Privacy Policy
Last updated 28 July 2026
Hyrewell is software that companies use to hire. In plain English, this page covers what we collect, why we collect it, and the control you have over it. If anything here is unclear, write to support@hyrewell.com.
Who we are
Hyrewell is an agentic AI hiring platform. Hirers use it to screen applications, run interviews and send offers. For anything in this policy, including data requests, the contact point is support@hyrewell.com.
What we collect
It depends on which side of the hiring table you are on.
- If you hire with Hyrewell: your account email, your name, company details such as your company name and logo, and how you use the product, like the roles you create and the resumes you screen.
- If your employer runs talent reviews on Hyrewell: employee data provided by the employer, such as your name, position and your manager’s assessments. It is assessed only on job-related skills, and it is visible only to the account owner and the assessors they choose.
- If you applied for a job: your resume, your answers to screening questions, your contact details, interview notes and feedback about you, messages the hirer sends you through Hyrewell, and any offer documents you sign.
Candidates never create an account. Candidate data is submitted in the course of a specific hirer’s recruitment and is shared only with that hirer, not with other companies on Hyrewell.
What we take from your resume file
The file you upload is stored as you sent it. Screening also reads details out of it and saves them alongside your record, such as your current job title, your employer and the dates you printed. Three of those are worth calling out on their own.
- A photo, if your resume has one. If the file contains a headshot we pull it out and show it on your candidate card. It plays no part in screening: it is never sent to the AI, and it has no bearing on how your application is assessed. If you would rather it was not there, write to support@hyrewell.com and we will remove it.
- Links your resume prints. Public addresses already on the page, such as LinkedIn, GitHub or a portfolio, are pulled out and shown to the hirer as links. We take only what your resume itself shows, and we do not search the web to add anything to your application.
- A fingerprint of the file. We store a SHA-256 digest of the exact bytes you uploaded. It is a one-way fingerprint, not a copy, and it cannot be turned back into your resume. It exists so that the same document sent twice for the same job is recognised as one application and read once, rather than read and charged again.
What we use it for
- Screening applications against the job-related criteria the hirer confirmed.
- Scheduling and running interviews.
- Preparing, sending and signing offers.
- Telling you your application arrived, and telling the hirer that it did.
- Letting a hirer keep in touch about future roles at their company, but only where you ticked the box on their application form asking for exactly that. It applies to that one company, it is never assumed, and you can ask us or them to stop at any time.
- Billing hirers on a paid plan, and keeping the records we are required to keep.
We do not sell personal data, and we do not use it for advertising.
Job adverts we publish for hirers
A hirer can choose to publish a role publicly. When they do, we put the job advert on a page on hyrewell.com and on that company’s careers page, list it in our sitemap, and include it in a job feed that search engines and job boards read — Google for Jobs, and aggregators such as Adzuna, Jooble, Talent.com and Careerjet.
Only the advert travels, never an application. What we publish is the job itself: title, description, location, work type, salary range if the hirer gave one, and the company name and logo. No candidate’s name, resume, answers or contact details are ever placed on a public page or sent to a job board. Applying always happens on Hyrewell, and what you send goes only to the hirer you applied to.
A role stops being published the moment the hirer closes it: the page stops showing the job and it leaves the feed and the sitemap. Search engines re-crawl on their own schedule, so a closed job can linger briefly in their results after it has gone from ours.
Automated processing, and what it does not do
Resumes, screening answers and manager assessments in talent reviews are read by an AI model and matched against the job-related criteria the hirer confirmed for that role. What comes back is evidence: the words you actually wrote, quoted, next to the requirement they belong to.
There is no automated decision. Hyrewell produces no composite score, no percentage, no rating and no verdict on you. Nothing is accepted or rejected by the software. A person at the hiring company reads the evidence and makes every decision, including every rejection.
A hirer’s list may be ordered by how many of their own criteria the evidence met, so that they have somewhere to start. That order carries no score and decides nothing, and no application is hidden or dropped from it.
The criteria are job-related only. Screening never considers age, race, religion, nationality, gender, marital or family status, or disability, and never infers them.
Your data is never used to train AI models. Not by us, and not by our AI provider.
Who processes data for us
We run on a small set of specialist service providers. Each one processes data only to provide its service to us, under contracts that protect your data. These are the companies we use today:
| Provider | What it does |
|---|---|
| Anthropic | Reads resumes, cover letters, screening answers and manager assessments to produce evidence, and answers the support chat |
| Supabase | Holds the database and the uploaded files: resumes, cover letters, photos, logos and offer documents. Sends sign-in emails |
| Netlify | Hosts the site and runs its server functions |
| Resend | Delivers notifications to hirers and confirmations to candidates |
| Daily | Runs the video interview rooms |
| Stripe | Takes payment and holds the card details of hirers on a paid plan |
| Google Programmable Search | Searches the public web when a hirer uses candidate sourcing |
Payments
Only hirers pay, and only hirers on a paid plan. Card details are entered on Stripe’s own checkout and are held by Stripe: Hyrewell never sees or stores a card number. We keep the identifiers Stripe gives us so that your plan, your invoices and your cancellation work, along with your billing email and the record of what you were charged.
Candidates never pay for anything and are never asked for payment details.
How long we keep it
Candidate data is kept while the hirer’s account is active. Hirers can delete any candidate at any time, and deleting a hirer account permanently removes all of its roles, candidates, files and offers.
Cookies and local storage
There are no advertising cookies and nothing that follows you around the web. Your browser’s local storage keeps you signed in and remembers small interface preferences. To understand what is popular we may use privacy-friendly, cookie-less analytics that count page views without identifying you or setting a cookie.
Your rights
Under the data protection laws that apply to you, you can ask to access your data, have it corrected, withdraw consent, or have it deleted. Candidates can raise this with the hirer they applied to, who can act on it directly, or write to support@hyrewell.com and we will help.
If you are not satisfied with how we handle a request, you can raise it with the data protection authority where you live.
Changes and contact
If this policy changes, we will update this page and the date at the top. Questions, requests and complaints all go to support@hyrewell.com. Our Terms of Service cover the rest of the relationship.