// legal
Privacy Policy
How we collect, use, share, and protect your personal data when you use Hyrrd.
Last updated: August 30, 2026
Hyrrd Labs (“Hyrrd”, “we”, “us”) operates a hiring-intelligence platform that helps engineering teams find candidates by analyzing real work signals. This policy explains what personal data we process, why, and the rights you have over it. It applies to candidates, recruiters, and visitors to hyrrd.tech.
1. Data we collect
Data you provide
- Account data: name, email, and authentication identifiers (e.g. your GitHub OAuth account).
- Candidate profile: résumé/CV files you upload, headline, location, years of experience, work history, preferred work modes, and availability.
- Recruiter/company data: company name, role postings, search queries, and shortlisting decisions.
Data we ingest with your authorization
- GitHub activity: when you connect GitHub, we read public repositories, commits, pull requests, and contribution metadata to derive capability signals. We do not access private repositories unless you explicitly grant that scope.
- Derived signals: structured signals and embeddings computed from the above (e.g. domain depth, ownership signals, tech-stack vectors). These are inferences, not raw source content.
Data collected automatically
- Usage & device data: pages viewed, actions taken, IP address, and browser/device information, collected via product analytics (PostHog) and error monitoring.
2. How we use your data
- To build your candidate intelligence profile and compute match scores.
- To let recruiters discover and evaluate candidates for open roles.
- To operate, secure, debug, and improve the platform.
- To send transactional email (application updates, interview scheduling, reminders).
- To detect abuse and enforce our Terms of Service.
We do not sell your personal data. We do not use your résumé or code to train third-party foundation models beyond the transient processing described below.
3. AI processing
We use third-party AI providers (e.g. OpenAI, Anthropic) to parse résumés, summarize candidate work, and power natural-language search. Content is sent transiently for inference and is not used by us to train models. Our providers are contractually bound not to train on data submitted through their business APIs.
4. Legal bases (EEA/UK)
- Contract: processing needed to provide the service you signed up for.
- Legitimate interests: improving and securing the platform, and connecting candidates with relevant roles — balanced against your rights.
- Consent: connecting optional data sources (e.g. GitHub) and any non-essential analytics, which you may withdraw at any time.
5. Sharing
- With recruiters: candidate profiles and derived signals are shown to verified recruiters on the platform for the purpose of hiring.
- Service providers (subprocessors): cloud hosting and database (Vercel, Neon/Postgres), object storage (Cloudflare R2), email delivery, AI inference (OpenAI, Anthropic), background jobs (Inngest), and analytics/monitoring (PostHog). Each is bound by a data-processing agreement.
- Legal: where required by law or to protect our rights and users’ safety.
6. Retention
We retain profile data for as long as your account is active. If you delete your account, we delete or irreversibly anonymize your personal data within 30 days, except where we must retain limited records for legal, security, or audit purposes. Backups are purged on a rolling schedule.
7. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or port your data, and to object to certain processing. You can export or delete your data from your account settings, or see our GDPR & Data Rights page. To make a request, email privacy@hyrrd.tech.
8. Security
We use encryption in transit, access controls, and least-privilege practices. See our Security page for details. No system is perfectly secure; we encourage responsible disclosure of any vulnerabilities.
9. International transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Children
Hyrrd is not directed to individuals under 16, and we do not knowingly collect their data.
11. Changes
We may update this policy; material changes will be announced in-app or by email. The “last updated” date above reflects the current version.
12. Contact
Hyrrd Labs — Data Protection. Email privacy@hyrrd.tech.