Skip to content
    Privacy

    Privacy Notice

    How TrueRole handles information across our public website, customer accounts, and the candidate data we process for hiring teams.

    Effective July 13, 2026 Last updated October 5, 2026

    Customers control candidate data

    Hiring organizations choose what information enters TrueRole and why it is processed.

    AI-assisted analysis, human decisions

    TrueRole organizes analysis and evidence; the customer’s hiring team decides what moves forward.

    No sale of personal information

    We do not sell personal information or use candidate data for cross-context behavioral advertising.

    01

    Scope and our role

    This Privacy Notice explains how TrueRole collects, uses, discloses, and protects personal information through truerole.ai, access and demo requests, customer accounts, and the TrueRole candidate-analysis service (together, the “Service”). It does not cover a customer’s own recruiting site, applicant notice, or employment practices.

    For website visitors, demo contacts, account users, and our own business contacts, TrueRole generally determines why and how personal information is processed and acts as a controller or business under applicable privacy law. For candidate and hiring information submitted or connected by a customer, the customer determines the hiring purpose and generally acts as the controller or business; TrueRole processes that information for the customer as a processor or service provider.

    If you applied to a company that uses TrueRole, that company controls your application and hiring process. Contact the company first to exercise rights related to your application; we will support its response as required.
    02

    Information we process

    The information we process depends on how you interact with TrueRole and which features a customer enables. Customers decide what candidate materials and role criteria to submit, connect, or ask us to analyze.

    Business and account information

    Examples
    Name, work email, company, role, workspace membership, permissions, and account settings.
    Why we use it
    Create and secure accounts, administer workspaces, provide support, and communicate about the service.

    Candidate and hiring information

    Examples
    Resumes, contact details, employment and education history, skills, application materials, role criteria, reviewer input, and decision records.
    Why we use it
    Provide candidate analysis, evidence review, interview preparation, collaboration, and hiring-workflow records at the customer’s direction.

    Connected materials and integrations

    Examples
    Portfolio links and content, integration identifiers, imported records, and synchronization metadata.
    Why we use it
    Retrieve or connect materials and systems the customer chooses to use with TrueRole.

    Usage, device, and security information

    Examples
    IP address, browser and device details, session identifiers, timestamps, feature interactions, logs, and audit events.
    Why we use it
    Operate, secure, troubleshoot, and improve the service and investigate misuse.

    Billing and commercial information

    Examples
    Plan, usage, billing contact, subscription status, transaction identifiers, and demo-request details.
    Why we use it
    Provide demos, administer subscriptions, calculate usage, process payments, and maintain business records.

    Sources of information

    • Directly from you, such as when you request a demo, create an account, contact support, or provide reviewer input.
    • From our customers and their authorized users, including candidate materials, role information, team feedback, and records imported from connected hiring systems.
    • From candidate-provided or customer-directed links and materials, when a customer asks the Service to retrieve or review them.
    • Automatically from browsers, devices, and use of the Service, including session, log, and security information.
    • From service providers and business partners, such as payment, authentication, email, infrastructure, and integration providers.

    Please do not submit sensitive personal information—such as medical or genetic information, government identifiers, financial account details, or protected-class information—unless it is necessary for a lawful hiring process and you are authorized to do so. TrueRole is not designed to use protected characteristics as role criteria.

    03

    How we use information

    We use personal information for the following business and service purposes:

    • Provide, operate, maintain, and secure the Service.
    • Create accounts, administer workspaces, manage permissions, and authenticate users.
    • Analyze candidate materials against customer-defined, job-related criteria and present evidence, open questions, summaries, and workflow records for human review.
    • Process subscriptions, measure candidate-evaluation usage, and maintain billing and transaction records.
    • Respond to access and demo requests, sales inquiries, support questions, security reports, and other communications.
    • Debug, monitor, measure, and improve performance, reliability, usability, and safety.
    • Prevent fraud, abuse, unauthorized access, and violations of our Terms.
    • Comply with law, enforce agreements, and establish, exercise, or defend legal claims.

    Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, consent where requested, and—when processing customer content—the customer’s documented instructions and legal basis.

