For recruiters
Privacy policy
How Kira-AI collects, uses, stores and shares your personal data, and how you can exercise your privacy rights.
- Last updated
- 15 September 2026
- Applies to
- getkira.com and the Kira-AI app
Contents
01
What this covers
This policy explains how Kira-AI (“we”) handles personal data on our website, in our recruiter application and during AI voice interviews.
- Recruiters and their colleagues — people who hold an account with us. For your account data we are the controller.
- Candidates — people invited to an interview by a company that uses Kira-AI. For candidate data the employer is the controller and we act on their instructions. For information about your interview data and rights, read our Candidate privacy notice.
02
Controller and processor
We are the controller for the data we need in order to run a business: your account and profile, your workspace and its settings, team membership and invitations, billing and subscription records, transactional email we send you, support correspondence, and the security and audit records described below.
We are a processor for everything that belongs to a hiring process: candidates, their interviews, recordings, transcripts, scorecards, and the notes recruiters write about them. The customer decides which roles to advertise, whom to invite, what to ask, how candidates are assessed and what happens next. We process that data only to provide the service, on the customer’s documented instructions.
The processor terms are set out separately in our Data processing agreement.
03
Your account data
We collect the following information to provide and manage your account:
- Identity and sign-in — email address, display name, an optional profile photo, interface language, and the authentication records held by our database provider (password hash, sign-in sessions, and that provider’s own security log, which does record IP addresses).
- Workspace — company name, logo, brand colour, client names and company information you provide to guide interviews.
- Team — who is a member, who owns the workspace, invitations you have sent (email address, a hashed invitation token, expiry) and when people joined or were removed.
- Connected AI apps — which app you connected, when you approved it, and the authorization records needed to keep the connection working.
- Billing — your subscription, plan and usage counts. Card details are handled by our payment provider and never reach our servers.
- Email we send you — recipient address, message type, template and delivery reference.
The public demo
If you try the demo, we collect your verified email address, product-updates preference, and the interview recording and transcript. Kira-AI is responsible for this data. Demo interviews are not scored or shared with hiring companies. We send product updates only if you opt in. To request deletion, email support@getkira.com.
What we do not collect
We use a hashed version of your IP address to limit repeated requests. These records are kept for 24 hours. We do not record browser or device fingerprints, we do not derive your location, and there is no analytics or advertising technology anywhere in the product or on this website — see Cookie policy.
Our hosting, storage and email providers also keep infrastructure logs that may include IP addresses.
04
Candidate data
We process the following candidate data on behalf of the hiring company:
- Identity — name (optional), email address, and an internal reference number.
- Invitation and consent — the invitation record, a hashed access token and a hashed one-time verification code, plus the exact version, language and timestamp of the consent the candidate gave.
- The interview — start, activity and completion timestamps, the interview language, which planned questions were answered or skipped, and an encrypted reference to the AI provider’s session.
- Audio — Separate audio recordings of the candidate and AI interviewer. We do not record video or request camera access.
- Transcript — The interview text, including who spoke and when.
- Scorecard — scores for each assessment criterion, explanations, supporting transcript quotes, strengths, gaps and relevant factual information. We also record the model and prompt version used to produce it.
- Human input — Recruiter ratings, notes and comments, recruitment stage and any recorded rejection reason.
- Candidate feedback — an optional star rating and free-text comment about the interview experience.
Kira-AI does not accept CV or document uploads.
05
Why we use personal data and our legal basis
| What | Why | Legal basis |
|---|---|---|
| Account, workspace, team | To provide the service you signed up for | Performance of a contract — Art. 6(1)(b) |
| Billing and usage counts | To calculate usage and issue invoices | Contract, and legal obligation for tax records — Art. 6(1)(b), 6(1)(c) |
| Transactional email | To send invitations, verification codes and account notices | Contract — Art. 6(1)(b) |
| Security, rate limiting, audit records | To prevent misuse and keep records of access | Legitimate interests — Art. 6(1)(f) |
| Candidate interviews and scorecards | To screen applicants for the hiring company | Determined by the hiring company as controller |
| Support access by our staff | To investigate problems at the customer’s request and record staff access | Legitimate interests, and the DPA — Art. 6(1)(f) |
06
How long we keep it
Recordings, transcripts and scorecards are kept until deleted. They do not expire automatically. The hiring company is responsible for deciding how long to retain candidate interview data.
