Trust
What we hold, and what we don’t
Everything your data protection officer needs, on one page. Where the data sits, how long we keep it, and what we can’t prove yet.
We’d rather lose a deal than make a claim we can’t back.
- Audio only
- No proctoring
- Human decides
- Proof of erasure
Where your data lives
Recordings, transcripts and scorecards are stored in the EU. One hop isn’t, and it’s the last row.
| Layer | Provider | Region |
|---|---|---|
| Interview audio | Cloudflare R2 | EU — refuses to start otherwise |
| Database | Supabase | EU — Frankfurt |
| Interview servers | Fly.io | EU — Amsterdam |
| Website and app | Vercel | EU — Frankfurt |
| Email delivery | Resend | [region TBC] |
| Payments | Stripe | US — no candidate data |
| The AI model | Google Gemini | Not pinned to the EU yet |
Our host’s routing layer runs worldwide. It refreshes a login cookie, stores nothing and logs no content.
The model call is the one thing we can’t place in the EU today.
The EU endpoint isn’t in service yet, so we don’t claim it. Your recordings and transcripts stay in the EU either way.
What we keep, and for how long
Interview data has no expiry. It stays until someone asks us to delete it.
| Data | Kept for |
|---|---|
| Interview audio | Until you delete it |
| Transcripts and scorecards | Until you delete it |
| Candidate name and email | Until you delete it |
| Records of our staff access | 24 months |
| Proof-of-erasure records | 24 months |
| Sent email records | 30 days |
| Rate-limit counters | 24 hours |
We never delete on a timer. You own the retention decision, and it is a decision you have to make.
IP addresses are never stored readable. We hold a one-way hash for 24 hours, to stop abuse.
Erasure
Deletion you can prove
Ask us, and it goes: the records, the audio files, the scorecards, the notes.
We erase the records and the stored audio.
We verify the audio objects are gone before closing.
You get a signed record that it happened.
That record holds no name and no email. We keep it for 24 months.
Two honest limits, because this is the page for them.
Deletion is run by our team, not a button. We publish no turnaround, because none is enforced in software.
One part is self-serve: deleting a vacancy deletes every candidate under it. There is no undo.
What Kira never does
Several of these are features we cut. Deciding not to build something is also a position.
- Never rejects anyone. Every scorecard is read-only.
- No proctoring, no cheating detection, no browser lockdown.
- No emotion, mood, personality or culture-fit inference.
- No judging accents, grammar, pauses or filler words.
- Audio only. No video, and no camera access.
- No training on your data.
- No analytics and no tracking on this website.
That sixth one is a contract term, not a switch in our code. We say so because your DPO will ask.
The register
What we hold, and what we don’t. Nobody in this category publishes this table, which is the reason to publish it.
| Item | Status | Detail |
|---|---|---|
| Data processing agreement | Have | Published, drafted, in legal review |
| Sub-processor list | Have | Published inside the DPA |
| Candidate privacy notice | Have | Published, drafted, in legal review |
| Consent before recording | Have | Versioned and timestamped, in the product |
| Signed proof of erasure | Have | In the product |
| Log of our staff access | Have | In the product, kept 24 months |
| Tenant isolation | Have | Row-level, enforced per workspace |
| No automated rejection | Have | Enforced by database permissions |
| ISO 27001 | Don’t have | Not certified |
| SOC 2 Type II | Don’t have | Not certified |
| NYC bias audit | Don’t have | Local Law 144 — none held |
| AI Act conformity file | Don’t have | Annex III artefacts absent |
| Penetration test report | Don’t have | [pen test status TBC] |
| Named DPO | Don’t have | [DPO status TBC] |
| Self-serve data export | Don’t have | Requests assembled by hand |
| Published deletion SLA | Don’t have | None enforced in software |
| EU-pinned model endpoint | Don’t have | Being built, not in service |
“Drafted” means the document is written and published, with legal review unfinished. Each one says so at the top.
The EU picture
Recruitment AI is high-risk under Annex III of the EU AI Act. We don’t claim alignment with it.
In the product
- Kira never rejects. A person decides, always.
- Candidates are told it is AI, and consent first.
- Consent is versioned, timestamped and pinned.
- Every decision is logged against a named person.
- Scorecards quote the transcript, verified word for word.
Not in place
- Risk management documentation.
- Technical documentation and conformity assessment.
- A quality management system.
- Registration as a high-risk system.
Under GDPR you are the controller and we are your processor. A DPIA is likely required, and running it is yours.
The US picture
Three laws come up on every US call. Here is where we actually stand on each.
| Law | What it asks | Where we stand |
|---|---|---|
| NYC Local Law 144 | Annual independent bias audit, published, plus notice to candidates | We hold no bias audit and cannot supply one today. |
| Illinois AI Video Interview Act | Notice, consent, an explanation, and deletion on request | Written for video interviews. Kira records audio only. Have counsel confirm scope. |
| Colorado AI Act | Deployer notice and an impact assessment for high-risk employment AI | We supply the disclosures. We hold no impact assessment. |
These duties land on the employer, not on us. We give you what we have and name what we don’t.
Questions your DPO will ask
It is legal and regulated. Recruitment AI is high-risk under Annex III of the EU AI Act, and the duties fall on you as employer. Kira never rejects anyone, so no decision is automated. We hold no conformity file.
You are the controller and we are your processor. Recordings, transcripts and scorecards are stored in the EU. Our data processing agreement is published, with legal review unfinished. The model call is not pinned to the EU yet.
Recordings, transcripts and scorecards are stored in the EU: Cloudflare R2, Supabase in Frankfurt, Fly.io in Amsterdam, Vercel in Frankfurt. The model call is the one hop not in the EU. The retention table above gives every period.
No. Neither, and no bias audit, no penetration test report and no named DPO. The register above lists what we hold and what we do not. We would rather lose a deal than imply otherwise.
The documents
Six of them, all public. Each one is honest about what it cannot promise yet.
Something we didn’t answer?
A security questionnaire, a signed DPA, or a question your DPO has. Write to us.