How HireKey handles your data

This page explains how HireKey processes and stores information used by its job-search features. Our Privacy Policy covers additional privacy information.

1. Hosting and storage

HireKey's application frontend is hosted on Vercel and its backend on Railway. The public website uses WordPress. Application records and uploaded documents are stored using Supabase.

Saved information can include your profile, resume content, job applications, generated documents, interview preparation, company briefings, coaching conversations, scores, debriefs and usage records. PDF and Word exports are generated when requested; downloading an existing result does not create another saved version.

2. Connections and credentials

HireKey uses HTTPS for communication with its application services. Backend service credentials are configured in the hosting environment. They are distinct from the public configuration needed by the browser application.

3. Account access

HireKey uses Supabase authentication, including Google sign-in. Application endpoints verify authentication and apply ownership or organisation-access checks. Database access policies provide additional controls where applicable. Backend operations using privileged service credentials also rely on application-level access checks.

4. Application safeguards

The application includes request validation, access checks and rate limits. AI features include instructions to treat uploaded content as data and to avoid inventing qualifications or experience. These measures do not guarantee that every error or misuse will be prevented.

5. AI processing

HireKey uses OpenAI APIs for its current content-generation and coaching features. Depending on the feature, inputs can include resume text, job descriptions, interview answers and related context. The provider processes these inputs to return the requested output. Provider processing and retention are separate from the saved records in your HireKey account.

6. Voice interview coaching

When you use the microphone, your browser converts speech to text. Depending on the browser, this may involve its speech-recognition provider. You can type your answer instead.

HireKey sends submitted answer text and relevant coaching context to its AI provider to generate feedback. We save conversation text, progress, scores and debriefs so you can return to your session. Coach response text is sent to Microsoft's speech service for audio playback. The current coaching flow does not save raw microphone recordings or generated playback audio as files in HireKey storage.

Coaching conversations and debriefs are separate from the resumes and cover letters listed in Documents. Removing a document does not remove its related coaching history.

7. Error reporting and analytics

HireKey uses Sentry for backend error reporting. Its reporting code removes request bodies, cookies and query strings, filters request headers and user fields, and applies credential redaction. Operational logs and analytics are separate systems and may contain technical metadata.

Our public website uses PostHog to understand website usage. We do not describe technical identifiers as anonymous simply because they are not a person's name.

8. Service providers

ProviderPurpose and information processed
VercelApplication frontend hosting and delivery, including request and device metadata.
RailwayBackend application processing, including information submitted to application features.
SupabaseAuthentication, application records and uploaded document storage.
OpenAIAI generation and coaching using relevant user inputs and context.
Microsoft speech serviceCoach response text for speech playback.
Browser speech-recognition providerMicrophone input for speech-to-text, depending on the browser used.
StripePayment and subscription processing.
GoogleGoogle sign-in when selected.
PostHogWebsite analytics and associated technical metadata.
ResendTransactional email delivery, including email addresses, retention notices and delivery metadata.
SentryBackend error reports with the filtering described above.

9. Retention, deletion and backups

HireKey saves document content and related information so you can return to your work. PDF and Word downloads are generated when requested; repeated downloads do not create additional saved versions.

Saved versions per job

  • Tailored resumes: the latest version plus up to one older version.
  • Cover letters: the latest version plus up to one older version, regardless of tone.

After a new version is saved successfully, versions exceeding these limits are automatically removed from Documents. You can delete any of your files at any time. Removed files are kept for seven days for easy recovery before being permanently deleted.

Older versions are also eligible for removal after six calendar months, with the same seven-day recovery period. We preserve the latest tailored resume and the latest cover letter for each job under these older-version rules.

Some older documents lack reliable job information. We preserve these copies rather than guess which versions to remove. You can remove unwanted copies through Documents.

Inactive accounts

For free accounts and accounts without an active paid subscription, saved documents and uploaded files become eligible for deletion after twelve months without an authenticated visit or meaningful use of HireKey. Accounts with an active paid subscription or organisation-sponsored access are excluded from this inactivity cleanup.

We email a notice thirty days before deletion and a final reminder seven days before deletion. Signing back in cancels the scheduled deletion. You can download your documents before the deletion date.

Other records and backups

These document rules are separate from coaching conversations and debriefs, account records, billing information and security logs. Removing documents does not necessarily remove these other records.

Deleting an active record does not necessarily remove copies from provider backups or operational logs immediately. This page does not promise continuous point-in-time recovery, a fixed backup-retention period or a guaranteed restoration time.

For questions about retained information or a deletion request, contact privacy@hirekey.io.

10. Security reports and certifications

HireKey does not currently hold a SOC 2 report. We do not offer a formal bug bounty programme. Please send suspected security issues to privacy@hirekey.io, with enough detail to help us investigate. Avoid including unnecessary personal information or credentials.

11. Your responsibilities

  • Keep your sign-in credentials secure and enable multi-factor authentication on your sign-in provider where available.
  • Upload only information you are authorised to use.
  • Review generated documents and advice before relying on them or sharing them.

Security questions and reports: privacy@hirekey.io