Back to Policies

Privacy Policy

Last updated: March 19, 2026

1. Information We Collect

We collect information that you provide directly to us, including when you create an account, use our services, or communicate with us. The categories of information we collect include:

1.1 Account Information

When you register for HireUp, we collect your name, email address, organization name, and role. Authentication is managed by our third-party identity provider, Clerk, which processes your login credentials, session tokens, and organization membership data on our behalf.

1.2 Contact and Communication Data

When you connect communication channels to HireUp, we collect and store data from those channels, including:

  • Email (Gmail and Outlook): Email messages, sender and recipient information, subject lines, timestamps, and metadata.
  • WhatsApp: Message content, sender information, timestamps, and phone numbers via the WhatsApp Business API.
  • Phone calls (Aircall and Ringover): Call metadata, call recordings, and transcripts.
  • Video meetings (Google Meet): Meeting metadata and transcripts.
  • Slack: Messages and workspace data from connected Slack integrations.
  • LinkedIn: Message content, sender information, timestamps, and profile URLs collected via the HireUp Browser Extension (see Section 1.5).

1.3 Contact Profile Data

We store contact profiles that you create or import, including names, email addresses, phone numbers, LinkedIn URLs, and custom metadata. We also store data derived from communications, including skills, job titles, company names, salary information, location preferences, and employment history extracted from messages, emails, call transcripts, and uploaded documents.

1.4 Documents

When you upload resumes or other documents, we store the original files and extract text content from them for indexing and enrichment purposes.

1.5 HireUp Browser Extension

When you use the HireUp Browser Extension, we additionally collect:

  • LinkedIn message data: The extension reads message content, sender information, and timestamps from the LinkedIn messaging interface while you are actively using LinkedIn. This data is sent to the HireUp platform to sync communications with your contacts.
  • LinkedIn profile information: The extension resolves LinkedIn profile URLs to match messages with contacts in your HireUp account. This may involve accessing LinkedIn's page context using your active LinkedIn session.
  • Authentication tokens: The extension stores your HireUp authentication token locally in your browser's extension storage to maintain your session. This token is never shared with third parties.

1.6 ATS Integration Data

If you connect an Applicant Tracking System (ATS) such as Loxo, Greenhouse, Lever, Workday, BambooHR, SmartRecruiters, or JobVite, we import candidate and client data including names, email addresses, phone numbers, and other profile information from your ATS account. ATS credentials are stored securely and are never exposed to other users or third parties.

1.7 Usage and Analytics Data

We use PostHog, a third-party analytics service, to collect usage data including feature interactions, page views, and feature flag evaluations. We identify users by their internal user ID for the purpose of feature flag targeting and product analytics. We do not send personally identifiable information such as names or email addresses to PostHog.

1.8 Search History

We store search queries, search sessions, and interaction history to provide and improve our search functionality.

1.9 Payment Information

Subscription billing is processed by Stripe. We do not store your payment card details. Stripe processes and stores your payment information in accordance with PCI-DSS standards. We retain only subscription plan details and usage metrics.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing core services: Aggregating communications from connected channels, maintaining contact profiles, enabling search across your data, and managing campaigns.
  • AI-powered features: We use artificial intelligence (powered by Amazon Web Services Bedrock) to generate contact profile summaries, extract skills and professional attributes from communications, classify profile types, generate campaign message drafts, and power search result summaries. AI processing occurs on-demand and generated outputs are stored alongside your data.
  • Profile enrichment: We analyze your communications and uploaded documents to automatically extract and score professional attributes such as skills, job titles, salary expectations, and location preferences. Each extracted data point is tracked with its source, confidence score, and timestamp.
  • Automated campaigns: When you create campaigns, we use your data to schedule and send messages via connected channels (email, WhatsApp) to your specified audience.
  • Email delivery: We use Amazon Simple Email Service (SES) to send emails on your behalf and track delivery status, bounces, and complaints.
  • Analytics and improvement: We use aggregated usage data to understand how features are used and to improve the platform.

3. Information Sharing and Disclosure

We do not sell, trade, or otherwise transfer your personally identifiable information to third parties without your consent. We share data with the following categories of service providers solely to operate the platform:

  • Cloud infrastructure: Amazon Web Services (AWS) hosts our data and provides compute, storage, and AI services.
  • Authentication: Clerk processes login credentials and manages user sessions.
  • Analytics: PostHog receives anonymized usage events for product analytics and feature flag management.
  • Payment processing: Stripe processes subscription payments.
  • Database: MongoDB Atlas stores a subset of communication data for full-text and semantic search.

We may also disclose your information when required by law or to protect our legal rights.

