Start here: which part of this applies to you?
We run more than one service, and the people whose data we handle are in three different positions. Find yourself in this table and read the sections named.
| You are | You should read |
|---|---|
| An employer using the hiring platform | Sections 1, 2, 5, 6, 7, 8, 9, 10 |
| A candidate invited to an AI interview by an employer | Sections 1, 3, 5, 6, 7, 8, 9, 10 — and the separate Candidate Privacy Notice, which is shorter |
| A job seeker using JobsChat.ai for your own job search | Sections 1, 4, 5, 6, 7, 8, 9, 10 |
1. Who we are
JobsChat.ai is operated by JobsChat LLC, registered in Delaware, United States, at 2604 Whittier Pl, Wilmington, DE 19808, United States.
For questions about this policy, or to make a request about your data, write to privacy@jobschat.ai.
Who is responsible for what. This matters and we want to be exact about it.
- For employers and job seekers, we are the controller of your data. We decide why and how it is processed.
- For candidates interviewed on the employer platform, the employer who invited you is the controller. They decided to process your application. We run the interview and the assessment on their instructions. We are the processor.
- Even so, if you are a candidate you may contact us directly at privacy@jobschat.ai. We will act on your request or pass it to the employer, and we will tell you which we did. You do not have to go through the employer to reach us.
2. Employers — what we collect about you
| What | Where it comes from |
|---|---|
| Your name, work email address, company name and company description | You, at signup or in settings. If you create your account with Google, Microsoft or LinkedIn, or first sign in with one of them before you have verified an email signup, your name and email address come from that provider (see section 6, row 7). |
| Your password, stored only as a cryptographic hash — never the password itself | You |
| Your company logo, if you upload one | You |
| Your sign-in provider or providers, their identifier for you, and when you last signed in with each, if you sign in with Google, Microsoft or LinkedIn | That provider |
| Your job posts — title, location, salary range, full description | You |
| Your conversations with the platform assistant, including everything you type and everything it replies | You, and the platform |
| When your account was created, when you last signed in, and your interview usage | The platform |
Colleagues on an account. When an account Admin invites a colleague we hold the colleague's email address, the Admin's name and email as the inviter, the date and time of the invitation and whether it was accepted, withdrawn or expired. When the colleague joins we hold their name, email address, role (Admin or Member), the date they joined and, if they later leave, the date they were removed and by whom. Every user of an account sees the same jobs, candidates and interviews, including the candidates' CVs and interview recordings, and each item shows which user added it.
While someone is a member, only they can see their own conversations with the assistant. If the Admin removes a user, the Admin can read that user's conversations for thirty days after the removal, after which they are deleted. The removed user's email address is kept for the same thirty days so that a sign-in attempt can be answered, and their name stays on the records they added.
We do not store an IP address against an employer account.
3. Candidates — what we collect about you
You do not have an account with us, and you never signed up. An employer uploaded your CV and invited you. Here is everything we hold.
3.1 From your CV, which the employer uploaded
Your name, email address, phone number, location and headline; your years of experience, your last role and last employer; your skills, languages, education and links; the full text of your CV, up to 60,000 characters; and the original CV file itself.
3.2 What we work out from your CV, rather than read from it
We want to be explicit that some of what we hold about you was generated by a model, not supplied by anyone:
- a written summary of your background;
- a seniority band, being the level at which our model reads your experience;
- whether your track reads as management or individual-contributor;
- a fit score from 0 to 100 against a particular job, and written reasoning for it;
- a mathematical representation of your CV, used for searching.
3.3 If you take an AI interview
- The recording. Video from your camera and audio from your microphone, recorded in your browser and sent to the employer's storage.
- Your voice, streamed live during the interview so that it can be turned into text.
- A transcript of the interview — everything you said, everything the interviewer said, with timings.
- An assessment written by AI after the interview: a score from 0 to 100, findings against each competency, quotes from what you said as evidence, strengths, gaps, and a recommendation of proceed, proceed with reservations, insufficient evidence, or do not proceed.
- A record of your consent — the wording you were shown, and the moment you agreed.
- Technical data when you open the interview link: your IP address, your browser type and version, and your device's basic characteristics.
- A technical log of the interview page — what the page did and when, such as when the interviewer finished speaking or the connection dropped, and your type of device — never your words, your voice or your image; we keep it for 30 days to find and fix problems.
3.4 What we do NOT do
We say this affirmatively, because these things are commonly done by hiring tools and we do not do them:
- We do not analyse your face. Your camera image is recorded in your browser and sent to the employer. It is never sent to the system that runs the interview, and no model ever looks at it.
