Privacy Policy

Effective August 8, 2026 · Last updated August 8, 2026

This policy covers job seekers, employers, applicants, and visitors. It says what we collect, why, who receives it, how long we keep it, and what you can ask us to do — including the parts where an employer, not Hirefy, is the one making decisions about your data.

The short version

  • We never sell your dataNo sale, no sharing for cross-context behavioral advertising, no ad targeting — under any US state privacy law's definition of those terms.
  • Your job search is private from employersAn employer sees your information only when you apply to them or take an action that sends it. Nothing tells your current employer you are looking.
  • AI reads what you give it, and only for youWe send content to AI providers to run the feature you asked for. Your content is not used to train general-purpose AI models.
  • A person makes every hiring decisionEmployer screening can classify and suggest. It cannot advance, reject, or hire anyone — that always takes an authenticated human, a reason, and an audit record.
  • You can take your data or delete itAccess, correct, export, and delete from your account, or write to privacy@gethirefy.com. We honor Global Privacy Control signals.

This summary is for orientation only. The numbered sections below are the agreement.

1. What this policy covers

This policy explains how Hirefy ("Hirefy," "we," "us") handles personal information across everything we run: the public website and waitlist, job seeker accounts and tools, the employer workspace, public job pages and application forms, embedded widgets, published portfolio pages, and the emails we send.

It applies to four groups of people, and some sections apply to only one of them: job seekers with a Hirefy account; employer users who work inside a workspace; applicants who apply to an employer through a Hirefy-hosted page, with or without an account; and visitors to our public pages.

2. Our role: when we decide, and when an employer decides

The same company can hold different responsibilities for different data, and which one applies changes who you go to with a request.

  • For job seekers and visitors, we are the controllerWe decide why and how your information is processed, and this policy is our notice to you.
  • For applicant data inside an employer workspace, we are a processorThe employer is the controller (the “business” under US state law). They decide what to collect, what to ask, how long to keep it, and who to hire. We process it on their documented instructions under the data processing terms in our Terms.
  • What that means for a requestIf you applied to an employer, send access, correction, or deletion requests to that employer first. We will help them respond, and if you cannot reach them, write to privacy@gethirefy.com and we will do what we can as their processor.

3. What we collect

We collect what a feature needs to work, plus what is required to keep accounts secure and the service running. We do not buy personal information from data brokers.

From job seekers

  • Account and identity: name, email address, password or federated sign-in identifier, email-verification status, optional phone number.
  • Career content: resumes and other files you upload, imported career documents you supply (including a LinkedIn profile PDF you downloaded yourself), work and volunteer history, education, skills, licenses and certifications, projects, achievements, and the evidence and narratives built from them.
  • Preferences and goals: target roles, industries, locations, work setting, salary expectations, career stage, and availability.
  • Activity: saved and applied roles, application stages and outcomes, interview practice sessions, readiness and match scores, calendar events Hirefy creates, assistant conversations, notes, feedback, and support requests with any screenshots you attach.
  • Published content: anything you choose to publish, such as a portfolio page and the media on it.
  • Billing: plan, subscription status, and payment history. Card details go to Stripe and are never stored by Hirefy.
  • Identity verification, where offered and only if you start it: you submit documents directly to Stripe, and Hirefy receives the outcome — not your documents.

From employer users

  • Workspace and account: your name, work email, role in the workspace, and invitations you send or accept.
  • Organization details you enter: legal and display name, industry, size, website, locations, description, logo or storefront photo, and hiring-contact details.
  • Hiring content: job posts and their versions, criteria and application questions, interview scorecards, notes, stage history, and messages sent to applicants.
  • Billing: plan, subscription status, and payment history through Stripe.

From applicants (on behalf of the employer)

  • Contact and application data: name, email, required phone number, city and state, resume, the answers you give to the employer's questions, and any optional photo, LinkedIn, GitHub, or portfolio link you choose to add.
  • Screening output: a per-criterion result with the evidence behind it, a score, and the summary shown to the employer.
  • Process record: stage changes, who made them and when, interview details sent to you, scorecards, and employer notes about your application.
  • Whether you opted in to be contacted about the employer's future roles.

