Back to CalHire

Privacy Policy

Last updated: June 2025

1. Who We Are

CalHire ("we", "us") is an AI-powered hiring platform operated by CalHire Inc. This policy explains how we handle data when you use our services.

2. What We Collect

  • Account data: Email address (for OTP authentication only).
  • Company data: Company name, logo, job postings provided by employers.
  • Application data: Resumes, test answers, and interview responses submitted by candidates.
  • Usage data: Timestamps, anonymized event counts, and error correlation IDs. No IP addresses or device fingerprints are stored.

3. How We Use Data

  • Authenticate you via passwordless OTP.
  • Process job applications, score tests, and generate AI-powered scorecards.
  • Send transactional emails (OTPs, test invitations, offer letters).
  • Improve platform reliability via anonymous error logs.

4. AI Processing

We use AI models (Claude, GPT-4o, Gemini) to score resumes, generate job descriptions, and assess interviews. Zero PII is sent to any AI model. All data is anonymized before processing — no names, emails, or identifying information leaves our servers for AI inference.

5. Data Storage & Security

  • Data is stored in Supabase PostgreSQL (encrypted at rest) and Azure Blob Storage (encrypted at rest).
  • Authentication uses RS256 JWT tokens with zero PII in claims.
  • All connections use TLS 1.2+.
  • Rate limiting protects all endpoints. IP bans apply to repeated auth failures.

6. Data Sharing

We do not sell your data. We share data only with:

  • Cloud infrastructure providers (Azure, Supabase) as data processors.
  • AI model providers (Anthropic, OpenAI, Google) — anonymized data only.
  • Payment processors (Paddle, Razorpay) for subscription billing.

7. Your Rights (DPDP Act & GDPR)

  • Access: Request a summary of your account data at any time.
  • Erasure: Deactivate your account — permanent deletion within 30 days.
  • Portability: Contact us for a full data export.
  • Correction: Update your profile through the portal.

8. Cookies

We use only essential cookies for authentication (session tokens). No advertising or analytics cookies are used. No third-party tracking scripts are loaded.

9. Data Retention

  • Active accounts: data retained while account is active.
  • Deleted accounts: PII cleared immediately, hard delete after 30 days.
  • Application data: retained for 12 months after job closure, then anonymized.

10. Children

CalHire is not intended for users under 16. We do not knowingly collect data from minors.

11. Changes

We may update this policy. Material changes will be communicated via the platform.

12. Contact

For privacy inquiries: privacy@calhire.com