Unreviewed draft. Not legal advice, and not binding on anyone.
This page was written from what the Kira-AI product actually does in code, so that a lawyer has an accurate starting point instead of a blank page. It has not been reviewed by a lawyer. Do not rely on it, do not sign anything on the strength of it, and expect the wording to change. Highlighted ▲ to supply markers are facts we could not confirm and have not invented.
For recruiters
Privacy policy
What Kira-AI collects, why, where it is stored, who else touches it, and what you can ask us to do about it. Written from the system as it is actually built, including the parts that are not finished.
- Status
- Unreviewed draft
- Drafted
- 9 August 2026
- Applies to
- getkira.com and the Kira-AI app
Contents
01
What this covers
This policy explains how Legal entity — VV to supply (“Kira-AI”, “we”) handles personal data in connection with the Kira-AI website, the recruiter application, and the voice interviews the product conducts.
There are two audiences and they are treated differently, so it is worth knowing which one you are:
- Recruiters and their colleagues — people who hold an account with us. For your account data we are the controller, and this policy is the notice you are owed.
- Candidates — people invited to an interview by a company that uses Kira-AI. For candidate data the employer is the controller and we act on their instructions. If you are a candidate, the notice written for you is at /legal/candidate-privacy, and it is shorter and plainer than this one.
02
Controller and processor
We are the controller for the data we need in order to run a business: your account and profile, your workspace and its settings, team membership and invitations, billing and subscription records, transactional email we send you, support correspondence, and the security and audit records described below.
We are a processor for everything that belongs to a hiring process: candidates, their interviews, recordings, transcripts, scorecards, and the notes recruiters write about them. The customer decides which roles to advertise, whom to invite, what to ask, how candidates are assessed and what happens next. We process that data only to provide the service, on the customer’s documented instructions.
The processor terms are set out separately in our data processing agreement at /legal/dpa.
03
What we collect about you (account data)
Kira-AI is built to hold as little as it can get away with. There are no profile photos, no phone numbers, no job titles, and no marketing profile. What exists is:
- Identity and sign-in — email address, display name, interface language, and the authentication records held by our database provider (password hash, sign-in sessions, and that provider’s own security log, which does record IP addresses).
- Workspace — company name, logo, brand colour, client names, and free-text “company knowledge” you enter to brief the interviewer.
- Team — who is a member, who owns the workspace, invitations you have sent (email address, a hashed invitation token, expiry) and when people joined or were removed.
- Connected AI apps — which app you connected, when you approved it, and the authorization records needed to keep the connection working.
- Billing — your subscription, plan and usage counts. Card details are handled by our payment provider and never reach our servers.
- Email we send you — recipient address, the message class and template, and the provider’s delivery id.
What we do not collect
We do not store your IP address in readable form. Requests are rate-limited using a keyed one-way hash of the IP address, which is discarded after 24 hours; the raw address never reaches the database. We do not record browser or device fingerprints, we do not derive your location, and there is no analytics or advertising technology anywhere in the product or on this website — see /legal/cookies.
Our hosting, storage and email providers keep their own infrastructure logs, which will contain IP addresses. Those are held under their terms, not ours.
04
What we process about candidates
The following is processed on behalf of the hiring company. It is listed here because a customer signing up needs to know exactly what the platform will hold on their applicants.
- Identity — name (optional), email address, and an internal reference number.
- Invitation and consent — the invitation record, a hashed access token and a hashed one-time verification code, plus the exact version, language and timestamp of the consent the candidate gave.
- The interview — start, activity and completion timestamps, the interview language, which planned questions were answered or skipped, and an encrypted reference to the AI provider’s session.
- Audio — the recording of the conversation, stored as two separate tracks (the candidate and the interviewer). Audio only. There is no video and the product never requests camera access.
- Transcript — the full text of what was said, turn by turn, with speaker labels and timings.
