Privacy Policy

Version v2.0 · Last updated 2026-07-28

1. Data we collect

We collect the following categories of data:

  • Account data: name, email, profile image (if you sign in with a social provider), password hash (we never store plaintext).
  • Workspace data: saved searches, saved builders, private notes per builder, alerts, exports.
  • Claim data: if you claim a builder profile, your email and a one-time token. We never store the token after use.
  • Usage data: server logs (IP address, user agent, page path, response code) for 30 days. We use these for abuse prevention and capacity planning.
  • Device recognition data: a one-way, salted hash of a random device identifier we set in a first-party cookie, combined with a coarse browser family (e.g. "chrome", "safari") — never your full browser/OS string, screen size, fonts, or any other device fingerprint, and never reversible back to the original values. We use this only to recognize when the same device signs in to multiple accounts or an unusual number of accounts sign up from it, as part of abuse prevention.
  • Interview data (candidates): if someone using BuilderHunt invites you to an interview, we process what you submit and what happens in the interview. This is set out in full in section 9.
  • Cookies: see our Cookie Policy.

2. How we use your data

We use your data solely to: (a) provide and improve the Service; (b) deliver alerts and exports you create; (c) prevent abuse and enforce our Terms; (d) comply with legal obligations. We do not sell your personal data to third parties, ever.

3. Subprocessors

We share data only with the following subprocessors, all of which are bound by data processing agreements:

  • PostgreSQL database (self-hosted) — primary data store. Encrypted at rest.
  • Redis (self-hosted, when configured) — session cache, rate limiting.
  • GitHub, Reddit, Hacker News, DEV.to, npm, Hugging Face, GitLab, Codeberg — public data sources we query on your behalf.
  • Resend — sends transactional email only (account verification, password reset, organization invitations, smart-alert digests, and account deletion/data-export notices). Falls back to a server-side console log with no third-party call when unconfigured.
  • MiniMax M3 — a server-side AI model used to generate persisted, shared artifacts (e.g. profile enrichment summaries, code fingerprints) and to power background AI features. We only send public profile data and your own submitted inputs (e.g. a job description) — never your account email, password, private notes, or other users' data.
  • Embedding provider (configured via a server-only vector API) — converts already-public builder profile text into numeric vectors that power semantic search. No account data is embedded.
  • Stripe — our payment processor. Billing is not yet enabled for customer accounts: today, Stripe is used only for our own product-catalog setup and to verify the authenticity of Stripe's webhook messages — no customer payment method, card, or subscription data is sent to or received from Stripe yet. Once billing is enabled, this section will be updated before any customer payment, card, or subscription data is processed.
  • Hetzner Online (Germany) — hosts the servers this service runs on, the database, and the off-site encrypted backups. All of it sits in EU data centres. Everything you store with us is stored on their infrastructure; they do not access it.
  • Mistral AI (France) — generates interview briefs and reports from candidate documents and interview notes, when a customer enables that feature. EU-processed by default, on a paid API that is not used to train models. This replaced a previously planned US provider specifically to keep this processing inside the EU. Not yet enabled for any account.
  • Deepgram — transcribes interview audio, when a customer enables that feature and every participant has consented. Routed exclusively through Deepgram's EU endpoint; our servers refuse to start if configured to use any other region. Not yet enabled for any account.

Entries marked not yet enabled are listed in advance because we would rather over-disclose than update this page after the fact. They process nothing until the corresponding feature is switched on for your organization, and we will not switch it on without the consent flow described below.

We do not use Sentry or PostHog — no error-tracking or analytics provider currently has access to your data.

4. Cookies and localStorage

We use cookies and localStorage for authentication (session), cookie-consent state, onboarding state, and a random device identifier used for abuse prevention (see "Device recognition data" above). We do not use third-party analytics cookies by default. See our Cookie Policy for details and how to opt out.

5. Data retention

We retain your account data for as long as your account is active. If you delete your account, all your personal data is permanently deleted within 30 days (the grace period you can cancel). After 30 days, we retain only anonymized, aggregated statistics (e.g., "we had N searches today") that cannot identify you.

Device recognition data and internal abuse-review records follow the same lifecycle as your account and are deleted along with it, with one exception: where a specific signal was already part of an active fraud or abuse investigation, we may retain that specific record after account deletion, consistent with our need to keep an audit trail for that investigation — never for any other purpose.

6. Your rights (GDPR Art. 15–22)

As a data subject you have the right to:

  • Access (Art. 15): see all data we hold about you. Use Privacy → Export my data in your dashboard.
  • Rectification (Art. 16): edit your profile and notes anytime from your dashboard.
  • Erasure (Art. 17): delete your account. Use Privacy → Delete account.
  • Restriction (Art. 18): contact us to restrict processing while a dispute is open.
  • Portability (Art. 20): export your data as JSON. Same control as access.
  • Object (Art. 21): opt out of non-essential processing. Cookie preferences are available on the cookie banner.

