Back to Lucid Hire

Privacy Policy

Last updated 3 September 2026

Lucid Hire screens CVs for the employers who post jobs on it. That means we handle two kinds of people's data: the recruiters who hold an account, and the applicants who send a CV to a job posting. This page says exactly what we take, where it goes, and how to get it back or removed.

Who is responsible for your data

For a recruiter’s own account data, Lucid Hire is the controller. For applicant data, the employer that published the job is the controller and decides why the CV is being screened; Lucid Hire processes it on their instructions. If you applied for a role and want your data removed, you can write to either the employer or to us at the address below and we will act on it.

What we collect from recruiters

  • Your name and email address, held by our authentication provider so you can sign in.
  • Your organisation name, chosen during onboarding.
  • The job postings you write, including any cover image you upload and any text our AI rewrote for you.
  • Billing status: your plan tier and the subscription identifiers returned by our payment provider. We never see or store your card details.

What we collect from applicants

When you apply to a job posting hosted here, we receive and store:

  • The email address you type into the application form.
  • The CV PDF you upload, kept as a file in our cloud storage.
  • The text extracted from that PDF, and a structured profile derived from it by an AI model — typically your name, phone number, links, work experience, education, certifications and skills.
  • Numerical embeddings of that profile, plus a match score, a rank and a short written rationale explaining the score to the employer.

The employer who published the job can see all of the above, and can download your CV. Applications are only accepted for postings the employer has actively published.

Automated processing you should know about

Your CV is read by a large language model, which extracts a profile and scores it against the job description. That score orders the list the employer sees. It is a ranking aid, not a decision: a human at the employer decides who to contact. If you would like the reasoning behind your score, ask us and we will provide it.

Who else processes it

We do not sell data and we do not share it for advertising. We use these processors to run the service:

  • Clerk — recruiter authentication and session management.
  • Neon — the PostgreSQL database holding jobs, candidates and extracted profiles.
  • Google Cloud Storage — storage for uploaded CV PDFs and job cover images.
  • Google Gemini — the AI models that extract profiles, generate embeddings, score candidates and rewrite job descriptions.
  • Trigger.dev — runs the CV processing pipeline in the background.
  • Cloudflare Turnstile — checks that an application came from a person and not a bot. It receives your IP address for that check.
  • Polar — subscription billing for paying customers. Applicant data never reaches it.

How long we keep it

Applications are kept for as long as the employer keeps the job and the candidate record. When a recruiter deletes a candidate or a job, the record and everything derived from it — the extracted profile, the embeddings, the score and the rationale — are removed from the database immediately.

The uploaded PDF itself is held in our cloud storage and is not currently removed by that same action. If you want the file itself erased, write to us at the address below and we will delete it and confirm.

Recruiter accounts and their organisation data are kept until you ask us to close the account.

Your rights

You can ask for a copy of the data we hold about you, ask us to correct it, ask us to delete it, or object to the automated scoring described above. Email [email protected] and say which job you applied to and which email address you used, so we can find your record. We answer within 30 days.

Cookies

We set the cookies needed to keep you signed in and to remember your light or dark theme preference. Cloudflare Turnstile sets its own cookie when it runs the bot check on the application form. We run no advertising or analytics trackers.

Changes and contact

If we change what we collect or who processes it, we will update the date at the top of this page. Questions about anything here go to [email protected].