From visitors and waitlist signups

  • Waitlist: your name and email address, plus the signup source and time, delivery and subscription status, and the identifier our email provider returns. We use it to confirm your signup, hold your place, prevent duplicate or abusive signups, and send waitlist and launch updates.
  • Support: what you write to us and any screenshots you attach.
  • Nothing else. Browsing our public pages does not create a profile.

From everyone, automatically

  • Technical data: IP address, browser and device type, timestamps, referring page, authentication events, error and diagnostic logs, and security signals such as rate-limit and abuse checks.
  • Email delivery data: whether a message was delivered, bounced, or unsubscribed.
  • Page-view analytics after the cookie notice is acknowledged. See the cookies and analytics section below.

4. Where the information comes from

  • You — everything you type, upload, publish, or submit.
  • Your device and browser, automatically, when you use the Service.
  • Your sign-in provider, if you use one, which returns basic account details consistent with your settings there.
  • An employer, when they add notes, ratings, or stage decisions about an application.
  • A service you connect, such as a calendar you authorize.
  • Our providers: delivery and engagement results from our email provider, payment and verification status from Stripe.
  • Public job listing sources, for the listings themselves — these carry no personal information about you.

6. Sensitive information, and what we refuse to infer

Hirefy does not ask for special-category or sensitive personal information — racial or ethnic origin, religion, health or disability, sexual orientation, union membership, biometrics, precise geolocation, or government identifiers — and no feature requires it.

  • A resume or an answer you write may happen to mention something sensitive. When it does, we process it as ordinary content of the document you gave us, only to deliver the feature you asked for. Do not include sensitive details you do not want processed.
  • We do not infer, derive, or score protected characteristics, and we do not build profiles of them. Employer criteria that reference a protected trait, or that ask for behavioral inference, are rejected before a role can be published.
  • The Service performs no emotion recognition, facial or voice analysis, personality testing, or background, credit, or criminal-history checks. Hirefy is not a consumer reporting agency.
  • We do not use or disclose sensitive personal information for any purpose beyond those permitted under California law, so the right to limit its use has nothing to restrict.

7. AI processing and automated decision-making

AI is how several features work, so it deserves a plain description rather than a footnote.

What we send, and to whom

  • When you use an AI-assisted feature, we send the provider only what that feature needs: resume text, relevant profile fields, a job description, an application answer, or your prompt.
  • Our AI providers process it to return the result and are contractually barred from using it to train general-purpose models. We do not train models on your content either.
  • Employer screening runs the application answers and the employer's stated criteria through an automation workflow and an AI model, and returns a per-criterion verdict with the evidence behind it.

Automated decision-making

  • Hirefy produces scores and suggestions. It does not make decisions that produce legal or similarly significant effects on its own, and it is built so it cannot: advancing, rejecting, interviewing, offering, and hiring each require an authenticated human at the employer, a stated reason, and an audit record. A suggested scorecard rating is only a starting point a person must confirm or change.
  • Because a person decides, this is not solely automated decision-making under Article 22 of the GDPR. Even so, if you are an applicant you may ask the employer for human review of any decision, to express your view, and to contest it — and you may ask for an accommodation or an alternative to any automated step.
  • The logic is simple to state: your answers are compared to the criteria the employer wrote, each criterion comes back met, not met, or unclear with the text that supports it, and those results are combined into a score against a threshold the employer set. The consequence is where you appear in that employer's review queue — not an automatic rejection.

8. Cookies and analytics

  • Essential storageCookies and browser storage needed for sign-in, security, saving your cookie-notice acknowledgement, and remembering product state. Blocking them breaks parts of the Service.
  • First-party site analyticsAfter you acknowledge the notice, Google Analytics for Firebase sets first-party cookies and records page path and title, referrer, session and device details, and approximate location derived from an IP address. We do not put your name, email address, resume, profile, job-search information, or other career content in these events.
  • Your browser controlsYou can clear or block cookies in your browser. Clearing the Hirefy acknowledgement cookie makes the notice appear again; blocking essential storage can prevent sign-in and saved product state from working.
  • Global Privacy ControlWe treat a GPC or other universal opt-out signal as a valid opt-out of sale and sharing (we do neither) and of targeted advertising, applied to that browser.
  • No advertising trackersWe run no advertising pixels, no ad networks, and no cross-site tracking.