- We do not analyse your voice as a biometric. Your audio is converted to text. We do not create a voiceprint, and we do not draw conclusions from your accent, your tone, your pitch or your speech rate.
- We do not score your appearance, your expression, your background or your eye contact.
- We do not infer your age, race, ethnicity, sex, religion, disability, health or any other protected characteristic, and our interviewer is instructed not to ask about them. The question set carries an explicit list of prohibitions.
The assessment is written from the words you said. Nothing else.
4. Job seekers — what we collect about you
Your contact details, if you choose to give them; the text of your chat sessions; documents you upload; documents we generate or modify for you; and usage logs including IP address, browser type, timestamps and pages visited.
If you take a practice interview, we store its transcript and its scorecard.
5. Why we process it, and on what basis
| Purpose | Basis |
|---|---|
| Providing the service you or your employer asked for | Performance of a contract |
| Running an interview and producing an assessment for an employer | The employer's lawful basis, on the employer's instructions. Your agreement is recorded at the start of the interview |
| Keeping the platform secure, and preventing abuse | Our legitimate interests |
| Meeting our legal obligations | Legal obligation |
| Sending you service emails — verification, password reset, interview invitations | Performance of a contract |
We do not sell personal data. We do not use your data, or a candidate's data, to train artificial-intelligence models. Our language model providers do not train on data sent through their business interfaces.
6. Who receives your data
We use external services to operate the platform. This section names every one of them and states exactly what reaches it. Nothing else leaves our systems.
| # | Service provider | What reaches it |
|---|---|---|
| 1 | OpenAI | The employer's conversation with the platform assistant, which can include candidate CV text, names and contact details; job post text; and text converted into search representations. Used for the assistant, the job-post writer, seniority reading and search. |
| 2 | Anthropic | The AI interviewer's intelligence. It receives the question set, the candidate's CV text, the job description and the live conversation, and generates every word the interviewer speaks. It also receives the full transcript afterwards and produces the assessment, the score and the recommendation. |
| 3 | Modal | The candidate's live microphone audio for the whole interview, processed on a GPU to convert speech to text and to generate the interviewer's speech and animated image. The candidate's camera video is not sent here. |
| 4 | Microsoft | A speech synthesis service, which receives the text the AI interviewer is about to say, in order to produce its voice. That text is generated by a model and routinely contains the candidate's first name and paraphrases of what the candidate has just said. |
| 5 | Amazon Web Services | Outbound email. Employer name and email address for verification and password reset; candidate name and email address, employer company name, role title and the interview link for an invitation. We email an invited colleague on the Admin's behalf, we email the Admin when a colleague joins, and we email an address that is invited while it already has its own JobsChat account to explain why it cannot join. |
| 6 | Analytics and advertising measurement — page views, IP address, browser, referrer and cookies — on the public marketing pages of jobschat.ai only. These are not loaded on the employer platform, not on the candidate invitation page, and not in the interview room. | |
| 7 | Google, Microsoft, LinkedIn | Where you choose to sign in with one of these, that provider confirms your identity to us and we receive your email address, name and their identifier for you. |
| 8 | Stripe | Payments and subscriptions. Your email address; your company name or your own name; the plan or bundle you buy, its quantity and price; and our internal reference number for your account, so that payments can be matched to it. The card details you enter on Stripe's own payment page go directly to Stripe and never reach our servers — we never see or store them. Stripe returns to us your subscription status, the plan you are on and your invoices. No candidate data is sent to Stripe. |
We may also disclose personal data where we are legally required to, where it is necessary to establish or defend a legal claim, or to a buyer as part of a sale or reorganisation of our business — in which case we will tell you before it happens.
7. Where your data is processed
Our own servers are located in Ashburn, Virginia, United States.
The providers listed in section 6 operate internationally. In particular, the GPU processing that handles a candidate's live interview audio is placed by the provider's scheduler and is not pinned to a region, so it may take place in any country where that provider operates.
If you are in a country whose law restricts transfers of personal data abroad, you should take this into account. We are able to discuss this with an employer who needs a specific arrangement.
