Privacy
How SkipRecruiter collects, uses and protects personal data.
Effective date: 16 September 2026
This Privacy Policy explains how SkipRecruiter ("we", "us") processes personal data when you use our service at skiprecruiter.co. If you have questions or want to exercise a right, contact us at privacy@skiprecruiter.co.
1. Who is responsible
SkipRecruiter operates the service. You are the controller of the candidate profile and campaign content you upload; we act as your processor for the data we handle on your instructions, and as a controller for account and billing data.
2. Data we process
- Account data: name, email address, authentication identity (Google or GitHub), plan and billing identifiers.
- Profile data: the CVs you upload, the structured profile we extract, and generated resumes and pitch emails.
- Mailbox data: the sending mailbox you connect. Credentials are encrypted at rest; we read replies from the inbox only when you enable reply tracking.
- Recipient data: business contact details found in public sources (name, title, company, professional profile, work email) and verification results.
- Campaign data: sends, deliveries, opens, replies, bounces and complaints we receive from your mailbox or email provider.
- Usage data: minimal product telemetry (credits used, AI cost, errors).
3. Why we process it
- To provide the service (contract performance): parsing your CV, finding and verifying contacts, drafting and sending emails on your behalf, tracking replies.
- To keep the service reliable and safe (legitimate interests): fraud prevention, deliverability protection, abuse prevention, product analytics.
- To comply with law, and with your consent where required.
Cold outreach is sent by you, from your mailbox. You are responsible for having a lawful basis to contact each recipient and for honoring opt-outs; we maintain suppression lists and stop sequences when someone replies or unsubscribes.
4. Sub-processors
We share data with service providers under written agreements, including: hosting (Vercel), database (Neon), cache and rate limiting (Upstash), background jobs (Inngest), transactional email (Resend), AI model providers, search data (Brave Search), and object storage (Cloudflare R2). Data may be processed outside the EEA under standard contractual clauses or equivalent safeguards.
5. Retention
- CVs, profiles and campaign content: until you delete them or close your account.
- Reply and delivery metadata: kept while your account is active for analytics, then deleted.
- Email verification results: cached up to 180 days before re-checking.
- Billing records: kept as long as legally required.
Deleting your account from Settings removes your CVs, campaigns, leads and mailbox credentials from active systems; backups are purged on a rolling schedule.
6. Your rights
You can access, correct, export or delete your data from the dashboard, and you can object to processing based on legitimate interests. Email privacy@skiprecruiter.co for any request. You also have the right to complain to your supervisory authority. If a recipient asks us to stop contacting them, we add them to a global suppression list and will not email them again for any customer.
7. Cookies and security
We use a single session cookie for authentication; we do not use advertising cookies. Credentials are encrypted with keys managed separately from the database, transport is encrypted in transit, and tenant data is isolated per account.
8. Changes
We may update this policy; material changes will be announced in the product or by email before they take effect.