Privacy Policy
Last updated: September 7, 2026
1. Introduction
Hirable ("we," "our," or "us") operates an AI-powered SaaS platform that generates ATS-friendly resumes tailored to specific job postings. This Privacy Policy explains how we collect, use, share, and protect your information when you use our website, application, Chrome extension, and related services (collectively, the "Service"). By using the Service, you agree to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
When you create a profile and use our Service, you may provide:
- Professional profile data — work history, education, skills, certifications, projects, languages, and awards
- Resume-import data — uploaded resumes, pasted resume text, and the structured profile draft extracted from that content
- Contact information — phone number, LinkedIn URL, GitHub URL, and portfolio URL
- Job information — job titles, company names, and job descriptions you submit for resume tailoring
- Generated content — resumes (PDF/DOCX) and cover letters created through the Service
- Payment information — processed entirely by Stripe; we never see or store your credit card numbers
2.2 Information from OAuth Providers
We use Clerk for authentication via Google and Apple OAuth. When you sign in, we receive your email address and display name from your OAuth provider. We do not store passwords — authentication is managed entirely by Clerk.
2.3 Information Collected Automatically
When you access the Service, we automatically collect:
- IP address and approximate location
- Browser type and version
- Device type and operating system
If you consent, we use PostHog for product analytics. Session replay is disabled by default and may be enabled only on reviewed, non-administrative routes. We collect reviewed product events such as sanitized page categories, button placements, funnel milestones, device and browser information, and pseudonymous account identifiers. If replay is enabled, we mask all text, form inputs, and element attributes and exclude administrative routes. We do not send names, email addresses, user-authored text, filenames, raw URLs, authentication parameters, or payment-provider IDs to PostHog. We also use Google Ads conversion measurement to determine whether an ad led to key product outcomes such as a completed tailored-resume generation, a completed resume export, or a verified paid subscription. Those conversions may include browser and device information, an advertising click identifier, a pseudonymous transaction identifier, and, for paid subscriptions, purchase value and currency.
2.4 Information from the Chrome Extension
Our optional Chrome extension scrapes job postings from job boards on your behalf. When activated, it collects the job title, company name, and job description from the page you are viewing, and sends that data to our backend for resume tailoring. The extension only operates when you explicitly trigger it.
2.5 Sensitive Information We Do Not Request
Hirable does not ask you to provide Social Security numbers, government ID numbers, passport numbers, driver's license numbers, credit card numbers, dates of birth, photographs, race or ethnicity, gender, disability status, religious affiliation, or other sensitive identifiers. Please do not upload resumes or documents that contain this information.
Because resume files and pasted resume text are user-submitted, they may accidentally contain sensitive identifiers. When you import a resume, we scan the extracted text before sending it to an AI provider. Depending on the type of information detected, we may block the import until you remove or acknowledge the risk, redact matching values before AI processing, or warn you before continuing.
Our sensitive-information scan logs only summary metadata, such as the category and count of findings. It does not log the matched Social Security number, credit card number, passport number, driver's license number, or date-of-birth value itself.
3. How We Use Your Information
We use the information we collect to:
- Deliver the Service — generate tailored resumes and cover letters, analyze job descriptions, and match your skills to job requirements
- Process AI-powered generation — send relevant profile and job data to AI providers to produce resume content on your behalf
- Manage your account — authenticate your identity, process payments, and maintain your profile
- Communicate with you — send transactional emails, service updates, and optional marketing communications
- Improve the Service — use bug reports, support requests, and general usage patterns to enhance features, fix issues, and inform product decisions
- Comply with legal obligations — respond to lawful requests and enforce our terms
4. AI Processing
To generate resumes and cover letters, we send portions of your profile data and job description information to third-party AI providers. OpenAI is our primary provider; Google Gemini may process requests as a fallback provider when needed. Providers may change over time. The data sent may include your work history, skills, education, and the target job description — limited to what is necessary for content generation.
Resume import requires your consent before AI processing. If our import scanner detects sensitive identifiers in the extracted resume text, we may block the import until you remove or acknowledge those findings. We redact matching sensitive identifier values from the text sent to AI providers when our scanner classifies them as blocking or redactable.
We do not use your resume data to train Hirable models. Your data is sent to AI providers solely to provide the content or analysis you requested. Provider handling, including limited retention for safety, abuse monitoring, or legal compliance, is governed by our commercial agreements and each provider's policies.
AI providers operate under their own privacy policies and terms of service. We select providers that offer commercial API terms with appropriate data handling commitments, but we encourage you to review their policies as well.
Connected AI assistants
If you connect Hirable to ChatGPT or another supported AI assistant, Hirable uses authenticated Model Context Protocol (MCP) tools to return information needed for workflows you request or authorize. Depending on the workflow, that information may include profile and contact fields, career history, saved job postings, resume-template metadata, review diffs, generation status, and generated-file references. OpenAI receives these tool responses when you use Hirable from ChatGPT.
