Privacy Policy
Last updated September 1, 2026
1. What we collect
Recruiter collects three categories of information:
- Account information: your name, work email, and authentication details, handled by our identity provider, Clerk
- Job posting content: titles, descriptions, requirements, interview plans, and scorecard templates you create
- Candidate data: names, emails, phone numbers, resumes, application answers, interview scheduling details, and panel scorecards submitted for your open postings
If your organization connects Google Calendar for interview scheduling, we store an encrypted OAuth token (AES-256-GCM) to create Meet links — we never see or store your Google password.
2. How we use it
We use this information only to operate Recruiter: to run your job postings, route candidates through your hiring pipeline, schedule interviews, generate scorecards, and maintain the audit log of hiring decisions. We do not sell candidate or organization data, and we do not use it to train third-party models.
3. Storage and security
Data is stored in Supabase (PostgreSQL and file storage) with encryption at rest and in transit. Sensitive credentials such as Google OAuth tokens are additionally encrypted at the application level before being written to the database. Access to production data is limited to the people who need it to operate the Service.
4. Sub-processors
We rely on the following sub-processors to run Recruiter:
| Provider | Purpose |
|---|---|
| Clerk | Account authentication and session management |
| Supabase | Database and resume/file storage |
| Vercel | Frontend hosting |
| Render | Backend API hosting |
| Paddle | Payment processing for the per-posting fee |
| Amazon SES | Transactional email delivery (primary) |
| Brevo | Transactional email delivery (fallback) |
| Calendar/Meet integration, only if an organization connects it | |
| PostHog | Product analytics, only if you consent to it |
Google user data.Recruiter's use and transfer of information received from Google APIs (via the Google Calendar/Meet integration) adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access only the Google Calendar data needed to check availability and create a Meet link for a scheduled interview. We do not share, transfer, sell, or otherwise disclose Google user data to any third party, except as necessary to provide this feature to you, to comply with applicable law, or with your explicit consent.
5. Data retention
We retain job posting and candidate data for as long as your organization's account is active, so you can refer back to past hires and audit trails. If you close your account, we delete organization and candidate data within 90 days, except where we are required to retain records for legal or accounting purposes.
Candidates may ask the hiring organization that posted a role to remove their information; organizations can delete a candidate's record directly, or contact support@opsveritas.com for assistance.
6. Your rights
Depending on where you're located, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to certain processing. To exercise any of these rights, email support@opsveritas.com — we will respond within 30 days.
7. Cookies
Recruiter uses a session cookie set by Clerk to keep you signed in — this is essential and always on.
With your consent, we also use PostHog for product analytics, including session recording (all form input values are masked, never captured). Analytics are off by default — you're asked to choose the first time you visit, and you can change that choice at any time via the "Cookie preferences" link in the footer. We do not use third-party advertising cookies.
8. International transfers
Our infrastructure providers may process data in multiple regions. Where personal data is transferred internationally, we rely on our providers' standard contractual safeguards to protect it.
9. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where practical, notify account owners directly.
10. Contact
Questions about this policy can be sent to support@opsveritas.com.