Privacy Policy

Last updated: September 24, 2026

AutoTalent (“AutoTalent”, “we”, “us”) runs the AutoTalent recruiting service at autotalent.ai. This policy explains what personal data we handle about our customers and visitors to our site, and how. If AutoTalent found or contacted you as a candidate, the Candidate privacy notice is written for you.

1. Information we collect

Account information

When you sign up, our sign-in provider (Clerk) collects your name, email address and organization. We keep your user and organization IDs, your role in the organization and your settings.

What you put into the service

Requisitions and job descriptions, hiring-manager notes, outreach settings, emails you write or approve, notes and tags on candidates, messages exchanged with candidates, and your conversations with the talent assistant.

Connected email accounts

If you connect Gmail or your own SMTP server to send outreach, we store the Google refresh token or SMTP password encrypted (AES-256-GCM). For Gmail we request only the gmail.send permission, so we can send mail but cannot read your inbox. Candidate replies come back to AutoTalent through a reply address on our domain; we store them with the candidate and forward a copy to you.

Billing and usage

Stripe processes payments. We keep your plan, subscription status, Stripe customer and subscription IDs and usage counts (candidates sourced, emails sent, requisitions created). We never see or store full card numbers.

API keys

API keys for the MCP server and CLI are shown to you once. We store only a keyed hash (HMAC-SHA256) and a short prefix so you can recognise them.

Technical data, cookies and tracking

Our hosting providers record request logs (such as IP address, browser and the page or API requested), and our application logs can include names and email addresses while we process a request. We use only the cookies our sign-in provider needs to keep you signed in, plus your browser’s local storage for interface preferences (for example, a dismissed tip). We don’t use analytics or advertising trackers, and outreach emails are sent with open and click tracking turned off.

2. Candidate data

To find candidates we process professional information about people who have not signed up to AutoTalent: public LinkedIn profiles (retrieved through Apify), public GitHub activity, work email addresses from Apollo.io and Hunter.io, the AI scores and summaries we generate, and any messages they exchange with you. The Candidate privacy notice sets out the sources, legal bases and the rights those people have.

Shared talent pool. AutoTalent keeps a platform-wide pool of public profile data. When your searches retrieve a full public profile, that profile’s public fields (name, headline, location, work history, education, skills and summary) are added to the pool, and other customers’ searches can match it. Your requisitions, notes, scores, email addresses you found, messages and pipeline decisions are never added to the pool or shown to other customers. For the pool, AutoTalent decides how the data is used and is responsible for it; for your own recruiting records you decide, and we process them on your behalf.

3. How we use information

  • Provide the service: search, screen and score candidates, draft and send outreach, route replies and run follow-ups
  • Keep your account secure and prevent abuse
  • Bill you and enforce plan limits
  • Support you and tell you about changes to the service
  • Fix problems and improve the service
  • Meet legal obligations, including honouring unsubscribe and data-rights requests

4. AI processing

We send candidate profiles, requisition details, email drafts and candidate replies to AI model providers to score candidates, write drafts and classify replies. Today those providers are OpenAI, TypeSafe and, for the talent assistant, OpenRouter (routing to DeepSeek models). The AI & automated decisions page explains what the models do, which steps happen without a person, and what that means under hiring laws.

5. How we share information

  • Service providers who host, store or process data for us, listed on the Subprocessors page.
  • Other customers, only for public profile data in the shared talent pool (see section 2).
  • Hiring managers you share a review link with: the link shows the candidates you chose to share.
  • Legal and safety: when the law requires it, or to protect rights, property or safety.
  • Business transfers: if AutoTalent is merged, acquired or sells assets, data can move to the new owner under this policy.

We don’t sell personal information for money, and we don’t share it for cross-context behavioural advertising.

6. Security

Data travels over HTTPS. Stored email credentials and third-party API keys are encrypted with AES-256-GCM, and our API keys are stored only as hashes. Every signed-in request is tied to your organization. The Security page has the details, including what we don’t have yet.

7. Retention and deletion

We keep account and organization data while your account is active. We don’t yet delete data automatically on a schedule. To have your organization’s data deleted, email support@autotalent.ai, and we’ll delete it unless the law requires us to keep it (for example, billing records). We may keep the minimum needed to honour opt-outs, such as a suppressed email address.

8. International transfers

AutoTalent is run from the United States, and our providers process data in the United States and in other countries. When data about people in the EU, UK or Switzerland is transferred, we rely on the safeguards in our providers’ data processing terms, such as Standard Contractual Clauses.

9. Your rights

Depending on where you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy
  • correct it
  • delete it
  • restrict or object to how we use it
  • give it to you in a portable format
  • not sell or share it (we don’t)

Email support@autotalent.ai. We’ll check it’s you before acting, and we reply within the time the law sets (for example, one month under the GDPR and 45 days under California law). You can use an authorized agent. We won’t treat you differently for using these rights. In the EU or UK you can also complain to your data protection authority.

10. Children

AutoTalent is a business tool. It is not meant for, and we don’t knowingly collect data from, anyone under 16.

11. Changes

When we change this policy we update the date at the top. We’ll tell customers about material changes by email or in the app before they take effect.

12. Contact

Questions or requests: support@autotalent.ai.