7. California (CCPA / CPRA)

California residents have the right to: (a) know what personal information we collect, use, share, or sell; (b) delete personal information we collect; (c) opt out of the sale or sharing of personal information. We do not sell personal information. To exercise these rights, use the in-product controls or email privacy@builderhunt.dev. We honor Global Privacy Control (GPC) signals as opt-out.

8. International transfers

Our servers are located in the European Union. If you access the Service from outside the EU, your data is transferred to the EU. For users in the US, the data is stored in the EU. We use standard contractual clauses where required.

9. Children

The Service is not directed to children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact privacy@builderhunt.dev and we will delete it within 7 days.

10. Security

We use industry-standard security: TLS for data in transit, encryption at rest for the database, bcrypt for password hashing, parameterized queries to prevent SQL injection, and HTTP-only secure cookies for sessions. Despite our efforts, no system is 100% secure.

11. Changes to this policy

We may update this policy. Material changes will be communicated via email and in-product notice at least 14 days before they take effect. The current version is always at /legal/privacy.

12. Contact

Privacy questions: privacy@builderhunt.dev. You can also reach us at the address listed in our Imprint. We aim to respond within 5 business days.

9. Interviews: documents, public links, audio, and AI

This section is for candidates. It applies when a company using BuilderHunt invites you to an interview. Everything here happens only if you agree to it, and each part is a separate choice — there is no single "accept all".

Who is responsible for your data

The company interviewing you decides why your data is processed and is the controller. BuilderHunt is their processor: we handle it on their instructions and for no purpose of our own. Requests about your data are best directed to them; if you contact us we will pass them on and tell you we did.

What you can be asked to agree to

  • Documents you upload. A CV or portfolio you choose to send. We scan it for malware, extract its text so the interviewer can read and search it, and store both.
  • Public links you submit. If you tick the separate box confirming you are entitled to share it, we fetch a page you gave us and keep the text. We honour robots.txt, we never sign in to anything, and we never bypass a paywall or a login. Platforms whose terms forbid it — LinkedIn, X, Facebook, Instagram — are stored as a link only and never fetched.
  • Live transcription. During the interview your audio is streamed to a transcription service in the EU and turned into text as it happens. The audio itself is never stored— not by us and not by the provider. The text is stored.
  • AI assistance. A model reads the documents, the imported page text, and the transcript, and produces a preparation brief, suggested follow-up questions, and a written record of the interview.

Our legal basis

Your consent, for each of the four purposes above, recorded separately with the exact version of the notice you were shown. Boxes are never pre-ticked. Booking a time is not agreement to any of it: you can book an interview and decline all four.

Withdrawing, and what happens then

You can withdraw any of them at any time from the same page you gave them on. Withdrawal is not retroactive — it stops future processing and does not un-write what has already happened. Concretely: withdrawing transcription stops the transcription within ten seconds and the interview continues without it; withdrawing document processing stops any further use of your documents. Already-stored text remains until its retention period ends, or sooner if you ask the interviewing company to delete it.

Who else sees it

  • Transcription: Deepgram, EU endpoint (api.eu.deepgram.com). Audio in, text out, nothing retained.
  • AI: Mistral, EU (api.mistral.ai). Chosen for its region.
  • Storage: self-hosted, private buckets on our own infrastructure — no third-party storage provider. No document is ever publicly reachable.
  • Email: Resend, to send you the invitation.

Nothing you give us trains anyone's model. We do not train on your data and our providers are engaged on terms that forbid training on it.

How long it is kept

  • Documents and their extracted text: 180 days.
  • Transcripts, briefs, and interview records: 90 days.
  • Consent receipts: up to 24 months — longer than the data, because the receipt is the evidence that processing it was lawful.
  • Audio: never stored, so there is nothing to delete.

An interviewing company may choose shorter periods. Deletion is automatic when the period ends.

No automated decision about you

The AI writes drafts for a human to read. It does not score you, rank you against anyone, or recommend hiring or rejecting you — the system has nowhere to record such a thing and refuses output that attempts it. Every AI output is labelled as a draft and is editable by the interviewer, who makes the decision. You are not subject to a decision based solely on automated processing.

AI output can be wrong. It can misattribute who said what, mis-transcribe a name or a technical term, and miss things. If you believe a record about you is inaccurate, you can ask the interviewing company to correct it, and you can ask for a human to review any conclusion drawn from it.

Your rights

Access, correction, deletion, restriction, objection, and portability, plus the right to complain to your data protection authority. Because the interviewing company is the controller, ask them first — they can act directly. Reach us at privacy@builderhunt.dev and we will route it and confirm we have.

10. Interview credits (for companies)

Interview features consume prepaid credits: a preparation brief and a written record cost 5 credits each, live transcription costs 1 credit per minute the provider bills, and follow-up suggestions are included while transcription is running. Credits are reserved when work starts and settled against what the provider actually billed, with the unused part returned.

Running out of credits stops paid transcription. It does not end an interview in progress, and notes keep saving.