hirenao

Privacy Policy

This policy explains what Hirenao processes when you build a job radar, create an account, connect another service, or turn on alerts. Effective date: July 27, 2026.

Draft for review. This document is an early, unreviewed draft prepared for the site owner’s legal review. It is not legal advice, has not been reviewed by counsel, and should not be relied on as final.

Summary

Hirenao is a candidate-side job discovery and application-preparation service. It uses the information you provide to create a profile, rank third-party job listings, explain the results, and generate optional application materials. Hirenao does not send your resume to employers, submit applications, or make employment decisions for employers.

The current product has no advertising integration. Hirenao sends information to the vendors and other recipients described below to operate the service. The contracts and data-control settings that determine the final legal classification of those transfers must be confirmed before this draft is published as final.

Information we collect

  • Account and contact information. Email address, email-verification status, a password hash for email accounts, and account and session timestamps. Hirenao does not store your plaintext password.
  • Resume and search input. Resume text; files or screenshots you upload; file name and type; search prompts, clarifications, refinements, profile-question answers, and other text you submit. Resume content may reveal professional, education, location, work-authorization, or other information about you. Please remove Social Security numbers, financial account data, medical information, and other details that are not needed for a job search.
  • Profile and generated data. Parsed and inferred information such as name, skills, experience, education, projects, seniority, locations, work preferences, work-authorization signals, strengths, gaps, career direction, source provenance, confidence values, and mathematical embeddings.
  • Radar and application activity. Radar prompts and filters, recommendations and explanations, saved, hidden, and applied jobs, application stages, more-or-less feedback, refinement chat, revision history, and the application materials you ask Hirenao to generate.
  • Connected-service information. If you connect GitHub or LinkedIn, Hirenao stores the provider account identifier, reported email and verification status, granted scopes, token expiry, and encrypted access or refresh tokens. A provider may also return a name and avatar during sign-in. Hirenao may add the reported name to your candidate profile; it does not currently persist the provider avatar URL. For GitHub, Hirenao also reads public profile information, public repository metadata and descriptions, and repository language data to derive profile facts such as skills and notable projects. LinkedIn is currently used for basic sign-in information; only the reported name is added to the candidate profile.
  • Email-alert information. The email address and filter you choose, confirmation and unsubscribe status, message content, and delivery and provider-reconciliation records.
  • Communications with Hirenao. If you email the privacy contact, Hirenao and its email providers receive the sender and recipient addresses, subject, message body, attachments, routing information, and delivery metadata. Please do not send identity documents, passwords, financial information, or other highly sensitive material unless Hirenao specifically asks for it through an appropriate channel.
  • Browser, device, and security data. A first-party sign-in cookie, a random anonymous radar identifier, temporary browser storage described below, IP address or IP-prefix rate-limit records, user agent, request and error metadata, and aggregate page-view information in production.

Where the information comes from

  • directly from you when you type, upload, connect, save, apply, or subscribe;
  • from GitHub or LinkedIn after you approve the provider’s permissions;
  • from Hirenao’s processing of your input and your use of the service; and
  • from hosting, analytics, security, and email providers that operate the service.

How we use information

  • build, restore, personalize, rank, and explain your radar;
  • generate profile questions, resume-edit suggestions, and draft cover letters;
  • save your preferences and application progress when you ask us to;
  • create and secure accounts, sessions, and connected-service links;
  • verify email, reset passwords, provide service and legal notices, and send job alerts you confirm;
  • prevent abuse, enforce limits, investigate failures, protect users, and maintain the service;
  • measure aggregate usage and improve reliability and product performance; and
  • comply with law and protect legal rights.

AI and automated processing

Hirenao sends information to OpenAI to transcribe resume screenshots, parse resumes and prompts, create embeddings, rank jobs, produce explanations, interpret refinements and profile answers, and draft resume edits or cover letters. Depending on the feature, this can include resume content, prompts and chat, connected-account-derived profile facts, job and application-preference context, and third-party job descriptions.

Hirenao sends model requests with provider-side response storage disabled. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. Under OpenAI’s standard API data controls, abuse-monitoring logs may include content and may be retained for up to 30 days, unless OpenAI is legally required to retain them longer.

Rankings and generated text are probabilistic and can be incomplete, inaccurate, biased, or out of date. They support your own job search; they are not employer assessments or automated hiring decisions. Review every listing and every generated application statement before relying on or submitting it.

Cookies and browser storage

  • A first-party, HttpOnly cookie keeps signed-in users authenticated. Short-lived, first-party OAuth transaction cookies protect sign-in and connection flows.
  • A random identifier in local browser storage identifies an anonymous radar before you create an account. It can be claimed by your account when you sign in.
  • The resume, prompt, uploaded-file bytes, and build state can be held temporarily in session storage while a radar builds. Hirenao normally replaces that input with a server-side radar pointer after a successful build; it can remain until the tab session ends if browser storage is unavailable or cleanup fails.

Clearing browser storage does not itself delete information already stored on Hirenao servers, and it can remove the anonymous identifier needed to access and delete an anonymous radar.

