Legal · Privacy Policy
Privacy Policy
Effective June 3, 2026
1. What we collect
When you sign up, we collect:
- Your email address (for sign-in and transactional email).
- Optional full name (if you provide one on signup).
- An encrypted password hash via Supabase Auth — we never see your plaintext password.
When you run an analysis, we additionally store:
- The job description and candidate resume text you submit.
- The transcript and scorecard the model produces.
- Metadata about the run (timestamp, mode, credits consumed).
We do not use your analysis content to train or fine-tune any model.
If you use optional features, we also store: a referral code and the referral events linking you to people you invite (so we can credit both accounts); and any post-hire outcome you record on a past analysis (still here / promoted / let go / under-performing), which is added to your own private calibration data to sharpen your future analyses. We never share this across organizations.
2. Data processors (sub-processors)
- Anthropic — AI inference for the analysis engine. CV + JD text is sent to Anthropic at run time; under Anthropic's API terms, API content is not used for training.
- Stripe — payment processing for credit-pack purchases. Stripe stores card details on its PCI-DSS infrastructure; we never see or store full card numbers.
- Supabase — Postgres database + authentication. Hosts the user table, credit ledger, and analysis history.
- Resend — delivery of transactional emails (purchase receipts, password-reset, etc).
- Crisp — customer-support live chat. If you open the support widget, the messages you send (and, when signed in, your account email) are shared with Crisp to route and answer your request. Crisp does not receive CV, candidate, or job-description content.
- PostHog (EU) — product analytics. Receives only pseudonymous behavioural events (e.g. signup, analysis run, purchase) keyed by an opaque user id; never CV, candidate, or job-description content.
- Ahrefs Web Analytics — cookieless website analytics. Receives aggregate page-view data (URL visited, referrer, approximate country, device type); sets no cookies and never receives CV, candidate, or job-description content.
- Google Cloud Run — application hosting in the us-central1 region.
3. Your GDPR rights
If you are in the EU/UK or any other jurisdiction with GDPR-equivalent rights, you have the following rights over your data:
- Right of access — self-serve: sign in and visit /dashboard or hit
GET /api/me/gdpr-exportto download a JSON file containing every row we hold tied to your account (profile, balance, transactions, analyses, ranking runs, rate-limit history). - Right to rectification: update your email or full name from your account page, or email contacto@infinure.com.
- Right to erasure — self-serve: sign in and visit /settings → Delete my data (or hit
POST /api/me/gdpr-delete)). This immediately and permanently deletes your analyses, rankings, promote assessments, roles, candidate CVs and calibration sets, anonymizes your account, and signs you out. Financial records are retained where required by law (eg invoice records for tax purposes). You can also email contacto@infinure.com. - Right to portability: the GDPR-export JSON is the portability artifact — it is structured, machine-readable, and contains the full dataset.
- Right to object / withdraw consent: stop using the Service and request deletion. There is no separate marketing consent — we only send transactional emails.
4. Retention
Analyses, rankings and calibration sets are retained on your account so you can re-download transcripts and PDFs, until you delete them. You can erase all of it at any time, yourself, from /settings → Delete my data. Financial records (transaction ledger, Stripe receipts) may be retained for up to 7 years where required by tax or accounting law in our operating jurisdiction.
Shared verdict links. If you create a read-only share link for a verdict, anyone holding that link can view it — including the candidate names it contains — without signing in. A link is only ever created by your deliberate action, and you can revoke it at any time, which immediately and permanently disables it.
5. Security
- All connections use HTTPS; HTTP is rejected.
- Database access is mediated by Supabase row-level security policies + a service-role key held only in our server runtime.
- Authentication tokens are JWTs issued by Supabase Auth, scoped to .infinure.com, with short lifetimes.
- Stripe webhook signature verification is enforced on every billing event.
- An internal audit log records every credit purchase and analysis consumption.
6. International transfers
The Service runs on US infrastructure (Google Cloud Run, us-central1). If you access the Service from outside the US, your data is transferred to and processed in the US. Where required, we rely on the EU Standard Contractual Clauses as the lawful transfer mechanism with our sub-processors.
7. Cookies & analytics
We use a single first-party authentication cookie set by Supabase Auth to keep you signed in. This is strictly necessary and requires no consent. With your consent, we also use PostHog (EU) for privacy-friendly product analytics (see §3): it stores a first-party identifier in your browser to measure how Verdict is used, and never receives CV, candidate, or job-description content. You choose to accept or decline analytics in the banner shown on your first visit, and you can change your mind by clearing your browser storage. We do not use any third-party advertising cookies, ad pixels, or cross-site trackers on Verdict.
8. Children
Verdict is not directed to or intended for children under 16. We do not knowingly collect personal data from minors.
9. Nature of the assessment
Verdict is a decision-support tool. An assessment is an analysis of the evidence in the documents you provide (a CV against a job description) — it is not a judgment of the person, and it is never intended as a negative or malicious characterization of any candidate. Language such as "weak fit" or a noted "gap" describes the fit between the supplied evidence and a specific role at a point in time; it says nothing about a person's worth, character, or potential.
The assessments are produced by AI models, which can make mistakes — they may misread, omit, or misweigh information. Evaluations are evidence-based but directional and probabilistic: re-running the same analysis on the same inputs can yield different results. Outputs are therefore guidance, not definitive verdicts, and must be reviewed by a human and weighed alongside other information. Verdict should never be used as the sole basis for a hiring, promotion, or rejection decision.
10. Changes
We may update this policy. Material changes will bump the effective date and, when significant, be announced to the email on file at least 14 days before they take effect.
11. Contact
Infinure · contacto@infinure.com