9. Who receives personal information

We share only what a recipient needs, under contracts that limit them to processing it for us. Our providers are:

  • Google Cloud / Firebase (Authentication, Firestore, Cloud Storage, App Hosting)Hosting, sign-in, database, and file storage for the whole service. Receives: Account and authentication data, profile and career content, uploaded files, employer and application records, logs. Processed in: United States.
  • Google Gemini (Google AI)Resume parsing, drafting, readiness scoring, interview practice, and employer screening analysis. Receives: The content a feature needs: resume text, profile fields, job descriptions, application answers, and prompts. Processed in: United States.
  • CareerOneStop / U.S. Department of LaborPublic Career Match skills assessment and occupation profiles. Receives: Skills-rating values, selected occupation code, and optional location. Processed in: United States.
  • Google Analytics for FirebaseSite analytics after the cookie notice is acknowledged, never for advertising. Receives: Page path and title, referrer, session and device details, approximate location from IP, pseudonymous identifier. Processed in: United States.
  • Google Calendar (only if you connect it)Creating and updating interview and follow-up events in a Hirefy-owned calendar. Receives: OAuth tokens limited to the calendar.app.created scope, plus the events Hirefy creates. Processed in: United States.
  • StripeSubscription billing and, where offered, optional identity verification. Receives: Billing contact, plan and payment status, and — for identity verification — documents you submit directly to Stripe; Hirefy receives only the verification outcome. Processed in: United States.
  • ResendSending transactional, waitlist, job-match, and employer notification email. Receives: Name, email address, delivery and engagement status, and message content. Processed in: United States.
  • n8n (workflow automation)Running employer screening and role-assistant workflows. Receives: Role criteria and the application answers being evaluated, passed through to the AI model above. Processed in: United States.
  • Job board and listing providers (Adzuna, Arbeitnow, Himalayas, Hirebase, Jobicy, JSearch, Remotive, The Muse, USAJOBS)Supplying the public job listings Hirefy searches and displays. Receives: Search terms and filters. Your profile, resume, and identity are not sent to them. Processed in: United States and other countries.
  • Logo.devCompany logos shown next to job listings. Receives: Company names and domains only — no personal data. Processed in: United States.

We also disclose information when the law requires it or to respond to a lawful request; to protect the rights, safety, or property of users, the public, or Hirefy; to our professional advisers; and, in a merger, financing, acquisition, or sale of assets, to the counterparty under confidentiality — with notice to you if the new owner would handle your information materially differently.

Employers receive the applications submitted to them. Job seekers' saved roles, drafts, scores, and search activity are never disclosed to an employer, and no employer is told that you are looking.

10. What we never do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising — including under the definitions in the California, Colorado, Connecticut, Virginia, Texas, Oregon, and other state privacy laws.
  • We have not sold or shared personal information in the preceding 12 months, and we do not sell or share the personal information of anyone we know to be under 16.
  • We do not use your content to train general-purpose AI models, and we do not let our providers do it either.
  • We do not disclose your resume or contact details to an employer or recruiter unless you take an action that sends them.
  • We do not use employer applicant data for our own purposes, to build a candidate database, or to market to applicants.

11. Retention: how long we keep it

We keep personal information only as long as the purpose requires, then delete or de-identify it.

  • Account, profile, and career content (resumes, evidence, generated documents)Until you delete the item or your account, then removed from live systems within 30 days and from encrypted backups within 90 days
  • Waitlist entriesUntil you unsubscribe or ask us to remove you, then deleted apart from a minimal suppression record
  • Email suppression records (so an opt-out is honored)Kept for as long as we send email, because deleting them would undo the opt-out
  • Employer workspace records — jobs, applications, applicant answers, screening results, scorecards, notesKept for as long as the employer's workspace is active, and at least one year from the application or personnel action so the employer can meet EEOC recordkeeping rules (29 C.F.R. § 1602.14). Deleted or returned within 90 days of workspace closure, unless the employer instructs otherwise or the law requires longer
  • Audit and security logs, including stage-change historyUp to 24 months, because they are the record of who decided what and when
  • Billing and tax recordsUp to 7 years, as tax and accounting law requires
  • Analytics events (only if you consented)Per the retention setting on our Analytics property, up to 14 months
  • Support requests and screenshotsUp to 24 months after the request is resolved

Deleting your account removes your profile, career content, and generated documents. Applications you already submitted to an employer stay with that employer, because they are the employer's record and are subject to their own retention obligations.