Who receives information

Hirenao uses the following vendors to operate the current service:

OpenAI
Processes resume text and screenshots, prompts, profile and application context, job data, refinements, and profile answers for OCR, parsing, embeddings, ranking, explanations, and application-material drafts. Hirenao sends model requests with response storage disabled. OpenAI says API inputs and outputs are not used for training by default; standard abuse-monitoring logs may retain content for up to 30 days unless OpenAI is legally required to retain them longer. Approved modified or zero-retention controls can change what those logs contain.
Supabase
Hosts the database used for accounts, profiles, radars, recommendations, saved and application activity, connected-account records, and email-alert records.
Vercel
Hosts the application and processes request metadata such as IP address and user agent in infrastructure logs. In production, Vercel Web Analytics also receives page-view data for aggregate, cookie-free analytics.
Resend
Receives recipient and sender addresses, message content, attachments when present, unsubscribe headers, routing information, and delivery metadata. It sends verification, password-reset, and opted-in job-alert emails, receives mail addressed to the privacy contact, stores inbound messages in its receiving service, and forwards complete privacy-contact messages to the configured destination mailbox.
Google
Operates the private Gmail mailbox that receives forwarded privacy-contact messages, including their content and attachments. Google’s favicon service also receives company domains requested by Hirenao’s server for company logos; it does not receive the requesting user’s browser IP address or a user-linked sequence of the roles shown.

GitHub and LinkedIn receive the OAuth requests you initiate and respond under their own terms and privacy policies. When you follow a job or application link, the destination site receives information from your browser under its own policy.

Email sent to Hirenao’s privacy address is received and stored in Resend’s inbound-email service. Hirenao asks Resend to pass the complete message through to a private Gmail mailbox operated by Google. Google also receives and may store the message and its attachments; the private destination address is not published.

Company logos are fetched by Hirenao’s server from Google’s favicon service. Google receives the requested company domain, but not your browser IP address or a user-linked sequence of the roles shown to you.

We may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a merger, financing, acquisition, or sale. A successor would remain subject to this policy for information collected under it unless users receive legally required notice of a change.

Retention and deletion

Hirenao currently has no inactivity-based deletion schedule for profiles, radars, or anonymous radars. Account, profile, radar, recommendation, refinement, and application activity remains in the active database until you use a deletion control or a legal or operational need requires a different result. This criterion is being converted into a fixed, counsel-reviewed retention schedule before launch.

  • Signed-in users can delete the account and its active product data from Settings.
  • An anonymous user can delete the current profile, radar, and associated product data with the Delete my data control on that radar, while the browser still has its anonymous identifier.
  • A locally connected provider token and binding are deleted when you disconnect it, after you establish another sign-in method if it is your only credential. Disconnecting does not revoke the provider’s own authorization grant; you can also revoke Hirenao from the provider’s settings.
  • Confirmed job alerts remain until you unsubscribe, replace the subscription, delete its radar, or delete your account. Unconfirmed subscriptions do not yet have an automatic expiry.
  • Sign-in sessions have a 90-day absolute maximum. Short-lived in-memory parsing and OCR caches expire after about 15 minutes.
  • Privacy-contact messages can remain in Resend’s inbound-email service and the forwarding destination mailbox under their configured retention settings. Hirenao does not yet have a fixed deletion schedule for those messages or attachments.

Uploaded file bytes are processed in memory and are not intentionally stored as files in Hirenao’s database, but extracted resume text and generated profile data are stored. A resume screenshot is also sent to OpenAI for transcription.

Deletion removes active Hirenao database records through the product’s deletion flow. Limited security logs, provider records, backups, or an email delivery record whose provider outcome is still uncertain may remain under provider schedules, legal obligations, or until the delivery is reconciled. Hirenao does not use deleted information for ordinary product operations.

Your choices and rights

  • Export the main account, profile, radar, preferences, and subscription data included in Hirenao’s self-service export from Settings. Contact us if you need an access request covering other eligible records.
  • Correct profile facts through the product, or ask us to correct eligible account data.
  • Delete a signed-in account or the current anonymous radar as described above.
  • Disconnect GitHub or LinkedIn from Connections and revoke Hirenao separately in the provider’s settings.
  • Unsubscribe from any job alert using the link in that email.
  • Exercise access, correction, deletion, portability, restriction, objection, or appeal rights that apply where you live.

We may need to verify your identity and authority before completing a request. Applicable law may permit or require us to deny or limit a request, in which case we will explain the reason when legally allowed. We will not discriminate against you for exercising a privacy right.

California and tracking disclosures

The categories described above include identifiers, internet or device activity, professional and education information, account and job-search activity, and inferences drawn from that information. Hirenao collects them from the sources and for the purposes described above and sends them to the recipients identified in this policy for the stated operational purposes. Resume content can also contain other or sensitive information that you choose to include.

The current implementation has no advertising integration or data-broker feature and does not use tracking technologies to serve cross-context behavioral ads. It therefore does not currently change product behavior in response to browser Do Not Track or Global Privacy Control signals. Before publication, counsel must confirm the California-law classification of each vendor transfer, the final sale-and-sharing disclosure, and whether any additional signal response or control is required.

Security

Hirenao uses measures designed to protect information, including encrypted transport, hashed passwords and session tokens, HttpOnly authentication cookies, encrypted connected-account tokens, access controls, request validation, and rate limits. No internet service or storage system can guarantee absolute security. Please use a unique password and tell us promptly if you believe your account or data has been compromised.

Children

Hirenao is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so we can investigate and delete it as appropriate. The final Terms must set a counsel-approved eligibility rule for teenagers before launch.

International processing

Hirenao and its providers may process information in the United States and other countries, where privacy laws may differ from those where you live. Any legally required transfer safeguards and regional notices must be confirmed before Hirenao is offered in a jurisdiction that requires them.

Changes to this policy

We will update the effective date when this policy changes. For material changes, Hirenao will provide additional email or in-product notice when required and seek renewed acknowledgment or consent where applicable. Changes apply prospectively unless law permits otherwise.

Contact

Questions and privacy requests can be sent to privacy@hirenao.ai. Messages sent there are received by Resend and passed to a private Gmail mailbox operated by Google. Both providers may store the message and its attachments. The operator’s final legal name, mailing address, phone number, access restrictions, and fixed retention procedure for those messages must be confirmed before publication.