4. Data Storage and Security

Your data is stored on Amazon Web Services infrastructure in the European Union (EU-West-1 region). Communication data is stored in both Amazon DynamoDB and MongoDB Atlas for different query requirements. Documents and files are stored in Amazon S3 with encryption at rest.

We implement appropriate technical and organizational measures to protect the security of your personal information, including:

  • Encryption in transit (TLS/HTTPS) for all API communications
  • Encryption at rest for stored data
  • OAuth credentials and API keys stored in AWS Secrets Manager
  • Role-based access control with organization-level data isolation
  • JWT-based authentication for all API requests

The HireUp Browser Extension stores data locally on your device using Chrome's extension storage, which is isolated from web pages and accessible only to the extension. All communication between the extension and the HireUp platform occurs over encrypted HTTPS connections with authenticated requests.

No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.

5. Third-Party Integrations

Our service integrates with the following third-party platforms. Your use of these integrations is subject to the respective third-party privacy policies and terms of service.

Communication Platforms

  • Google (Gmail, Google Meet): Email synchronization and meeting transcript processing via Google OAuth.
  • Microsoft (Outlook): Email synchronization via Microsoft Graph API and Microsoft OAuth.
  • WhatsApp: Two-way messaging via the WhatsApp Business API.
  • Aircall: Call tracking and transcript processing via Aircall API.
  • Ringover: Call tracking and real-time call integration via Ringover API.
  • Slack: Workspace messaging integration.
  • LinkedIn (via Browser Extension): The extension operates on LinkedIn pages to detect and capture messages. It accesses LinkedIn's page context to resolve profile URLs. The extension does not store your LinkedIn credentials or access your LinkedIn account beyond what is visible in your active browser session.

Applicant Tracking Systems

  • Loxo, Greenhouse, Lever, Workday, BambooHR, SmartRecruiters, JobVite: Candidate and client data synchronization via their respective APIs.

Service Providers

  • HireUp Platform (app.hireup.cloud, api.hireup.cloud): The primary application and API.
  • Clerk (clerk.com): Authentication and user management.
  • PostHog (posthog.com): Product analytics and feature flags.
  • Stripe (stripe.com): Subscription billing and payment processing.
  • Amazon Web Services: Cloud infrastructure including AI services (Bedrock), document processing (Textract), email delivery (SES), and location services.
  • MongoDB Atlas: Full-text and semantic search database.

6. Artificial Intelligence

HireUp uses artificial intelligence powered by Amazon Bedrock (Anthropic Claude models) to provide the following features:

  • Automated extraction of professional attributes (skills, titles, salary, location) from communications and documents
  • Contact profile summaries and classification
  • Search result summaries and query understanding
  • Campaign message draft generation

Your communication data is sent to AWS Bedrock for processing. AWS Bedrock does not use your data to train or improve its foundation models. AI-generated outputs are stored in your account alongside the source data.

AI-generated content may contain inaccuracies. You are responsible for reviewing AI outputs before acting on them.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide our services. Specific retention periods include:

Server-Side Data

  • Contact profiles and communications: Retained until you delete them or close your account.
  • AI-generated summaries and enrichment data: Retained alongside the contact profile until the contact is deleted.
  • Background job records: Automatically deleted after 7 days.
  • Application logs: Retained for 90 days in Amazon CloudWatch.
  • Search sessions: Retained for the duration of your account.

Browser Extension Data

  • Authentication tokens: Stored for the duration of your session and automatically cleared when you log out or close the HireUp application.
  • Message deduplication records: Retained for up to 7 days to prevent duplicate message processing, then automatically deleted.
  • Message retry queue: Messages that fail to send are retained for up to 24 hours before being automatically discarded.
  • Extension settings: Stored until you uninstall the extension or manually reset settings.

Uninstalling the HireUp Browser Extension removes all locally stored data from your device.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data. You can delete individual contacts or bulk-delete all contacts through the platform. Account deletion requests can be made by contacting us.
  • Restriction: Request restriction of processing in certain circumstances.
  • Portability: Request your data in a portable format.
  • Objection: Object to processing based on legitimate interests.
  • Revoke consent: Disconnect any integrated channel at any time through your account settings, which revokes our access to that channel's data.

To exercise these rights, contact us at privacy@hireup.cloud.

9. Data Processing

When you use HireUp on behalf of your organization, your organization is the data controller and HireUp acts as a data processor. We process personal data only as instructed by the data controller and in accordance with this privacy policy.

For enterprise customers requiring a formal Data Processing Agreement (DPA), please contact us at privacy@hireup.cloud.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new privacy policy on this page and updating the "Last updated" date.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at privacy@hireup.cloud.