HireForge

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how HireForge collects, uses, discloses, retains, and protects personal information. HireForge acts as a controller for account, website, security, and billing data used for our own purposes. For candidate or coaching-client data a business customer submits, HireForge generally acts as that customer’s processor or service provider under the Data Processing Addendum (“DPA”).

Scope and our roles

This Policy applies to the HireForge website, applications, hiring workspaces, and support interactions. It does not govern an employer’s, recruiter’s, or coach’s independent practices. If an organization submitted your information, that organization decides why it is processed and is the primary contact for your request; we assist it as required by the DPA.

Information we collect

Depending on how you use the Service, we collect:

  • Account and profile data, including email, name, avatar, account type, authentication records, and preferences.
  • Candidate, resume, and coaching-client data, including uploaded resume text, work history, education, skills, certifications, client profile information, and file metadata.
  • Role and assessment data, including job descriptions, customer-defined criteria, evidence excerpts, reviewer notes, interview transcripts or notes submitted for analysis, scorecard output, and debrief records. Raw interview text is used for the requested analysis and is not saved in the shortlist record.
  • Job-seeker output, including comparisons, gap plans, estimated probabilities, drafts, and saved analysis sessions.
  • Billing and commercial data, including plan, usage, transaction identifiers, consent records, subscription status, and limited Helcim customer information. HireForge does not store full card numbers.
  • Security and device data, including a hashed device fingerprint, hashed IP address, truncated user agent, login records, cookies, and standard server logs.
  • Support and communications data you send to us.

Sources

We receive information directly from users and business customers, from files and URLs they submit, from authentication and payment providers, and automatically from use of the Service. We may retrieve public job-posting text when a user provides a URL. We do not purchase candidate profiles or background reports.

How and why we use information

We process information to:

  • Provide requested resume, coaching, evidence-review, and interview-analysis features and save user-selected results.
  • Create and secure accounts, prevent abuse, enforce one-free-account device limits, and investigate incidents.
  • Process purchases, administer subscriptions, maintain consent records, and provide support.
  • Maintain, debug, and improve reliability and usability. We do not use business Customer Data to train a general-purpose AI model.
  • Comply with law, protect rights and safety, and establish or defend legal claims.

AI processing

The Service sends relevant resume, role, candidate, interview, or coaching content to xAI to produce requested analysis. Production AI processing is configured to fail closed unless the operator confirms that the xAI account is enabled for Zero Data Retention. Local development may use a self-hosted Ollama model. HireForge does not allow an AI provider to use business Customer Data to train general-purpose models.

AI output supports human review and does not itself make a final hiring or rejection decision. Employers and other customers are responsible for required notices, human review, accommodations, bias audits, and lawful decision-making. See the Employment AI Policy.

Service providers and disclosures

We disclose information only as needed to operate the Service, follow customer instructions, complete a transaction, comply with law, or protect rights and safety. Categories of providers include Supabase (authentication and database), xAI (AI inference), Helcim (payments), transactional email providers, infrastructure and monitoring providers, and job-content retrieval services.

We may disclose information in a corporate transaction, subject to appropriate confidentiality and notice. We do not sell personal information, share it for cross-context behavioral advertising, or use third-party advertising cookies.

Cookies and device verification

Required cookies maintain sessions, remember an optional login preference, protect OAuth flows, and complete Helcim checkout. Device verification uses hashed or truncated identifiers to prevent free-tier abuse. We do not store raw IP addresses for device verification or maintain a cross-site browsing profile.

Retention and deletion

Account and saved content are retained while the account is active and until deleted by the user or customer, subject to backups and legal obligations. Saved resumes, analysis sessions, client profiles, and employer shortlists can be deleted from the applicable workspace. A deleted active-role shortlist no longer counts toward the employer plan limit.

Security logs and hashed device records are kept only as long as reasonably needed for fraud prevention and account integrity. Billing, consent, tax, dispute, and transaction records may be kept for the legally required period. Business customers must select and follow a lawful retention period for employment records; an Enterprise order form may specify additional automated retention controls.

To request account deletion, contact support@ithubs.org. We delete or de-identify information within a reasonable period unless retention is required by law, needed to complete a transaction, or necessary to establish or defend legal claims. Residual backup copies are isolated and expire under backup schedules.

Your privacy rights

Depending on location, you may request access, correction, deletion, portability, restriction, or objection; withdraw consent; appeal a denied request; or opt out of sale, sharing, targeted advertising, or certain automated decisions. HireForge does not sell or share personal information for targeted advertising, so no opt-out is necessary for those practices.

Submit a request to support@ithubs.org or /contact. We may verify identity and authority before responding. An authorized agent may submit a request where law permits. We will not discriminate against you for exercising a privacy right. If a business customer supplied your information, contact that customer first; we will assist it with a verified request.

California notice

In the preceding 12 months, HireForge may have collected the categories described above: identifiers; customer records; commercial information; internet or network activity; professional or employment information; education information; inferences generated for requested features; and potentially sensitive personal information only when a user includes it in submitted content. We use and disclose these categories for the business purposes described in this Policy and do not sell or share them for cross-context behavioral advertising.

HireForge uses sensitive personal information only to provide and secure the Service or as instructed by a business customer, not to infer characteristics for advertising.

International transfers

Information may be processed in the United States and other countries where providers operate. Where required, we use recognized safeguards such as Standard Contractual Clauses, the UK Addendum, adequacy decisions, or another lawful transfer mechanism. The DPA provides business-customer transfer terms.

Security

We use reasonable administrative, technical, and organizational measures, including encrypted transport, access controls, least-privilege service access, row-level database policies, secrets management, logging, and incident procedures. No system is completely secure. Customers must configure access appropriately and avoid submitting unnecessary sensitive data.

Children

The Service is not directed to children under 16, and we do not knowingly create accounts for them. Employment customers must not submit information about minors unless they have a lawful basis and any required permission.

Changes and contact

We may update this Policy and will revise the date above. We will provide additional notice for material changes and obtain consent where law requires it.

For privacy questions, requests, or complaints, email support@ithubs.org or use /contact. You may also complain to your local privacy or data-protection authority.

See also: Terms of Service