Hirable keeps confirmation secrets and short-lived download credentials out of model-visible tool responses where the assistant platform supports private app metadata. You can revoke an assistant connection from Hirable settings. Data that Hirable returns to a connected assistant at your request is then handled under your account and the assistant provider's terms and privacy policy; it is separate from Hirable's server-to-server AI generation API processing described above.
5. Information We Share
We never sell your personal information. We share data only with the following categories of service providers, and only to the extent necessary to operate the Service:
- Clerk — authentication and session management (receives your OAuth credentials and email)
- Stripe — payment processing (receives billing information directly; we never handle your card details)
- Google Cloud Platform — infrastructure hosting and file storage (all user data is stored on GCP servers)
- AI providers (OpenAI and Google Gemini) — server-to-server content generation (receives profile excerpts and job descriptions as described in Section 4)
- Connected AI assistants (including ChatGPT/OpenAI) — authenticated assistant workflows you request or authorize (receives the relevant Hirable profile, job, template, review, generation-status, and generated-file fields described in Section 4)
- Legal authorities — when required by law, court order, or governmental regulation, or to protect the rights and safety of our users
6. Chrome Extension Data
The Hirable Chrome extension is an optional tool that lets you capture job postings directly from job board websites. Here is how it handles your data:
- What it collects — job title, company name, and job description text from the active page, only when you trigger the extension
- How data is transmitted — scraped data is sent over HTTPS to our backend API for processing
- Authentication — the extension uses a user-scoped API key (not your password) that you can revoke at any time from your dashboard
- Your control — you can disable or uninstall the extension at any time; it does not run in the background or collect data without your explicit action
7. Cookies & Tracking
We use essential storage to operate the Service and, only with your consent, optional PostHog analytics, masked session replay, and Google Ads measurement:
- Essential session cookies — set by Clerk for authentication; these are httpOnly and secure cookies required for sign-in functionality
- Optional product measurement — after you select "Accept," PostHog records the reviewed events and masked replay described above. Selecting "Reject" prevents initialization and delivery. You can change or withdraw your choice at any time through "Privacy settings" in the site footer or dashboard. Product analytics and replay are retained only while needed to understand and improve the Service, subject to our PostHog project retention settings. When you delete your account, we request deletion of the associated PostHog person data; de-identified aggregate statistics may remain.
- Optional advertising measurement — after you select "Accept" in our cookie banner, the Google tag may use cookies or similar identifiers to attribute key product outcomes, including completed tailored-resume generation, completed export, and verified paid subscriptions, to a Hirable advertisement. Selecting "Reject" prevents us from loading the tag or sending these conversion events.
We advertise Hirable through Google Ads, but we do not display third-party ads within the Service. You can learn more about how Google handles data in its Privacy Policy.
8. Data Security
We take the security of your data seriously and implement the following measures:
- All data in transit is encrypted using HTTPS/TLS
- Data at rest is encrypted on Google Cloud Platform infrastructure
- API keys are cryptographically hashed before storage — we cannot view your raw keys
- Authentication credentials are managed by Clerk and never stored in our database
While we strive to protect your personal information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security but are committed to following industry best practices.
9. Data Retention
- Active accounts — your data is retained for as long as your account remains active and is necessary to provide the Service
- Deleted accounts — account deletion starts immediate removal of your Hirable profile, generated files, uploaded files, and account data; invoices, receipts, charge records, refunds, and minimal audit records may be retained where required for tax, accounting, fraud prevention, dispute handling, or legal compliance, with personal references redacted where possible
- AI generation API data — data Hirable sends to AI providers for server-to-server content generation is processed under our commercial API terms and applicable provider retention commitments
- Connected-assistant data — data returned through an authenticated ChatGPT or other assistant connection is handled by that provider according to your account, its product terms, and its privacy policy after Hirable returns the requested tool response
- Hirable MCP workflow records — transient resume-generation request payloads are purged after 24 hours; committed saved-job review payloads are retained for up to 7 days for idempotent retries; and completed operation audit records are retained for up to 90 days. Expired or cancelled review drafts and short-lived download credentials are removed on their expiration/cleanup cycle.
10. Your Rights
You have the following rights regarding your personal data:
- Access — request a summary of the personal data we hold about you by emailing us; we will respond within 30 days
- Correction — update or correct inaccurate information in your profile at any time through your account settings
- Deletion — delete your account and all associated data from your account settings
- Marketing opt-out — unsubscribe from marketing emails at any time using the link in each email
Structured data export for portability is not yet available but is on our roadmap. To exercise any of these rights, contact us at privacy@hirable.me.
11. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a person under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@hirable.me.
12. International Users
Hirable is based in and operates from the United States. All data is processed and stored on servers located in the United States via Google Cloud Platform. If you access the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer and processing of your data in the United States.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at least 30 days before the changes take effect and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
14. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at privacy@hirable.me.