Contents
  1. Scope and Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. AI and Automated Decision-Making
  5. When We Share Data
  6. Third-Party Processors
  7. Data Retention
  8. Your Rights
  9. Security Measures
  10. Cookies and Tracking
  11. Children's Data
  12. International Data Transfers
  13. Changes to This Policy
  14. Contact Us

1. Scope and Who We Are

This Privacy Policy describes how AI Recruiting Assistant ("we", "us", "the Service") collects, uses, discloses, and protects personal information when you or your employer use our AI-powered recruiting and interview platform, available at www.recruitabilityai.com and related applications.

The Service operates in two modes:

2. Data We Collect

From Candidates

When a candidate participates in an interview, assessment, coding challenge, reference check, or skills matrix, we collect:

CategoryExamplesSource
IdentityName, email, phone, profile photoCandidate, invite link, OAuth provider
ProfessionalResume, work history, education, skills, certificationsCandidate upload, parsed by AI
Interview contentVideo and audio recordings, transcripts, screen recordings during coding challengesCandidate, recorded during sessions
Biometric (in some deployments)Voice characteristics used by AI interviewer; facial features during ID verificationCandidate, with explicit consent
Assessment responsesAnswers to questions, code submissions, test results, scoresCandidate during session
Device and technicalIP address, browser, OS, session identifiersAutomatically on access
Identity verificationDriver's license or passport image, extracted document fieldsCandidate upload (optional)

From Customers (Company Admins, Managers, Interviewers)

From Website Visitors

3. How We Use Your Data

We use the data listed above to:

We rely on the following legal bases under GDPR: (a) performance of a contract, (b) our legitimate interests in operating and improving the Service, (c) your or the Customer's explicit consent for recording and biometric processing, and (d) compliance with legal obligations.

4. AI and Automated Decision-Making

The Service uses AI models (including large language models, computer vision, and speech-to-text) to analyze candidate submissions. Outputs include fit scores, ranked recommendations, auto-generated questions, flagged fraud signals, and interview summaries.

AI outputs are decision-support, not final hiring decisions. Customer employees (hiring managers and recruiters) review AI outputs and make the actual hiring decision. Customers are contractually required to keep a human in the loop for every advance/reject decision.

Under Article 22 of the GDPR and similar laws, candidates in applicable jurisdictions have the right to:

To exercise these rights, contact us at privacy@recruitabilityai.com or the Customer that invited you.

5. When We Share Data

We share data only in the following circumstances:

We do not sell personal data. We do not share candidate data with advertisers.

6. Third-Party Processors

The Service depends on the following subprocessors. All are bound by written data-processing agreements:

PurposeProcessorLocation
Infrastructure hostingIONOSUS / EU
AI language modelsOpenAI, Anthropic, Google (Gemini), Groq, DeepSeek, Mistral, PerplexityUS
Speech-to-textOpenAI WhisperUS
Text-to-speechOpenAI, ElevenLabsUS
Embeddings and ML modelsOpenAI, HuggingFaceUS
Email deliverySelf-hosted Postfix SMTPUS
SMS and voiceTwilioUS
Payment processingStripe, PayPal, Square, Braintree, Authorize.netUS
Code execution sandboxPiston (self-hosted)US
Identity verificationID Analyzer, in-house AI vision (GPT-4o / Gemini)US
Teams/calendar integrationMicrosoft Graph, Google CalendarUS / EU
Analytics (optional)Google Analytics 4US
Error tracking (optional)SentryUS

A current list of subprocessors is maintained and can be provided to Customers under a Data Processing Addendum (DPA) upon request.

7. Data Retention

You or the Customer may request earlier deletion at any time, subject to legal-retention obligations.

8. Your Rights

Depending on your location, you have the following rights regarding your personal data:

Candidates can exercise these rights through the candidate portal at /candidate/privacy after logging in, or by contacting the Customer that invited them. Customer admins have admin-panel tools to handle candidate requests.

California residents have additional rights under the CCPA/CPRA, including the right to know categories of information collected and to request deletion. To submit a CCPA request, email privacy@recruitabilityai.com with "CCPA Request" in the subject line.

9. Security Measures

We implement technical and organizational measures designed to protect your data, including:

No system is fully secure. In the event of a breach affecting personal data, we will notify affected Customers and, where required, regulators within 72 hours of becoming aware.

10. Cookies and Tracking

We use a small number of cookies, categorized as:

We do not use advertising cookies or third-party ad trackers on this Service.

11. Children's Data

The Service is intended for use by adults (16+) in professional hiring contexts. We do not knowingly collect data from children under 16. If you believe we have inadvertently collected data from a minor, contact us and we will delete it.

12. International Data Transfers

We process data primarily in the United States. If you are located in the EEA, UK, or Switzerland, data transferred to us is protected by Standard Contractual Clauses (SCCs) as approved by the European Commission, and by supplementary technical measures. A copy of the SCCs is available on request.

13. Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be announced at least 30 days in advance by email to Customers and through a banner on the Service. The "Last updated" date at the top of this page always reflects the current version.

14. Contact Us

For privacy questions, data requests, or to reach our Data Protection Officer:

EU/EEA residents may also contact their local supervisory authority. UK residents may contact the ICO at ico.org.uk.