    04

    AI-assisted analysis and human decisions

    TrueRole uses artificial intelligence and deterministic software to compare candidate materials with role criteria, identify supporting evidence and missing information, generate summaries or interview questions, and help authorized reviewers organize their assessment. Outputs may include inferences about role alignment based on information the customer supplies or directs us to process.

    TrueRole provides analysis for review. It does not make the hiring decision. The customer’s hiring team decides what moves forward and is responsible for meaningful human review.

    AI-assisted outputs can be incomplete, inaccurate, or affected by the materials and criteria provided. Customers must review relevant source evidence, consider candidate-provided context, maintain appropriate oversight, provide required notices and accommodations, and comply with laws governing employment selection tools. TrueRole does not use customer content to train a shared or general-purpose model for other customers unless the customer expressly agrees in writing.

    05

    How we disclose information

    We may disclose personal information only as reasonably necessary for the purposes described in this Notice:

    • Within a customer workspace. To authorized users, administrators, reviewers, and other people the customer invites or directs us to support.
    • Service providers. To vendors that provide cloud hosting, storage, databases, AI model processing, security, support, transactional email, and payment services under contractual restrictions.
    • Customer-directed integrations. To applicant tracking systems or other services a customer chooses to connect.
    • Legal and safety reasons. When reasonably necessary to comply with law, protect rights or safety, investigate misuse, or respond to valid legal process.
    • Business transactions. In connection with financing, due diligence, reorganization, acquisition, sale, or transfer of all or part of the business, subject to appropriate safeguards.
    • With direction or consent. When the customer or individual directs us to disclose information or otherwise consents.

    TrueRole does not sell personal information or share it for cross-context behavioral advertising as those terms are defined by California law. We do not use candidate information to advertise to candidates or unrelated third parties.

    06

    Cookies and similar technologies

    TrueRole uses cookies and similar storage that are necessary to operate the Service—for example, to maintain a secure signed-in session, remember workspace or interface settings, and protect against misuse. We may also collect standard server logs and device information for security and reliability.

    Within authenticated workspaces, TrueRole records limited first-party product events—such as starting a session, creating a role, adding candidates, completing an evaluation, viewing a scorecard, or submitting feedback—to understand activation and feature adoption. These events use enumerated event and screen names rather than page contents and are retained for up to 14 months. Candidate names, role titles, emails, form text, and raw URLs are not included in this product-event record.

    Visits through our business-card QR link are counted in anonymous daily totals by campaign and destination. These totals contain no visitor identifiers, IP addresses, referrers, or device details and do not use cookies. They count requests, not unique people. With analytics consent, campaign attribution is also retained for the browser tab’s session to measure subsequent site visits, access and demo requests, and sales inquiries.

    On public marketing pages, TrueRole uses Google Analytics to understand page visits, general device and browser characteristics, approximate location, and referring websites. Where enabled for visitors identified as being in the United States, this basic measurement uses analytics cookies without requiring an initial opt-in. You can turn it off at any time through the Cookie choices link. For visitors outside the United States, or when location cannot be established, Google Analytics stays off until you explicitly allow it through Cookie choices. Existing declines and supported Global Privacy Control signals keep Google Analytics off. Country is estimated locally from the network address to select the consent settings; this lookup does not store the address or send it to an external geolocation service.

    Detailed measurement—including campaign attribution, interactions with marketing content, and demo-request conversions—requires you to select “Allow detailed analytics” or “Allow analytics.” For U.S. visitors offered automatic basic measurement, “Basic traffic only” leaves these detailed events disabled. These choices can be changed through the Cookie choices link. Basic Google Analytics is not anonymous: it uses browser identifiers for reports about users and sessions. We do not send demo-form contents, account identifiers, candidate information, workspace activity, or authenticated product activity to Google Analytics. Page addresses omit arbitrary query parameters and fragments, and referrers are limited to their website origin.

    TrueRole does not use third-party advertising cookies or cross-site tracking for targeted advertising. Google advertising features and Google Signals are disabled for this measurement, and user- and event-level analytics data is configured for a 14-month retention period. Browser controls can block or delete cookies, but disabling necessary cookies may prevent account features from working.

