Skip to content

Privacy Policy

Last updated: 16 July 2026

The short version: your data is yours, we protect it properly, and we never sell it or use it to train AI models. The detail follows.

1. Who we are

Hireable Ltd ("Hireable", "we", "us") is a company registered in England & Wales (company number 14871479) with its registered office at 20 Temple Fields, Hertford, England, SG14 3LR.

We run the Hireable platform: an AI-powered career platform at app.gethireable.com, the marketing site at gethireable.com, and the Hireable Chrome extension. For most of what this policy describes, we are the data controller.

If your employer (or former employer) has arranged Hireable for you as part of an outplacement programme, there is one difference worth knowing: your sponsoring organisation is the controller of the basic details it gives us to set up your access (your name and email), and we process those on its instructions under a data processing agreement. Everything you then do inside Hireable — your CV, your job search, your practice interviews — is yours, and section 12 explains exactly what your sponsor can and cannot see.

Privacy questions or requests: privacy@gethireable.com

2. What we collect

We collect what you give us, what our AI produces while helping you, and a small amount of technical data. Specifically:

  • Account details — name, email address, password (stored only as a secure hash by our authentication provider), and sign-in method (email or Google).
  • Profile — job title, location, phone number, LinkedIn URL, salary preferences, and anything else you add to your profile.
  • CV content — your work history, education, skills, achievements, and any CV files you upload (PDF/DOCX), plus the CVs and cover letters you build or tailor in Hireable.
  • Job-search activity — jobs you save or hide, applications and their status, match scores we calculate for you, and your application answers.
  • Contacts you add — if you use the contact tracker, the names, emails, phone numbers, employers, and LinkedIn URLs of recruiters or contacts you choose to record. You are responsible for only adding people in the context of your own job search.
  • Interview practice sessions — when you practise with the AI interview coach, the session runs as a live video call. Sessions are recorded so we can produce your transcript and feedback report. During the call, our video partner's perception technology also generates real-time coaching observations from the video and audio — things like eye contact, pace of speech, hesitation, and apparent nervousness or engagement — which are used to coach you in the moment and are stored with your interview record to build your feedback. This is a form of automated behavioural analysis, used only to coach you: it is never shared with employers or your sponsoring organisation, and it never decides anything about you (see "Automated decisions and AI" in section 3).
  • AI assistant conversations — your chats with your Career Concierge are stored so the assistant can keep context, along with a memory of useful facts it has learned about your search (for example, your target roles). You can ask us to clear this at any time.
  • Connected email accounts (optional) — if you connect Gmail or Outlook, we ask for permission to send emails you have drafted and approved. For Gmail, we also check whether an outreach thread has received a reply, looking only at thread metadata (sender, subject, date) — we do not read or store the content of your inbox or of replies. We store your connection tokens encrypted. Our use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements; we use Gmail data only to provide the outreach features you ask for, never for advertising, and we never sell it.
  • Chrome extension data — the extension reads job listings on the job pages you visit on LinkedIn, Indeed, and Glassdoor to show match scores and save jobs. It stores your sign-in token and preferences on your device. It does not collect your browsing history. Full detail: gethireable.com/extension-privacy.
  • Feedback and support — anything you send us through the in-app feedback tool (including optional screenshots) or by email.
  • Payment data — handled by Stripe, our payment processor. We never see or store your full card number.
  • Usage and device data — product analytics events (which features you use), approximate device/browser information, and error reports. Section 9 explains our analytics setup, which is deliberately cookieless.
  • Business enquiries — if you request a brochure, book a demo, or access a gated demo on our marketing site, we collect your name, work email, and company to respond.

We do not ask for, and do not want, special category data (such as health information, ethnicity, or religion) — you never need to include it for Hireable to work. If you choose to include something like this in your CV — for example, a disability disclosure for a Disability Confident employer — it is protected like everything else here and is never used for scoring or analysis.

