Privacy Policy
This privacy policy describes how RecruitSecure AI handles your data.
Last Updated: March 2026
1. Information We Collect
We collect information you provide directly to us, including:
- Account information (name, email address, password) when you register for an account.
- CV and candidate data that you upload to the platform for processing and search.
- Usage data including search queries, feature usage patterns, and interaction logs.
- Payment information processed securely through our payment provider (Stripe). We do not store credit card numbers on our servers.
2. How We Process Your Data
We process your data for the following purposes:
- To provide and maintain the RecruitSecure AI service, including semantic search and candidate ranking.
- To generate vector embeddings from CV text using our AI model running on our servers. CVs are not sent to external AI services.
- To improve our service through aggregated, anonymized usage analytics.
- To communicate with you about your account and service updates.
- To process payments and manage your subscription.
3. Data Storage and Security
Your data is stored in secured, multi-tenant databases with application-level organization scoping ensuring strict tenant isolation. All data is encrypted at rest using AES-256-GCM and in transit using TLS 1.3.
EU customers' data is stored in EU-region data centers. We perform regular security audits and maintain access controls to protect your information.
4. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of Access: You can request a copy of all personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate personal data.
- Right to Erasure: You can request deletion of your personal data. We will delete all associated data, including CVs and embeddings, within 30 days.
- Right to Data Portability: You can request an export of your data in a machine-readable format.
- Right to Object: You can object to the processing of your personal data for certain purposes.
- Right to Restrict Processing: You can request that we limit how we use your data.
To exercise any of these rights, contact us at privacy@recruitsecureai.com.
5. Sub-processors
We use the following third-party sub-processors to deliver our service:
- Supabase: Database hosting and authentication (PostgreSQL). Data stored in EU or US regions depending on customer preference.
- Vercel: Application hosting and CDN. Edge functions process requests in the region closest to the user.
- Stripe: Payment processing. Stripe handles all payment card data under their PCI-DSS certification.
- Resend: Transactional email delivery (welcome emails, password resets, trial reminders). Data processed: email address, name.
- Sentry: Error monitoring and performance tracking. Data processed: anonymized error reports, no PII.
- PostHog: Product analytics (EU servers). Data processed: anonymized usage events, no PII stored.
- Upstash: Rate limiting via Redis. Data processed: IP addresses (ephemeral, TTL-based).
6. Contact Information
For any privacy-related questions or requests, contact our Data Protection Officer at privacy@recruitsecureai.com.