12. Security

We protect personal information with authenticated access, role-based permissions inside employer workspaces, server-side authorization on every data path, encryption in transit, managed cloud infrastructure with access controls, and audit logging of hiring actions. Access by our personnel is limited to what a job requires.

No online service can promise perfect security. Use a strong, unique password, sign out on shared devices, and tell us at security@gethirefy.com if you see something wrong. If a breach affects your personal information, we will notify you and the relevant regulators as the law requires — for GDPR, without undue delay and within 72 hours of becoming aware where feasible.

13. International transfers

Hirefy operates in the United States, and our providers process information there and in other countries. If you are in the EEA, the UK, or Switzerland, your information will be transferred outside your country.

  • We rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum, as our primary transfer mechanism.
  • Where a recipient is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions, we may also rely on that certification.
  • We assess the destination's laws alongside the transfer and apply additional safeguards where needed, including encryption in transit and contractual limits on government-access disclosures.
  • You can request a copy of the safeguards we use by writing to privacy@gethirefy.com.

14. Your rights, and how to use them

Depending on where you live, you have some or all of the following rights. We honor these requests for everyone, wherever we can, rather than only where a law compels it.

  • Know and accessWhat we hold about you, where it came from, why we have it, and who received it.
  • CorrectFix anything inaccurate. Most profile and career fields you can edit yourself.
  • DeleteRemove your account and content. Delete an account from account settings, ask us to erase specific records, or withdraw from the waitlist at any time.
  • PortabilityGet a copy in a portable, machine-readable format.
  • Opt outOf targeted advertising, sale, sharing, and profiling with significant effects. We do none of these, and a GPC signal is honored automatically.
  • Restrict and objectAsk us to pause a use, or object to processing based on legitimate interests.
  • Withdraw consentWhere we rely on consent, such as optional emails, at any time without affecting what happened before.
  • No retaliationWe will not deny service, charge a different price, or give you a lesser experience for exercising a right.

To make a request, use your account settings or email privacy@gethirefy.com from the address on your account. We may need to verify your identity, and we may ask for enough detail to locate the records. We respond within 45 days (extendable by 45 more with notice) under US state law, and within one month (extendable by two more) under the GDPR. An authorized agent may act for you with written permission and verification.

If we decline a request, we will tell you why, and you may appeal by replying to our decision or writing to privacy@gethirefy.com with “Appeal” in the subject. We answer appeals within 45 days and will tell you how to contact your state attorney general if you disagree.

15. If you are in the EEA, the UK, or Switzerland

This section supplements the rest of the policy and prevails for you if the two conflict.

  • Controller: Hirefy, our registered mailing address, available on request. Privacy contact: privacy@gethirefy.com.
  • Hirefy does not currently offer the Service in the EEA. Before we do, we will appoint an Article 27 representative and name them here.
  • Legal bases are listed with each purpose above. Where we rely on legitimate interests, you may object and we will stop unless we have compelling grounds that override your rights, and always if you object to direct marketing.
  • You have the rights in Articles 15 to 22: access, rectification, erasure, restriction, portability, objection, and the safeguards around automated decision-making described under AI processing.
  • Providing your information is voluntary, but some of it is necessary to create an account or apply to a job; without it, those features cannot work.
  • You may complain to your national supervisory authority, to the UK Information Commissioner's Office, or to the Swiss Federal Data Protection and Information Commissioner. We would appreciate the chance to address it first.
  • Where an employer is the controller of your application data, that employer is your first point of contact and their notice governs their use of it.

16. If you are in California

This section is our notice at collection and our CCPA/CPRA disclosure. In the preceding 12 months we collected the categories below, from the sources described above, for the purposes and legal bases listed above, and disclosed each of them for business purposes to the providers named under Who receives personal information.