3. How we use your data

  • To run the platform — building and storing your CVs, matching and scoring jobs against your profile, tracking applications, running interview practice and feedback, drafting outreach, and operating your account (legal basis: performing our contract with you).
  • To act on your instructions — when you use auto-apply, we submit applications on your behalf to the employer's application system, using your profile and chosen CV. Every application is proposed to you first and sent only when you confirm, unless you choose to switch auto-apply into automatic mode — it is off by default (legal basis: contract).
  • To improve and secure the service — cookieless analytics, error monitoring, abuse prevention, and rate limiting (legal basis: legitimate interests, balanced so that the minimum personal data is used — see section 9).
  • To communicate with you — essential account and billing emails, and (separately) product updates and tips, which you can opt out of via the unsubscribe link in any such email (legal bases: contract for essential email; legitimate interests for updates, with an opt-out in every message).
  • To bill you — subscription management via Stripe, and keeping the records UK tax law requires (legal basis: contract and legal obligation).
  • To respond to business enquiries — following up brochure and demo requests (legal basis: legitimate interests; every follow-up offers an opt-out).

Your right to object: where we rely on legitimate interests, you can object at any time — and for anything that amounts to direct marketing, your objection is absolute: tell us (or click unsubscribe) and it stops.

Automated decisions and AI

Hireable is built around AI, and we are open about what it does:

  • Our AI scores and ranks jobs for you, drafts and improves CVs, coaches your interviews, and drafts outreach. AI output can be wrong; review it before you rely on it.
  • No employer receives Hireable's scores, rankings, or assessments of you. Our AI works for you, the candidate — no hiring decision is made or informed by our systems.
  • Interview perception analysis (section 2) is used solely to coach you. It is never shared with employers or your sponsoring organisation and is not used to make any decision about you with legal or similarly significant effect.
  • We do not make solely automated decisions about you that produce legal or similarly significant effects. Auto-apply acts only on your instruction and within limits you set.

4. We don't sell your data, and we don't train AI models on it

We never sell personal data. We never share it with third parties except the service providers acting on our instructions listed at gethireable.com/subprocessors, recipients you direct us to send it to (like an employer you apply to), or where the law requires.

We do not train machine-learning models on your personal data. This promise is enforced in our software, not just in this policy: our software is built to refuse to run at all if it is ever set up to collect your content for training. We do use non-personal and aggregated operational data — for example, how well our systems parse public job adverts — to improve Hireable. If we ever propose to change our approach to training, we will update this policy and give you a clear choice first.

5. Who we share data with

  • Service providers (processors) — the infrastructure and tools we use to run Hireable: Google Cloud (hosting, in London), Google AI (Gemini, which powers your Career Concierge), Anthropic (a narrow role: navigating unfamiliar application forms during auto-apply, running in the EU), Tavus (live interview video), Amazon Web Services (interview recording storage, Stockholm), Stripe (payments), PostHog (analytics, EU), Sentry (error monitoring), Resend (system email), and a small number of others. The complete, current list — with what each one does, where it runs, and the transfer safeguards — is published at gethireable.com/subprocessors. Each provider is bound by contract to process your data only on our instructions.
  • Recipients you choose — when you apply to a job (yourself or via auto-apply), your application goes to that employer or its applicant tracking system; when you send outreach from a connected email account, your message goes to your chosen recipient. These recipients handle your data under their own privacy policies.
  • Your sponsoring organisation — programme reporting only, as described in section 12: your seat's activation and engagement status, coach-hours usage, and whether you've landed a role. Never your CVs, application details, searches, conversations, or interview content.
  • Business tools for enquiries and feedback — B2B enquiries are managed in our CRM (Attio) and scheduling runs through Calendly; in-app feedback is triaged in ClickUp (so what you write in feedback reaches that tool). These are listed on the subprocessor page.
  • Authorities — if legally required, and only to the extent required.

6. Where your data lives

Hireable runs on Google Cloud in London (europe-west2) — your account, CVs, applications, and conversations are stored there. Interview practice recordings are stored in a Hireable-controlled AWS bucket in Stockholm (eu-north-1); recordings made before July 2026 remain in our video partner's storage (region being confirmed with them) — they are deleted on your request, and are covered by the same retention rules in section 7. AI requests are processed in the EU where the provider supports region pinning (Claude, embeddings); requests to Google's Gemini API are processed on Google-managed infrastructure that is not pinned to a single region.

Where a provider processes data outside the UK, we rely on the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, alongside each provider's own safeguards. The subprocessor page shows the mechanism per provider, and you can request a copy of the relevant safeguards by emailing privacy@gethireable.com.

