RecruitAI (“we,” “us,” “our”) operates a multi-agent recruitment intelligence platform on web and Android (Expo / React Native). By using RecruitAI you agree to this policy. Contact: santhisridinesh@gmail.com • Site: https://recruitaiofficial.vercel.app.
Who we are — Data Controller
RecruitAI is operated by the RecruitAI team. For privacy inquiries contact santhisridinesh@gmail.com. We are the controller for account and usage data; for candidate resumes you upload, you are the controller and we act as processor on your behalf. We handle requests within 30 days.
Data we collect
2.1 Account & authentication
- Email address, password hash (or Google OAuth identifier) and Supabase user ID.
- JWT validated server-side — we never store raw passwords.
2.2 Content you provide
- Job descriptions, resumes/CVs, rubric notes, chat messages, campaign sessions.
- PDF/DOCX/TXT parsed to text and scoped to your account.
2.3 Automatically collected
- Device info (OS, model), app version, crash logs, performance diagnostics.
- Usage analytics (screens, campaigns, ingestion) — aggregated, no personal IDs.
- IP address for rate limiting & security, retained briefly.
2.4 We do not collect
- Background location, contacts, SMS, call logs, biometrics, advertising IDs.
- We never sell data or use it for advertising.
How we use your data
- Provide core features: parsing, pgvector search, rubric scoring, blind redaction, interview/outreach drafting, analytics, ATS export.
- Authenticate you, enforce Row-Level Security so you only access your own data.
- Improve reliability — error diagnostics, LLM failover (Gemini ↔ Groq), support.
- Comply with law and enforce Terms.
Legal bases (EEA/UK): contract, legitimate interests (security, improvement), consent for optional content, and legal compliance.
AI processing & third-party services
We transmit only the minimum context for the task to:
LLM inference for routing, scoring, questions, outreach. Only redacted/task text is sent — never passwords or device data.
Generic salary/skill lookups (role/skills) — no personal identifiers.
Postgres + pgvector + Auth. Data encrypted in transit (TLS) and at rest per provider.
Processors act only on our instructions and may not use your content to train other customers’ models.
Data retention
After account deletion, primary data removed within 30 days; backups expire as above.
Security
TLS for all transport, JWT via Supabase Auth, RLS per table (auth.uid() = user_id), least-privilege service-role. Blind Mode redacts PII before LLM scoring. No system is 100% secure — we monitor logs and patch promptly.
Your rights & choices
International transfers
Data is processed where Supabase and LLM providers host services, potentially outside your country. Where required we use Standard Contractual Clauses or equivalent.
Children’s privacy
For recruiters 18+. We do not knowingly collect data from children under 13 (or under 16 where applicable). Contact us for deletion if you believe a child provided data.
Permissions (Android)
Internet for API calls, optional file picker for resume/JD upload, optional notifications if enabled. No background location, contacts, or SMS. Added permissions will be disclosed here and in Play Console Data Safety.
Data Safety — Google Play summary
Changes to this policy
We post updates here and revise the date. Material changes notified via in-app notice or email. Continued use after effective date is acceptance.
Contact
Include your account email and the right you wish to exercise. This policy does not constitute legal advice — have counsel review before final submission.