- Scorecard — a score from 1 to 5 per criterion with a written rationale, verbatim quotes from the transcript as evidence, must-have outcomes, short strength and gap bullets, and neutral factual flags such as notice period or work permit. Plus the model and prompt version used, so any scorecard can be traced to how it was produced.
- Human input — the recruiter’s own star rating, written notes and comments about the candidate, the pipeline stage, and a rejection reason if one is recorded.
- Candidate feedback — an optional star rating and free-text comment about the interview experience.
Kira-AI does not accept CV or document uploads, and there is nowhere in the system to store one. No phone number, postal address or date of birth is collected.
05
Why we process it, and on what basis
| What | Why | Basis (draft) |
|---|---|---|
| Account, workspace, team | To provide the service you signed up for | Performance of a contract — Art. 6(1)(b) |
| Billing and usage counts | To meter the subscription and issue invoices | Contract, and legal obligation for tax records — Art. 6(1)(b), 6(1)(c) |
| Transactional email | To send invitations, verification codes and account notices | Contract — Art. 6(1)(b) |
| Security, rate limiting, audit records | To keep accounts and candidate data from being abused or accessed without a trace | Legitimate interests — Art. 6(1)(f) |
| Candidate interviews and scorecards | To screen applicants for the hiring company | Determined by the hiring company as controller |
| Support access by our staff | To diagnose faults, on the customer’s instruction, with every access logged | Legitimate interests, and the DPA — Art. 6(1)(f) |
06
How long we keep it
Interview data has no automatic expiry. Recordings, transcripts and scorecards are kept until someone deletes them — keep-until-deleted, not delete-after-N-days. That is a deliberate product decision, and it means the customer, as controller, owns the retention decision and has to make it.
The retention rules that are actually implemented today:
| Data | Kept for |
|---|---|
| Recordings, transcripts, scorecards, candidate records, recruiter notes | Until deleted. No automatic expiry. |
| Records of what our staff accessed | 24 months |
| Proof-of-deletion ledger (see below) | 24 months |
| Delivered or failed transactional email records | 30 days |
| Invitations that were never linked to a candidate | 30 days |
| Rate-limit counters (hashed IP) | 24 hours |
| Contact details on unused prospect invitations | 90 days |
| Unmatched payment-provider webhook events | 30 days |
07
Who else processes the data
Kira-AI is built on a small number of named providers. This is the complete list of parties that receive personal data, and what each one receives.
| Provider | What it processes | Where |
|---|---|---|
| Google (Gemini API) | Live interview audio in both directions, live transcription, the interview plan, the transcript and criteria for scoring, and recruiter-entered role text for drafting | See “Where the data lives” below — this is the open item |
| Supabase | The database and authentication: candidate records, transcripts, scorecards, recruiter accounts and notes | EU — Frankfurt |
| Cloudflare (R2) | Interview audio files, workspace logos, and the deletion ledger | EU-jurisdiction storage, enforced at start-up |
| Fly.io | The voice relay and background workers. Audio passes through memory only and is never written to disk | EU — Amsterdam |
| Vercel | Hosting for the website, the recruiter app and the admin console — all web traffic passes through it | See “Where the data lives” below |
| Resend | Transactional email: recipient address and message content | Region — not pinned |
| Stripe | Subscriptions and payments. Receives billing contact details only, never candidate data | US, under standard contractual clauses |
There is no analytics, tracking, advertising or session-replay provider in the product or on this website, and no separate speech-to-text vendor: transcription is produced by the same model that conducts the interview.
08
Where the data lives, and international transfers
Data at rest is in the EU. The database is hosted in Frankfurt, audio is stored in EU-jurisdiction buckets — the service refuses to start if it is pointed at a non-EU storage endpoint — and the voice relay and background workers run in Amsterdam. There is no US replica and no US copy of the recordings.
Two hops are not covered by that statement, and both are disclosed here rather than glossed over.