How long we keep different types of data:
| Data | Kept for |
|---|---|
| Recordings, transcripts, scorecards, candidate records, recruiter notes | Until deleted. No automatic expiry. |
| Staff access records | 24 months |
| Deletion records | 24 months |
| Delivered or failed transactional email records | 30 days |
| Invitations that were never linked to a candidate | 30 days |
| Rate-limit counters (hashed IP) | 24 hours |
| Contact details on unused prospect invitations | 90 days |
| Unmatched payment-provider webhook events | 30 days |
07
Who else processes the data
Kira-AI is built on a small number of named providers. This is the complete list of parties that receive personal data, and what each one receives.
| Provider | What it processes | Where |
|---|---|---|
| Google (Gemini API) | Live interview audio in both directions, live transcription, the interview plan, the transcript and criteria for scoring, and recruiter-entered role text for drafting | See “Where the data lives” below — this is the open item |
| Supabase | The database and authentication: candidate records, transcripts, scorecards, recruiter accounts and notes | EU — Frankfurt |
| Cloudflare (R2) | Interview audio files, workspace logos, and the deletion ledger | EU-jurisdiction storage, enforced at start-up |
| Fly.io | The voice relay and background workers. Audio passes through memory only and is never written to disk | EU — Amsterdam |
| Vercel | Hosting for the website, the recruiter app and the admin console — all web traffic passes through it | See “Where the data lives” below |
| Resend | Transactional email: recipient address and message content | United States |
| Stripe | Subscriptions and payments. Receives billing contact details only, never candidate data | US, under standard contractual clauses |
There is no analytics, tracking, advertising or session-replay provider in the product or on this website, and no separate speech-to-text vendor: transcription is produced by the same model that conducts the interview.
08
Data locations and international transfers
Our interview database and audio storage are located in the EU.
Google’s Gemini API processes interview audio, transcripts and assessment prompts. This processing may take place outside the European Economic Area (EEA).
Our application is hosted in Frankfurt, while our hosting provider may route requests through other countries.
Resend stores email data, including recipient addresses and message content, in the United States.
We will transfer personal data outside the EEA only where permitted by applicable data protection law, using an applicable adequacy decision or appropriate safeguards, such as the European Commission’s standard contractual clauses.
09
Automated decision-making
Kira-AI does not make hiring decisions. This is not a positioning statement; it is how the system is built, and it was verified against the code before this page was written.
- The model produces evidence, not verdicts. It is instructed never to recommend hiring, rejecting, advancing or ranking anyone, and never to state an overall judgement. It returns per-criterion scores with written rationale and verbatim quotes, must-have outcomes, and short strength and gap bullets.
- The overall band shown on a scorecard is calculated by our own code as the arithmetic mean of those criterion scores, with each scored criterion counting equally. It is a triage label. It changes nothing about the candidate’s status.
- There is no automatic rejection, no automatic advancement, and no score threshold anywhere that changes a candidate’s state. Moving a candidate — and in particular recording a hire or a rejection — can only be done by a signed-in human member of the workspace, and it is attributed to that person in the workspace activity feed. That feed is not an audit log — see “How long we keep it”. The scoring service is technically incapable of writing to a candidate’s status; that permission does not exist for it.
- The model is explicitly prohibited from inferring or mentioning personality, character, emotion, mood, attitude, confidence, nervousness, culture fit, or any protected characteristic, and from reading meaning into pauses, hesitation, accent, grammar or vocabulary unless a criterion scores language proficiency. There is no emotion, sentiment or voice-analysis capability in the product, and the scoring step is given the text of the interview, not the audio.
On that basis we do not consider the product to make decisions producing legal or similarly significant effects within the meaning of Art. 22 GDPR. The employer remains responsible for the decision it takes, and for telling candidates that AI is used in its process.
10
Security
We protect personal data through:
- Access controls that keep each workspace’s data separate.
- Private audio storage and time-limited playback access.
- Encryption and hashing for sensitive identifiers and access codes.
- Audio processing that does not write audio to the relay server’s disk or include interview content in its logs.
- Restricted, logged staff access to customer data, with access logs retained for 24 months.
- Deletion records and checks confirming that stored files have been removed.
11
Your rights
If you hold an account with us, you have the rights given by the GDPR: access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent where processing rests on it. Write to support@getkira.com and we will respond within one month.
If you are a candidate, contact the company that invited you to exercise your privacy rights. You can also email us, and we will forward your request to that company and help carry it out on their instructions. See our Candidate privacy notice.
You can complain to a data protection authority, including the Spanish Data Protection Agency (AEPD), or the authority where you live or work.
12
Changes and contact
We will post material changes to this policy here and, where the change affects how customer data is handled, notify workspace owners by email.
Kira-AI is operated by Volodymyr Terekhov, Calle de Jesús i Maria 8/7, 46008 Valencia, Spain. Contact: support@getkira.com.