you. Contributions to someone else’s role stay with that role.
Who else sees it
Open this part of the privacy information.Expand or collapse the explanation under this heading.
We share data with the partners below and no one else. Nothing is sold. Nothing is used for advertising. Assad runs the server and can read stored data when needed to operate or support the tool.
Anthropic Claude models
Open this part of the privacy information.Expand or collapse the explanation under this heading.
- What they receive
- Redacted résumé text, your profile text, and job listings, sent through their API to produce ratings and drafts.
- Their policy, in short
- Inputs sent through the API are not used to train their models. Requests are kept for a limited time for abuse monitoring, then deleted.
- Read it
- Privacy PolicyRead the provider’s published policy.Open the linked document for the provider’s own explanation.Commercial TermsRead the provider’s published policy.Open the linked document for the provider’s own explanation.
OpenAI GPT models
Open this part of the privacy information.Expand or collapse the explanation under this heading.
- What they receive
- The same redacted text, profile text, and job listings, when a task is routed to an OpenAI model.
- Their policy, in short
- Data sent through the API is not used to train their models by default. Requests are kept for a limited time for abuse monitoring, then deleted.
- Read it
- Privacy PolicyRead the provider’s published policy.Open the linked document for the provider’s own explanation.API Data UsageRead the provider’s published policy.Open the linked document for the provider’s own explanation.
Fly.io Hosting
Open this part of the privacy information.Expand or collapse the explanation under this heading.
- What they receive
- The running application and its database, on hardware they operate.
- Their policy, in short
- Fly.io runs and stores the application. They access customer data only to operate the platform, on your request, or when law requires it.
- Read it
- Privacy PolicyRead the provider’s published policy.Open the linked document for the provider’s own explanation.
Limits
Open this part of the privacy information.Expand or collapse the explanation under this heading.
Identifier removal in Recruiter uses local pattern matching. Unusual formats can slip through. Scanned images are rejected until a text version is supplied.