Privacy Policy
Last updated: July 24, 2026
This policy explains what personal information HireBoard collects, how it's used, how long it's kept, and how you can reach us with questions. It applies to both recruiters using HireBoard to hire, and candidates applying to jobs through it.
Information we collect
If you're a recruiter or company owner — your name, work email, and company name when you create a workspace, plus a securely hashed password if you sign up that way. If you sign in with Google, GitHub, or Discord instead, we receive your name and email from that provider.
If you're applying for a job — the information you submit on the application form: your name, email, phone number, location, LinkedIn/GitHub/portfolio links, resume file, cover letter, and any skills you add. If you create an account to track your applications, we also store your sign-in method (email code or OAuth provider).
Automatically — technical information such as your IP address, used only for security, fraud prevention, and abuse protection (for example, rate-limiting repeated submissions).
How we use your information
To operate the hiring pipeline you're part of: showing your application to the recruiters at the company you applied to, sending status and confirmation emails, and — if you upload a resume — using AI to extract structured details (skills, experience) to help pre-fill your application faster. We never sell personal information to third parties.
How long we keep your data
Job applications — candidate data is retained for two years from the date you submit an application. If you submit another application later, that two-year period restarts from the new submission date.
When that period ends, your record is automatically anonymized: we replace your name and email with a generic placeholder, permanently delete your resume file from storage, clear every other personal field, and revoke any active sign-in sessions. This happens automatically on an ongoing basis — no action is needed from you or the recruiter, and it can't be reversed once it runs.
Recruiter/company accounts — retained for as long as the account remains active. We don't yet have an automated deletion process for company accounts — if you'd like your company's data removed, contact us using the details below and we'll handle it manually.
Cookies and session data
We use a session cookie to keep you signed in. It's set by our authentication system when you log in and cleared when you sign out. We don't use third-party advertising or tracking cookies.
Third-party service providers
We rely on a small number of specialized providers to run HireBoard, each only for the specific task described:
- UploadThing — stores uploaded resumes and company logos.
- Google Gemini — used to extract structured information from resumes you upload (skills, experience). Only invoked on the resume file you choose to submit.
- Resend — delivers transactional emails (application confirmations, sign-in codes, invitations).
- Google, GitHub, and Discord — only if you choose to sign in using one of these providers.
Your rights and requests
You have the right to ask what personal data we hold about you and to request its correction or removal. We don't currently offer a self-service "delete my data" button — instead, email us at the address below and we'll handle your request manually, typically within a reasonable timeframe. Note that candidate application data is deleted automatically after the retention period described above, regardless of whether a manual request is made.
Security
Passwords are never stored in plain text. Access to your data is restricted by database-level access controls, and sensitive identifiers (like invitation tokens) are stored as one-way hashes, never in a recoverable form.
Children's privacy
HireBoard is not directed at, and should not be used by, anyone under 18 years of age. We do not knowingly collect personal information from children.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page. Continued use of HireBoard after a change means you accept the updated policy.
Contact us
Questions about this policy, or requests regarding your personal data, can be sent to privacy@hireboard.dev.