OleeHire
Log inStart free
Privacy

Privacy policy

Last updated 12 August 2026
OleeHire handles two kinds of people: recruiters who run hiring, and candidates who apply. This policy explains what we collect from each, why we hold it, how long we keep it, and how to get it back or have it deleted. It is written to be read, not to be survived.
Section 1

Who we are

OleeHire is an AI hiring platform operated by Oleon (Private) Limited at hire.oleon.io. In this policy "we" and "us" mean Oleon (Private) Limited, and "you" means whoever is reading it, whether you are a recruiter using the platform or a candidate applying through it.

For anything about this policy, write to privacy@oleon.io and we will answer within 30 days.

Section 2

Two different relationships

Who controls your data depends on how you reached us. The distinction matters, because it decides who you ask when you want a copy or a deletion.

  • Recruiters and employers. We are the controller of your account data: your name, email, the organisation you belong to, your billing details and how you use the product.
  • Candidates. The employer that published the apply link is the controller of your application. We are their processor, acting on their instructions. We only handle your CV, interview and scores to run the hiring process for them.
Candidates: if the employer will not answer a request about your application, contact us at privacy@oleon.io and we will pass it on and help them action it.
Section 3

What we collect

We collect only what the hiring process needs, plus basic analytics about how the site is used. There is no advertising network here, nothing is sold on, and no profile is built for any purpose other than the role you applied to or the account you run.

From recruiters
  • Account details: name, work email, role in the organisation, and the password hash or Google account identifier used to sign in.
  • Organisation details: company name, team members you invite, plan and billing information.
  • Content you create: job descriptions, screening criteria, interview questions, notes, messages to candidates.
  • Usage and diagnostic data: pages visited inside the app, actions taken, IP address, browser and device type, error logs.
From candidates
  • Application data: your CV or resume file and everything inside it, plus any answers you give on the apply form.
  • Contact details: name, email address, phone number if you provide one.
  • Interview data: audio of your answers, the transcript generated from that audio, and timing information for the session.
  • Assessment data: scores, rankings, evidence citations and the written reasoning the AI produced against the employer's criteria.
  • Technical data: IP address, browser and device type, and the Google account identifier if the employer requires a Google sign-in to reach the interview.
Blind screening is on by default. Where the employer keeps it on, names, photos and demographic signals such as age, gender, nationality and address are stripped before anything is scored, and photos on a CV are never passed to the model.
Section 4

How we use it

  • To run the hiring process: collect applications, score CVs against the employer's criteria, conduct voice interviews, and produce the ranked report.
  • To operate accounts: authentication, permissions, billing, support, and service notices about outages or changes.
  • To keep the platform safe: rate limiting, abuse and fraud detection, and the insert-only audit log that records every state change on an application.
  • To improve the product: aggregated and de-identified usage statistics that cannot be traced back to a person.
  • To meet legal obligations: tax records, and equal opportunity or anti-discrimination records where an employer is required to keep them.
We do not sell personal data, and we do not use candidate CVs, recordings, transcripts or scores to train our own models or any third-party foundation model. Our AI provider processes this content to return a result and does not use it to train its models.
Section 5

AI processing and automated decisions

OleeHire uses Google Vertex AI to read CVs, generate interview questions, transcribe and grade answers, and write the reasoning behind each score. This is a substantial use of automated processing and we want you to understand its limits.

  • A human always decides. The AI produces a recommendation and a score. Selecting or rejecting a candidate is an action taken by a named person in the employer's team, recorded against that person in the audit log, never against the model.
  • Every score cites evidence. Scores reference the line in the CV or the moment in the interview that produced them, so a decision can be reviewed and challenged.
  • AI can be wrong. Models misread documents, mishear audio and miss context. Treat output as a first pass, not a verdict.
  • You can ask for a review. Candidates may request human review of any assessment, contest the result, and give their point of view. Ask the employer first, or write to privacy@oleon.io.
Section 7

Who we share it with

We share personal data with the employer running the role, and with the service providers below who process it on our instructions under contract. We do not sell it and we do not share it for advertising.

ProviderWhat it doesWhere
SupabasePostgres database, authentication, file storage for CVs and recordingsEU
Google Cloud, Vertex AICV screening, interview questions, transcription and grading, speechEU / US
VercelApplication hosting and edge deliveryGlobal
ResendTransactional email such as invites and remindersEU / US
Google Sign-InOptional account sign-in for recruiters and candidatesGlobal
Google AnalyticsCounts visits and page views so we can see what people useGlobal

We may also disclose data where the law requires it, to enforce our terms, or as part of a merger or acquisition, in which case we will tell you before your data moves to a new controller.

Section 8

International transfers

Data is stored in the region an organisation selects, EU by default. Some providers process data outside that region. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with encryption in transit and at rest.

Section 9

How long we keep it

Employers set retention windows for their own organisation, within the limits below. When a window ends, the record is deleted automatically rather than archived.

DataRuleDefault
CVs and applicationsDeleted automatically at the end of the period12 months
Interview recordingsAudio and transcript, deleted together6 months
Talent pool recordsKept only with the candidate agreeing24 months
Audit eventsCannot be shortened below the legal minimum7 years
Recruiter accountsDeleted 30 days after the account is closed30 days

Backups roll off on their own schedule and are fully replaced within 35 days of a deletion.

Section 10

How we protect it

  • Row Level Security in Postgres denies access by default. Every table has a policy, so one organisation can never read another's data.
  • CVs and recordings live in private storage buckets and are served only through short-lived signed URLs.
  • Candidates never receive an account password. Access to a status page or an interview uses an opaque, single-purpose, expiring token.
  • Service credentials for the database and the AI provider exist only in server-side code and are never sent to a browser.
  • Data is encrypted in transit with TLS and at rest by our infrastructure providers.
  • Every state change on an application is appended to an insert-only audit log.
Section 11

Your rights

Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent, and complain to your data protection authority.

  • Recruiters: most of this is self-service in Settings. Anything else, write to privacy@oleon.io.
  • Candidates: ask the employer that published the role first, since they control your application. Copy us at privacy@oleon.io and we will make sure the request is actioned.

We do not charge for these requests and we will not treat you differently for making one.

Section 12

Cookies

We use a small number of cookies. We do not run advertising cookies and we do not sell any of this to an ad network.

  • Session cookies that keep you signed in and hold your Supabase auth session. Necessary.
  • Security cookies that protect forms against cross-site request forgery. Necessary.
  • Preference cookies that remember settings such as the last pipeline view you opened. Necessary.
  • Google Analytics cookies, _ga and similar, that count visits and show us which pages people use. Analytics, not advertising. They record a random identifier, the pages you view and rough location from a truncated IP address.

In the EEA, the UK and Switzerland the analytics cookies are switched off until you accept them on the banner, and declining is a single click. Elsewhere they are on by default and you can turn them off with your browser, the Global Privacy Control signal, or the Google Analytics opt-out add-on. Blocking them does not change how the platform behaves.

Section 13

Children

OleeHire is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has submitted data through the platform, write to privacy@oleon.io and we will delete it.

Section 14

Changes to this policy

We update this policy when the product or the law changes. The date at the top always reflects the current version. For material changes we will email account holders and show a notice in the app at least 14 days before the change takes effect.

Section 15

Contact us

Privacy questions, data requests and complaints: privacy@oleon.io.

Postal address: Oleon (Private) Limited, hire.oleon.io. If you are in the EEA or the UK and are unhappy with our response, you may complain to your local supervisory authority.

See also our terms of service.