Privacy policy
Last updated: 26 July 2026 · For the live product at kandidhq.com
Kandid ("we") provides AI-assisted CV and application tools. This policy explains what personal data we process and why. We are the data controller for account and CV data you submit.
What we collect
- Account details (email, name, authentication identifiers).
- CV files and text, writing samples, voice profiles, job descriptions, applications, and related workspace content you create.
- Usage and billing metadata (plan, counters, Stripe customer IDs — payment card data is handled by Stripe, not stored by us).
- Technical logs needed to operate the service (including AI call telemetry without selling your CV content).
Why we process it
To provide the service you request (contract), to secure and improve the product (legitimate interests), and where required by law. CVs may contain sensitive personal data — we process them only to deliver the features you use.
Sub-processors
We use providers such as Supabase (database/auth/storage), OpenRouter and underlying model providers (AI generation), Stripe (payments), and our hosting provider (e.g. Vercel). We require appropriate data processing terms where applicable.
Your rights (UK GDPR)
You can access, correct, export, or delete your data from Settings, or email support@kandidhq.com. You may also complain to the ICO.
Retention
We keep your account data while your account is active. After deletion we remove or anonymise personal data from production systems within a reasonable period, subject to legal retention needs (e.g. billing).
This summary is not legal advice. We will refine it as the product and processor list mature.