HyrableTerms of Service →

Legal

Privacy Policy

Last updated: 14 August 2026

1. Who we are

Hyrable (“Hyrable”, “we”, “us”, “our”) is a job-search automation service operated as an independent product. For questions about this policy, contact us at privacy@hyrable.co.

2. What data we collect

We collect the following categories of personal data:

  • Account data: Your email address, collected when you sign up via Supabase Auth.
  • Profile data: Name, phone, LinkedIn URL, right-to-work status, notice period, salary expectations, target job titles and industries - provided by you in the Profile section.
  • Equal opportunity data (optional): Gender identity, race/ethnicity, disability status, veteran status, pronouns - entered voluntarily in the Profile section to auto-fill equal opportunity sections on application forms. Never shared with employers by Hyrable.
  • CV data: Your CV text and/or PDF, uploaded by you. This is the most sensitive data we hold.
  • Application data: Job applications you create, including tailored CVs, cover letters, AI-generated answers, and STAR stories you write for behavioural questions.
  • Usage data: Number of AI operations performed (tokens consumed, estimated cost) - used only to enforce daily fair-use quotas.
  • Technical data: Server logs, error traces - retained for up to 30 days and used only to diagnose technical issues.

3. How we use your data

  • To operate the service: match jobs to your profile, tailor CVs, track applications
  • To send transactional emails: daily job digests, quota notifications, follow-up reminders
  • To enforce fair-use quotas and process subscription payments (via Stripe)
  • To improve the service - aggregate, anonymised analytics only; never individual-level data sold or shared

We do not sell your personal data to any third party.

4. AI processing - Anthropic Claude

Hyrable uses Anthropic's Claude API to score jobs, tailor CVs, draft cover letters, and power the mock interview feature. When AI features are used, your CV text and the relevant job description are sent to Anthropic's servers.

Anthropic's data processing is governed by their Privacy Policy. Anthropic does not use API-submitted data to train their models by default (as of the date of this policy - please verify with Anthropic's current terms).

5. Browser extension

The Hyrable browser extension (available on Chrome) fills job application forms with your prepared materials. A dedicated extension privacy policy is available at hyrable.co/legal/extension-privacy. Key points:

  • The extension only activates on supported ATS domains (Greenhouse, Lever, Workable, Ashby, SmartRecruiters, Recruitee, Personio, Teamtailor, Workday) and the Hyrable app itself.
  • When triggered, it sends the page URL and detected form questions to the Hyrable API to retrieve your prepared materials. No other page content is transmitted.
  • Your pairing key is stored in chrome.storage.sync - encrypted by Chrome, never stored in plaintext on Hyrable servers after pairing.
  • The extension never submits forms on your behalf and never executes remotely hosted code.
  • No browsing history or activity on non-ATS sites is accessed.

6. International data transfers

Your primary data is stored in the EU (see section 7). Some processors operate outside the EU/UK:

  • Anthropic (USA): when AI features are used, your CV text and the relevant job description are sent to Anthropic's US servers. Anthropic processes this data under its API terms, which include data protection commitments. Anthropic does not use API data to train its models by default.
  • Stripe (USA): payment data is processed on Stripe's US infrastructure. Stripe is certified under the EU-US Data Privacy Framework.
  • Vercel (USA): server-side logs may pass through Vercel's US infrastructure. No user profile or CV content is stored by Vercel.

All international transfers are made with appropriate safeguards in compliance with UK GDPR and EU GDPR Article 46.

7. Where your data is stored

Your data is stored in Supabase, hosted on AWS in the EU (eu-west-2 / London or eu-central-1 / Frankfurt) region. Supabase is SOC 2 Type II certified. All data is encrypted at rest and in transit.

CV files (PDFs) are stored in Supabase Storage (private S3-backed bucket). Files are accessible only via short-lived signed URLs generated for your session.

8. Legal basis (GDPR / UK GDPR)

  • Contract performance: Processing your CV, profile, and applications is necessary to provide the service you signed up for.
  • Legitimate interests: Service security, fraud prevention, aggregate analytics.
  • Consent: Marketing communications (if applicable in future). You may withdraw consent at any time.

9. Your rights

Under UK GDPR and EU GDPR, you have the right to:

  • Access - request a copy of all personal data we hold about you
  • Rectification - correct inaccurate data (much of this you can do directly in the app)
  • Erasure - request deletion of your account and all associated data
  • Portability - receive your data in a machine-readable format
  • Restriction / Objection - limit or object to certain processing

To exercise any of these rights, email privacy@hyrable.co. We will respond within 30 days.

You also have the right to lodge a complaint with the ICO (UK) or your local supervisory authority.

10. Data retention

  • Account and profile data: retained until you delete your account
  • Job and application data: retained for 12 months after last activity, then deleted
  • Stripe billing data: governed by Stripe's retention policies (typically 7 years for financial records)
  • Server logs: 30 days

11. Cookies

Hyrable uses only essential cookies necessary for authentication (Supabase session cookie). We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

12. Third-party services

ServicePurposeData shared
SupabaseDatabase, auth, file storageAll user data
Anthropic ClaudeAI scoring, CV tailoring, cover letters, Q&A answersCV text, job descriptions, form questions
Chrome Web Store (Google)Extension distributionExtension package only - no user data
StripePayment processing (Pro tier)Email, billing details
VercelHosting and edge functionsServer logs only
Resend / email providerTransactional emailsEmail address

13. California residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights in addition to those described above:

  • Right to know - request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose, and any third parties we share it with.
  • Right to delete - request deletion of your personal information (subject to certain exceptions). You can exercise this directly via Settings → Delete account, or by emailing us.
  • Right to opt out of sale - we do not sell, rent, or share your personal information with third parties for their own marketing purposes. There is nothing to opt out of.
  • Right to non-discrimination - we will not discriminate against you for exercising any of these rights.
  • Right to correct - request correction of inaccurate personal information (most of this you can do directly in the app).

To exercise your California rights, email privacy@hyrable.co with the subject line “CCPA Request”. We will respond within 45 days.

We collect the following categories of personal information: identifiers (name, email), professional information (CV, work history), usage data, and billing information. Full details are in sections 2–3 above.

14. Changes to this policy

We may update this policy when we add new features or processors. Material changes will be communicated by email before they take effect. The date at the top of this page always reflects the most recent version.

15. Contact

Email: privacy@hyrable.co