The AI model provider
Interview audio, transcripts and scoring prompts are sent to Google’s Gemini API. The product is designed to call that model through a European endpoint, and the code refuses to run a production deployment on any other region. That European path is not yet in service: today the calls go to Google’s general API endpoint, which does not carry a regional commitment. In practice this means interview audio and transcripts may be processed outside the EU by Google.
Hosting regions
Our hosting provider is configured to run the application in Frankfurt, but its routing layer — a thin piece of code that refreshes a session cookie and redirects — runs in every region the provider operates. It handles requests in transit, stores nothing and logs no content.
Where personal data is transferred outside the EEA, transfers rely on the European Commission’s standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework. Transfer mechanism per provider — to confirm with counsel
09
Automated decision-making
Kira-AI does not make hiring decisions. This is not a positioning statement; it is how the system is built, and it was verified against the code before this page was written.
- The model produces evidence, not verdicts. It is instructed never to recommend hiring, rejecting, advancing or ranking anyone, and never to state an overall judgement. It returns per-criterion scores with written rationale and verbatim quotes, must-have outcomes, and short strength and gap bullets.
- The overall band shown on a scorecard is calculated by our own code as the arithmetic mean of those criterion scores, with each scored criterion counting equally. It is a triage label. It changes nothing about the candidate’s status.
- There is no automatic rejection, no automatic advancement, and no score threshold anywhere that changes a candidate’s state. Moving a candidate — and in particular recording a hire or a rejection — can only be done by a signed-in human member of the workspace, and it is attributed to that person in the workspace activity feed. That feed is not an audit log — see “How long we keep it”. The scoring service is technically incapable of writing to a candidate’s status; that permission does not exist for it.
- The model is explicitly prohibited from inferring or mentioning personality, character, emotion, mood, attitude, confidence, nervousness, culture fit, or any protected characteristic, and from reading meaning into pauses, hesitation, accent, grammar or vocabulary unless a criterion scores language proficiency. There is no emotion, sentiment or voice-analysis capability in the product, and the scoring step is given the text of the interview, not the audio.
On that basis we do not consider the product to make decisions producing legal or similarly significant effects within the meaning of Art. 22 GDPR. The employer remains responsible for the decision it takes, and for telling candidates that AI is used in its process.
10
Security
The measures in place today:
- Every table enforces row-level security, and the application connects through narrowly scoped database roles rather than one privileged account. A workspace cannot read another workspace’s rows.
- Audio is stored in private buckets with no public URLs. Playback is served through our own server using a sealed, encrypted, time-limited reference; signed storage URLs are capped at five minutes and staff playback grants expire in five minutes.
- Invitation tokens and verification codes are stored as hashes. The reference to the AI provider’s session and the candidate details inside queued emails are encrypted at rest.
- The voice relay keeps audio in memory only and never writes it to disk. Its logs are structurally incapable of carrying prompt or transcript text.
- Access to customer data by our own staff requires a platform-admin role and is written to a dedicated access log that is retained for 24 months.
- Deletion is proved rather than assumed: every erasure writes a signed ledger entry, and the process confirms that the stored objects are actually gone before it closes.
Certifications — none held; ISO 27001 / SOC 2 status to confirm We do not currently claim any third-party security certification, and no such claim should be made until one exists.
11
Your rights
If you hold an account with us, you have the rights given by the GDPR: access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent where processing rests on it. Write to Support email — VV to supply and we will respond within one month.
If you are a candidate, the company that invited you is the controller and your rights are exercised against them; we will pass on and act on their instruction. You can also contact us directly and we will route the request. See /legal/candidate-privacy.
You have the right to complain to a supervisory authority. Ours is Lead supervisory authority — depends on entity, VV to supply.
12
Changes and contact
We will post material changes to this policy here and, where the change affects how customer data is handled, notify workspace owners by email.
Legal entity — VV to supply
Registered address — VV to supply
Support email — VV to supply
Data protection officer — none appointed; confirm whether one is required