Privacy Policy
Last updated: 6 July 2026
OctoRecruit ("we", "us", "our") is an AI-powered applicant tracking system built for recruitment agencies and HR teams. This Privacy Policy explains what personal data we collect, how we use it, and the choices and rights available to you. If you are based in the European Economic Area (EEA) or the United Kingdom, please also read our GDPR Supplement.
1. Data We Collect
Account and profile data
When you create an account we collect your name, work email address, company name, and a hashed password. If you sign in via Google or Microsoft OAuth we receive the profile information those providers share with us (name and email).
Connected-mailbox OAuth tokens
If you connect a Gmail or Outlook mailbox, we store the OAuth access and refresh tokens returned by Google or Microsoft. These tokens are encrypted at rest using AES-256-GCM before being written to our database. We use them to read inbound emails so that candidate CVs and replies can be pulled into OctoRecruit automatically, and to send messages from your mailbox — but only messages that you compose, schedule, or configure through pipeline automations you enable.
Candidate data
You (the recruiter) upload or receive candidate CVs and profile information. This may include names, email addresses, phone numbers, work history, education, and any other information contained in CVs or typed by your team. You are the controller of this data; we process it on your behalf.
Usage and log data
We collect server-side logs including IP addresses, browser/device information, request timestamps, and error traces. This data is used for security monitoring, debugging, and aggregate analytics (no personal profiling).
Billing data
Payment card details are handled directly by Stripe and are never stored on our servers. We receive a Stripe customer ID, subscription status, and invoice history.
2. How We Use Your Data
- To provide and operate the OctoRecruit service.
- To process CVs and score candidates using AI (Anthropic Claude and OpenAI models). Documents are sent to these third-party APIs over HTTPS and, under the providers' API data-usage terms, are not used to train their models.
- To send transactional emails (email confirmations, password resets, stage notifications).
- To process payments and manage subscriptions via Stripe.
- To monitor for abuse, security incidents, and service reliability.
- To comply with applicable legal obligations.
We do not sell or rent your data to any third party.
3. Sub-processors and Third Parties
We use the following sub-processors to deliver the service. Each is engaged under a data processing agreement:
- Supabase — PostgreSQL database and object storage (CVs). Data stored in the EU (AWS eu-central-1).
- Anthropic — AI model API for CV parsing, candidate scoring, and deep analysis.
- OpenAI — Embedding generation for semantic candidate search.
- Stripe — Payment processing and subscription management.
- Resend — Transactional email delivery.
- Google (Gmail & Google Calendar APIs) / Microsoft (Outlook & Microsoft Graph APIs) — Email and calendar access when you connect a mailbox or calendar.
- Vercel — Cloud hosting, edge network, and serverless compute.
4. Cookies and Analytics
We use cookies that are strictly necessary to operate the service, such as your authentication session. On our public website and sign-in pages we also use Microsoft Clarity and Google Analytics to understand how visitors use the site. These analytics tools are never loaded inside the logged-in application, so they do not see your candidates or any recruitment data.
5. Data Retention
We retain your account data for as long as your account is active. Candidate data is retained as long as you maintain it in the system. Deleted records are soft-deleted and permanently purged within 30 days. Server logs are rotated after 90 days. You may request deletion at any time (see Section 7).
6. Security
We implement industry-standard security controls: TLS in transit, AES-256-GCM encryption for sensitive credentials, row-level security policies in our database, and regular dependency audits. For a fuller description of our security posture see our Security page.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. EEA/UK data subjects have additional rights described in our GDPR Supplement. To exercise any right, contact us at ···.
8. Children
OctoRecruit is a business tool not directed at children. We do not knowingly collect personal data from anyone under 16.
9. Changes to This Policy
We may update this policy from time to time. We will notify registered users of material changes by email. Continued use of the service after the effective date constitutes acceptance of the revised policy.
10. Contact
OctoRecruit
Data controller for account and platform data
Email: ···