7. How long we keep it

DataHow long
Your account and everything in it (CVs, applications, chats, AI memory, interview records)For as long as your account exists. Deleted on verified request (below). Contacts you added are deleted with your account.
Sponsor programme records (the roster and reporting data held for your sponsoring organisation)12 months after the programme ends, then purged (your own deletion request takes precedence). Your own account and content follow the row above — if you keep using Hireable after your programme, they stay yours.
Connected email tokensDeleted when you disconnect the account in Settings.
Business enquiries (brochure/demo requests, in our CRM)For as long as the conversation is live, reviewed annually. Opt out of follow-up at any time.
Feedback you submit (mirrored to our triage tools)Kept while relevant to fixing the issue; deleted with your account on request.
Product analytics eventsHeld in PostHog under our EU account; deletion requests are passed through.
Billing and invoice records6 years (UK tax law).
Error reports (Sentry)90 days (provider-side).
Server logs30 days.
BackupsDeleted data ages out of encrypted backups within 30 days.

Honesty note: deletion and retention are currently carried out by our team through an audited manual procedure, not a self-serve button. When you ask us to delete your account, we run a documented purge across our systems (including recordings and analytics/CRM tools) and confirm when it's done. We're building self-serve deletion; until then, one email is all it takes.

8. Your rights

You have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing (including the absolute right to object to direct marketing), and to withdraw consent where processing is based on consent (for example, disconnecting your email account at any time in Settings).

To exercise any right, email privacy@gethireable.com from the address on your account (or ask via the in-app assistant). We respond within one month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) — though we'd appreciate the chance to sort it out first.

On paid plans you can export any CV you've built (PDF/DOCX) from the app; on the Free plan, and for a full copy of everything we hold about you, email privacy@gethireable.com — that request is always free.

9. Analytics, error monitoring, and session replay

We designed our analytics to be minimally invasive:

  • PostHog (EU-hosted) runs cookieless — it stores nothing on your device and uses no advertising identifiers. Events are tied to your account ID once you're signed in so we can understand feature usage. In the app, session replay is enabled with all text and inputs masked — we can see how the interface behaved, not what you typed or read. Your chat content is never sent to analytics.
  • Sentry collects error reports (including IP address and request context) so we can fix crashes, with an automatic scrubber that strips the fields carrying emails, phone numbers, and CV content from reports before we see them. Sentry also records a masked replay of the interface for a small sample of sessions (currently 1 in 10) and whenever an error occurs, to help us reproduce bugs. Reports age out after 90 days.
  • The marketing site uses the same cookieless PostHog setup with session recording disabled.

Because none of this uses cookies or similar identifiers requiring consent, you won't see a cookie banner. The two cookies we do use exist only to sign you in and to remember that you're signed in — see the Cookie Policy (gethireable.com/cookies).

10. Security

All connections use TLS; all data stores are encrypted at rest (AES-256). Email connection tokens are additionally encrypted at the application layer with independently rotatable keys. Access is role-based and least-privilege; every privileged admin action is written to an append-only audit log that nothing in our software can edit or delete. We hold no SOC 2 or ISO 27001 certification yet — we'd rather say so plainly than imply otherwise. More detail: gethireable.com/trust.

If a breach ever puts your data at high risk, we will notify you and the ICO as UK GDPR requires.

11. Age

Hireable is for people aged 16 and over. We do not knowingly collect data from anyone younger; if you believe we have, contact privacy@gethireable.com and we will delete it.

12. Outplacement programme members

If your access is sponsored by an organisation (for example, a former employer's outplacement programme):

  • Your sponsor gives us your name and email to invite you, and pays for your access. It acts as controller for that roster information; we process it under a data processing agreement.
  • Once you activate your account, your workspace is yours. Your sponsor sees programme reporting about your seat: whether you've activated and are engaging, your coach-hours usage, and whether you've landed a role. It never sees your CVs, application details, searches, conversations, or interview practice.
  • Your content belongs to you — and when your programme ends, your account simply continues on the Free plan, so nothing you built goes away. Your deletion rights work exactly as in section 8.

13. If you're not a Hireable user

We may hold limited details about you even if you've never used Hireable:

  • Contacts — a Hireable user may have added you (name, email, role, employer) to their private contact tracker to manage their own job search, or corresponded with you using their own connected email account. We host this for that user alone; it is never shared with anyone else, never used for marketing, and is deleted with the account that created it.
  • Business enquiries — if a colleague named you when booking a demo or requesting a brochure.

If you'd like to know what we hold or want it removed, email privacy@gethireable.com.

14. Changes to this policy

When we make material changes, we'll tell you — by email or in-product notice — before they take effect, and we'll update the date at the top. Minor clarifications may be made without notice.

15. Contact