  • IdentifiersName, email, phone, account and device identifiers, IP address.
  • Customer recordsContact details and payment status associated with a paid plan.
  • Commercial informationPlan, subscription, and transaction history.
  • Internet activityProduct usage, page views, and diagnostic logs; analytics events after the cookie notice is acknowledged.
  • GeolocationApproximate location from IP address, and the city or region you enter yourself. No precise geolocation.
  • Professional or employment informationResumes, work and education history, skills, licenses, applications, interviews, and screening results.
  • Education informationSchools, programs, and dates you provide.
  • InferencesReadiness, match, and fit scores derived from what you provide — never inferences about protected characteristics.
  • Audio, electronic, or visualPhotos and media you upload, such as an employer logo or portfolio image, and screenshots you attach to a support request.

We do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out is required — and we honor Global Privacy Control regardless. We do not use or disclose sensitive personal information beyond the purposes California permits, so there is nothing for a “limit the use of my sensitive personal information” request to restrict.

You may request to know, access, correct, delete, and receive a portable copy, and you may appeal a denial. Retention is described under Retention: how long we keep it. Use of your rights never results in different pricing or service.

California residents may also ask about disclosures to third parties for direct marketing under the “Shine the Light” law: we make none. Requests go to privacy@gethirefy.com.

17. If you are in another US state with a privacy law

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Rhode Island, Indiana, Kentucky, and Washington — and Arkansas from July 1, 2026 — have rights that closely track those described under Your rights: to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects.

We do not conduct targeted advertising, do not sell personal data, and do not profile in a way that produces legal or similarly significant effects without a human decision, so those opt-outs have nothing to act on — but a universal opt-out signal is still honored where your state requires it. Minnesota residents may also ask about the profiling that informs a decision and how to correct the data behind it; The AI processing section describes that logic.

Every state with an appeal right is covered by the appeal process described under Your rights. Send requests to privacy@gethirefy.com.

18. If you applied to an employer through Hirefy

Your application belongs to the employer you sent it to. This section explains what happens on our side.

  • We collect your contact details, resume, and answers to give them to that employer, and we run the screening the employer configured.
  • The employer decides how long to keep your application, who on their team sees it, and what happens next. Their retention obligations, including EEOC recordkeeping, may require them to keep it for at least a year.
  • We send you the confirmations, interview details, and status updates the employer triggers. We do not add you to Hirefy marketing because you applied.
  • An employer can save you for future roles only if you opted in; without that opt-in, the feature refuses.
  • To reach the employer's own privacy contact, use the details on the job posting. If you cannot, write to privacy@gethirefy.com and we will route it or act on their instruction.

19. Children and teenagers

Hirefy is built for people starting their careers, which includes teenagers looking for a first job, but it is not directed to children under 13 and we do not knowingly collect their personal information.

In the EEA, the UK, and Switzerland, do not use Hirefy unless you are at least 16, or the lower minimum age your country sets. If you are under the age of majority where you live, use Hirefy only with a parent or guardian's permission. If you believe a child under 13 gave us information, write to privacy@gethirefy.com and we will delete it. We do not sell or share the personal information of anyone we know to be under 16.

20. If you are an employer using Hirefy

You are the controller for the applicant data in your workspace. You need your own privacy notice for applicants, a lawful basis for what you collect, and a way to answer their requests.

Our processor commitments — instructions, confidentiality, security, subprocessors, assistance, breach notice, deletion, and audits — are in the employer applicant-data section of the Terms. For a separately signed DPA or the Standard Contractual Clauses, write to privacy@gethirefy.com. We give notice before adding a subprocessor to the list above so you can object.

21. Changes to this policy

We update this policy as the Service and the law change. The effective date at the top always reflects the current version, and we keep the substance of what changed visible in the section it affects.

For a material change in how we use personal information, we give notice by email or in the product before it takes effect, and we obtain consent where the law requires it.

22. Contact us

Privacy requests and questions: privacy@gethirefy.com. Security reports: security@gethirefy.com. General help: support@gethirefy.com or the Help and feedback link in the app. Mail: Hirefy, our registered mailing address, available on request.

We have not appointed a Data Protection Officer because our processing does not require one. Privacy requests are handled by the team reachable at the address above.