8. How long we keep it
| What | How long |
|---|---|
| Interview video and audio recordings | 30 days, deleted automatically |
| Interview transcripts | 30 days, deleted automatically |
| A candidate's stored spoken answers | 30 days, deleted automatically |
| Interview page technical log | 30 days, deleted automatically |
| Raw scoring runs produced during evaluation | 30 days, deleted automatically |
| Job-seeker uploads and generated documents | 30 days, deleted automatically |
| Job-seeker practice interview transcripts and scorecards | 30 days, deleted automatically |
| Candidate CVs and the original CV files | Kept until the employer deletes them, or closes their account |
| Interview assessment reports | Kept until the employer deletes them, or closes their account |
| Employer chat history | Kept until the employer deletes it, or closes their account |
| Employer account records | While the account is open |
| Billing and subscription records, including invoices and payment history | Kept until the employer closes their account, and afterwards for as long as tax and accounting law requires |
| Web server request logs, which include IP addresses | 14 days |
| Application error log, which can record an employer's account number, the identifier a sign-in provider uses for them, the error message a provider returns when a sign-in fails, the Microsoft tenant identifier and the domain of the email address when a Microsoft sign-in is refused, the recipient's email address and the message subject when an email we send to an employer or a candidate cannot be delivered, and, rarely, a database error message that can quote an email address; each entry also records the IP address and the page address of the request that caused it | 14 days |
| Interview page access logs, which include candidate IP address and browser details | 14 days |
Two things we want to state plainly rather than leave you to discover.
The assessment outlives the recording. The assessment quotes the candidate word for word as its evidence. So when the recording, the transcript and the stored answers are deleted after 30 days, those quoted sentences remain inside the kept assessment.
CVs and assessments are kept, deliberately. They are the employer's hiring record. A candidate is often considered again for a later role, and an employer may need to show how a decision was reached. This is a choice we have made, and we would rather state it than let you assume a deletion that does not happen.
9. Your rights
Depending on where you are, you may have the right to ask for a copy of your data, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive it in a portable form, and to complain to your data protection authority.
How to exercise them:
- Employers and job seekers: write to privacy@jobschat.ai. Job seekers can also delete an uploaded document directly in the chat at any time.
- Candidates: the employer who invited you is the controller of your application, so a request usually has to be answered by them. You may still write to us at privacy@jobschat.ai. We will either act on your request or pass it to the employer, and we will tell you which we did, and who they are.
We will respond within 30 days.
We should be straight with candidates about one limitation. Because you do not have an account with us, there is no page you can sign in to in order to see, correct, download or delete your own data. The only route is to write to the employer or to us. We know this is a weaker position than having a self-service option, and we are telling you rather than implying otherwise.
10. Automated decision-making
This section matters, so it is written in full.
What is automated. Our AI conducts the entire interview — it decides which question to ask next, whether to follow up, and when the interview is over. Our AI then reads the transcript and writes a score, findings, quoted evidence and a recommendation. Our AI also produces the fit score that orders candidates in an employer's list.
What is not automated. No candidate is rejected, advanced, shortlisted or filtered out by our system. Our platform contains no mechanism that moves a candidate through a hiring pipeline. Only a person, acting in the employer's account, can do that. A recommendation of "do not proceed" is a sentence in a document, not an instruction the system carries out.
Our employers agree to this in their Terms. They are required to have a person review the assessment, and are prohibited from deciding solely on our output.
One honest qualification. The fit score that orders an employer's candidate list is generated by a language model, and re-running it on identical inputs on different days can produce materially different numbers. It is an ordering aid, not a measurement, and it should not be treated as one.
If you are a candidate and you want to contest an assessment, or have a person look at it again, write to the employer, or to us at privacy@jobschat.ai and we will put you in touch with them.
11. Security
Employer accounts are protected by password hashing and session-based authentication, and every request is checked against the account that owns the record. Interview recordings are stored outside the public web root and are served only to a signed-in employer who owns them. Interview links are single-use and expire.
No system is perfectly secure. If you believe you have found a vulnerability, write to security@jobschat.ai.
12. Cookies
On our public marketing pages, we use analytics and advertising cookies provided by Google. On the employer platform, we use only the cookie needed to keep you signed in. The candidate invitation page and the interview room set no analytics or advertising cookies at all.
13. Age
JobsChat.ai is not intended for anyone under 18. Do not use it, and do not invite a candidate to an interview, if they are under that age.
14. Changes
We may update this policy. Where a change materially affects you, we will give notice before it takes effect. We will change the "Last updated" date only when the text actually changes.
15. Contact
| For | Write to |
|---|---|
| Privacy and data requests | privacy@jobschat.ai |
| General support | support@jobschat.ai |
| Security reports | security@jobschat.ai |
JobsChat LLC, 2604 Whittier Pl, Wilmington, DE 19808, United States.
