Trust
Transparency & Policy Center
Everything about how SourceHire handles your data — what we collect, how AI participates in hiring workflows, how long things are kept, and the controls you can use yourself, right now, without emailing anyone.
Data we collect
Collected only to run the hiring workflow you asked for.
▸What applicants share with us
Your resume file, optional cover letter, the answers you type in an application, and your contact details. If you create an account: your email, a password hash (bcrypt — we never see the password), and profile fields you add. Basic technical context (IP, browser) is recorded with consent events and payments for security and receipt-evidence purposes.
▸What employers share with us
Job postings, screening questions, and — when a recruiter imports candidates by CSV or API — the records they attest they may lawfully process. Every import is batch-tracked with the importing account recorded, so provenance is always auditable.
▸What we do NOT do
We don't sell applicant contact data to advertisers, we don't use dark-pattern consent, and advertising surfaces only ever receive aggregated, anonymized cohort counts — never individual profiles.
How AI is used
AI assists; humans decide.
▸Resume extraction (opt-in)
If you grant AI-extraction consent when applying, we parse your resume into structured fields (skills, experience, location) so recruiters can find and evaluate you faster. If you decline, your resume is stored and shown to the recruiter as-is — you can still apply to everything.
▸Match scores and rankings
Match scores compare your structured profile against the job's stated requirements (skills, experience, location). They order lists for recruiters; they never auto-reject anyone. Rejection decisions are made by humans, and stage changes that trigger emails are recruiter-initiated.
▸No automated adverse decisions
No SourceHire system automatically rejects, disqualifies, or blacklists an applicant based on an AI signal. Automated emails fire only on recruiter-driven stage changes or clearly disclosed timers (e.g. a job's auto-close window that the employer explicitly enables).
Retention windows
Kept as short as the purpose allows.
▸Payment card details — 60 days
Card details captured for manual payment processing are encrypted at rest and purged 60 days after capture — the window needed to cover chargeback and dispute rights. Receipts retain only the last four digits.
▸Application data — until you delete it
Applications and profiles persist so recruiters can act on them and you can track them. You can trigger full erasure yourself at any time (see Your controls below).
▸Account closure — 60-day grace
Closing your account starts a 60-day grace period (in case it was unintended), after which deletion proceeds. Session cookies expire after 60 days of inactivity at most.
Your controls
Self-service, no support ticket required.
▸Delete everything (right to erasure)
Go to /data-access and verify you own the data — either by re-uploading the resume you applied with (matched by cryptographic hash) or by passing an identity quiz built from your own history. Verification succeeds → the erasure cascade runs immediately across profiles, files, and derived data.
▸Unsubscribe from email
Every marketing email includes one-click unsubscribe (RFC 8058) plus a footer link. Transactional emails about your own applications continue, since they're part of the service you requested.
▸Report an employer or listing
The Fraud & Reporting Center at /report takes reports with attachments and routes them to a human review queue. Reports are acknowledged and tracked.
▸EU / UK / California rights
Access, correction, portability, and deletion rights are honored via the tools above regardless of where you live; CCPA opt-outs and GDPR marketing-consent separation are enforced in our email pipeline at send time, per recipient.
Payments & receipts
Optional services, evidence-grade receipts.
▸What Priority Review is (and isn't)
Priority Review is an optional visibility service for applicants. It never changes hiring requirements and buying it is never required to apply. Terms are linked at purchase and on every receipt, versioned so your receipt always shows the terms you actually agreed to.
▸Receipts
Every purchase generates a receipt with the exact authorization language you agreed to, the checkout URL, timestamp, and technical evidence — the same artifact we'd present in a dispute, available to you at any time.
Fair hiring & EEO
Compliance built into the flow.
▸EEO data handling
Voluntary EEO self-identification is collected on a separate step, stored apart from the application a recruiter evaluates, and never shown alongside your candidacy.
▸Equal treatment of paid features
Paid visibility affects ordering in recruiter lists and is labeled as sponsored where it appears. It does not alter match scores, qualifications, or any hiring requirement.
Security
Defense in depth, verified continuously.
▸Platform protections
TLS everywhere; bcrypt password hashing; server-side sessions with immediate fleet-wide revocation; per-route rate limiting with exponential backoff; honeypot and bad-bot detection with automatic bans; encrypted-at-rest card data with scheduled purge; and API keys stored only as SHA-256 hashes.
▸Report a vulnerability
Email security@sourcehire.app. Good-faith research is welcomed; we commit to acknowledging reports promptly.
Subprocessors
Vendors that process data on our behalf.
| Vendor | Purpose | Region |
|---|---|---|
| Render | Application hosting | US |
| Neon | Postgres database | US |
| Upstash | Cache / rate limiting | US |
| Cloudflare | DNS, CDN, DDoS protection | Global |
| Vercel Blob | Resume file storage | US |
| SendGrid | Campaign email delivery | US |
| Resend | Transactional email | US |
| Anthropic | AI resume extraction (opt-in only) | US |
| Stripe | Advertiser billing | US |
Each subprocessor receives only the data needed for its purpose. This list is updated when vendors change.
Policy documents
The full legal texts, all in one place.