    07

    Retention and deletion

    We retain personal information only as long as reasonably necessary for the purposes described here, including to provide the Service, follow customer instructions, meet contractual commitments, maintain security and audit records, comply with law, and resolve disputes. Retention depends on the type of information, the customer’s configuration and instructions, the status of the account, legal requirements, and operational needs.

    Organization deletion

    Organization owners can request deletion in Workspace settings by confirming the workspace address. If a paid subscription is active, first schedule cancellation in Plan & Billing. The 30-day recovery window starts after the paid term ends, or when the request is made if there is no active subscription. Owners can withdraw their request before removal begins; withdrawal does not restart a canceled subscription or extend an access program’s retention terms.

    Organization deletion removes workspace roles, candidates, evaluations, and uploaded files through our deletion process. Personal login accounts and memberships in other organizations remain. Removal from active systems is asynchronous; running work, payment reconciliation, or cleanup failures may require additional processing. Contact support before confirming deletion if you need an export.

    You can delete your personal login through Account settings, including when you no longer belong to a workspace. Confirm your email address and current password. Sole owners must transfer ownership or finish deleting their workspace first. Account deletion removes your login, profile, and memberships; profile photos are cleaned up asynchronously. Workspace contributions remain with a “Deleted user” reference, and workspace subscriptions are not canceled by personal account deletion.

    Workspace closure and personal account deletion are separate from an individual’s broader privacy request. Contact support@truerole.ai for privacy requests; applicable rights and deadlines are assessed separately from the workspace recovery window. We retain only records covered by an applicable retention basis, including required accounting records and limited deletion-operation records. These limited records include the workspace identity, deletion dates and outcome, and authorization identifiers. Where we retain the deletion requester’s name and email for closure support, we remove those contact details within 90 days after completion or cancellation, or sooner if the requester deletes their account. Pending requests have a contact-retention deadline based on the scheduled removal date; expired contact details are not restored.

    When a customer deletes content or closes an account, we delete or de-identify covered information according to the applicable agreement and our operational deletion process, unless retention is required by law or reasonably necessary for security, fraud prevention, billing, or legal claims. Copies may remain in protected backups until they are overwritten through normal rotation. Customers should contact support before termination if they need an export.

    08

    Security

    We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, authenticated sessions, tenant-scoped permissions, audit records, and protections appropriate to the sensitivity of the information. We review safeguards as the Service evolves and require personnel and service providers to handle information only for authorized purposes.

    No transmission, storage, or processing system is completely secure. Customers are responsible for managing authorized users, using strong credentials, reviewing workspace permissions, and promptly notifying us of suspected unauthorized access at support@truerole.ai.

    09

    International processing

    TrueRole and its service providers may process information in countries other than the country where it was collected. Privacy laws in those countries may differ. Where required, we use appropriate contractual and organizational safeguards for cross-border transfers and support customers with transfer terms in the applicable data processing agreement.

    10

    Your privacy rights

    Depending on where you live and our role in the processing, you may have rights to request access, correction, deletion, restriction, portability, or an objection to certain processing; to withdraw consent; to opt out of certain sales, sharing, targeted advertising, or profiling; and to appeal a denied request. You may also have the right to complain to a privacy regulator.

    Account users and website contacts

    Email support@truerole.ai with “Privacy request” in the subject line. Describe your request and the email address or workspace involved. We may verify your identity and authority before acting. You may use an authorized agent where law permits, and we will not discriminate against you for exercising a privacy right.

    Candidates and applicants

    Submit requests to the employer or organization that received your application. Because that organization controls the hiring process and candidate record, it is usually best positioned to verify your identity, explain its legal basis, provide notices, correct source information, and decide whether information must be retained. If you contact us directly, we may refer the request to that customer and assist it as required.

    11

    Children

    The Service is designed for businesses and authorized hiring professionals, not for children to create accounts or use independently. We do not knowingly collect personal information directly from children under 16 through the public website. If a customer lawfully processes an application from a minor, the customer is responsible for appropriate notices, permissions, and employment-law compliance.

    12

    Changes and contact

    We may update this Notice to reflect changes in the Service, our practices, or applicable law. We will post the updated version here, change the “Last updated” date, and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.

    Questions, privacy requests, or security concerns can be sent to support@truerole.ai. Please do not email resumes, government identifiers, medical information, or other sensitive candidate materials.