← BurntCV Hire

Privacy & Data Promise

BurntCV Hire · effective 15 Aug 2026 · applies only to the Hire product

The short version

BurntCV Hire stores candidate data on behalf of your recruiting team, for one purpose: screening candidates for the role you created. A human makes every decision. Data is deleted on your retention schedule or on request — whichever comes first. Candidate data is never used to train models, never shared across accounts, and never touches the BurntCV roast product.

What we store, and for whom

When a recruiter adds a candidate, we store the résumé text, the structured extraction, the fit report, and any decision + note — all owned by the recruiter's account (the data fiduciary). BurntCV Hire is the processor. Every record is scoped to that account; cross-account access is impossible by construction.

Consent & lawful basis (DPDP)

Before screening, the recruiter attests a lawful basis per candidate: the candidate applied to this role, or the recruiter otherwise holds consent. The attestation — who, when, and on what basis — is recorded in the account's audit trail. Processing is limited to role screening; there is no secondary use.

Human-in-the-loop, always

The system never rejects anyone. It produces evidence-cited analysis; every Advance / Hold / Pass is recorded by a named, signed-in human. Knockout failures are flagged for review, never auto-actioned.

Retention & deletion

Candidate records carry a purge deadline (default 180 days, configurable 7–365) and are deleted automatically when it passes. Recruiters can hard-delete any candidate, any role, or the entire account's data at any time — deletions are immediate and logged. Candidates may exercise access or erasure rights via the recruiter, who can export or delete their record in one click.

The wall between Hire and the roast

The consumer roast product's promise is “we never store your résumé” — and it still holds. Hire runs on a separate data plane with its own storage namespace. No résumé, pipeline, or table is shared in either direction. A roasted résumé never becomes a Hire candidate; a Hire candidate is never roasted.

Security

Data is encrypted in transit (TLS) and at rest by our storage provider. Sessions are signed and scoped to one account. LLM calls for screening go to Anthropic's API under a zero-retention posture for inputs; candidate data is not used to train models. Rate limits cap abuse per account and per IP.

Contact & rights requests

For access, correction, or erasure requests — or anything about this policy — email support@burntcv.fun. We respond to data-subject requests within 30 days.