Privacy Policy
In force from 10 September 2026. Policy version 2026-09-10.
This policy describes what Earli Hire collects, why, who else sees it, and what you can do about it. Every statement in it describes what the software actually does.
1. Who is responsible
- Controller: Earli Hire Switzerland
- Contact for data-protection requests: support@earlihire.com
2. What we collect, and why
2.1 Because you typed it or uploaded it
| Data | Where it comes from | Why |
|---|---|---|
| Email address | Sign-in | It is the account identifier and the only way we contact you |
| Name, headline, phone, city, country, links | Profile editor or a parsed CV | Appears on documents you generate; city feeds location matching |
| Employment history — employer, title, dates, achievements | Profile editor or a parsed CV | The basis of every match score and every generated document |
| Education, certifications, languages, skills | As above | As above |
| What you are looking for — desired roles, locations, work mode, contract type, minimum salary, availability, notice period, right-to-work status, preferred language | Profile preferences | Scoring how well a posting fits you |
| Uploaded CV files (PDF, DOCX, text) | CV import | Read once to populate your profile |
Right-to-work status deserves separate mention. It is optional, "prefer not to say" is an available answer, and it is used only to score how well a posting fits you. We treat it as sensitive: it is never sent outside our own systems, it is excluded from the material used to draft documents, and it is never shown to anyone but you.
2.2 Because the service derived it
These are personal data too, and they are included in any export you request:
- Match scores and their rationale — a score per posting, with the reasoning broken down by skills, role fit, seniority, location, language and salary.
- Your writing fingerprint — statistics derived from your own prose (sentence-length distribution, preferred verbs, register). Used so generated drafts sound like you rather than like a model. It contains no text, only measurements of it.
- Profile completeness score.
- Generated documents — cover letters and tailored CVs, with the record of which model wrote each and from which version of the prompt.
- What you did — saved jobs, applications, jobs you rejected and why.
2.3 Technical data
- Session records: a hashed session token, expiry, browser user-agent, and a salted hash of your IP address. The raw address is never stored.
- Consent records: what you agreed to, when, and under which policy version.
- Sign-in codes: never stored. What is stored is a keyed hash of the code, which cannot be reversed to recover it. Codes expire after 15 minutes, allow five attempts, and work once.
3. Cookies
We use as few as the service can work with, and nothing beyond the strictly necessary ones is set unless you say yes.
3.1 Strictly necessary
These are set without asking, because without them the service cannot do what you have asked it to. They carry no advertising identifier and are not shared.
| Cookie | What it is for | How long | Set by |
|---|---|---|---|
vitae_session |
Keeps you signed in. Contains a signed reference to your session, not your details. | 30 days, or until you sign out | Us |
earli_cookie_choice |
Remembers whether you accepted or declined analytics, so we do not ask again. | 12 months | Us |
The second one exists only because you made a choice; recording a refusal is how we honour it.
3.2 Analytics — only if you accept
If you accept, we load Microsoft Clarity, which shows us which parts of the
site people get stuck on. It sets its own cookies (_clck, _clsk and related)
and is described in more detail in §5.
If you decline, or simply never answer, none of it loads at all. We do not load it and then ask it to behave — the code that would fetch it is not run. No Clarity cookie is written and no data is sent.
Declining costs you nothing. Every feature works identically either way, and we do not ask again for twelve months.
3.3 Changing your mind
Your choice is at /cookies, reachable from the footer of every page, and changing it takes one click in either direction. You can also delete these cookies in your browser at any time; we will then ask once more.
3.4 What we do not do
- No advertising cookies, no ad networks, no remarketing, no conversion pixels. We do not advertise, and we have no advertising relationships.
- No cross-site tracking, no data brokers, no social media pixels, and no fingerprinting used to identify you across sites.
- We do not sell or share your personal information, in the ordinary sense or in the specific sense those words carry under US state privacy laws.
- No third-party cookie is set anywhere on this site without your consent.
Because we run no advertising and do no cross-context behavioural tracking, a Global Privacy Control or Do Not Track signal from your browser has nothing to switch off here. We nonetheless treat a GPC signal as a refusal of analytics.
4. Your permissions, and what each one does
Consent is asked for separately for each purpose and each can be withdrawn independently at any time from your profile. We record refusals as well as agreements.
| Permission | What it enables | If you decline |
|---|---|---|
| Process my profile data | Storing your profile and scoring jobs against it | No profile can exist; you can still browse and search |
| Use my profile to draft documents | Cover letters and tailored CVs; reading an uploaded CV | Everything else works; you write documents yourself |
| Email me job matches | Alerts above your chosen match threshold | Matches still appear in the app |
| Help improve the product | Analysis of generated content quality | No effect on the service. Off unless you switch it on |
Withdrawing a permission stops the processing it covered. It does not delete what you have already written — deletion is a separate request (§9), because silently destroying your employment history because you moved a toggle would be worse than leaving it dormant.
Our lawful bases. Running the core service — holding your profile, matching it against postings, keeping you signed in — is performed to deliver the service you asked for (Art. 6(1)(b) GDPR, and the corresponding basis under the Swiss FADP). Sending your material for AI drafting, emailing you match alerts, and analysing generated content quality each rest on your consent (Art. 6(1)(a)), and each can be withdrawn without affecting the rest.
5. Analytics, and what it does not see
This section applies only if you accepted analytics. If you declined or have not answered, nothing described here happens.
5.1 What we use, and why
Microsoft Clarity, provided by Microsoft Corporation. We use it to find the places people get stuck — a button nobody can find, a form people abandon halfway. We do not use it to build a profile of you, and it plays no part in matching, scoring or any decision about you.
Clarity records session replays: a reconstruction of a visit, including pointer movement, clicks and scrolling. It is a more revealing technique than counting page views, which is why it is worth being exact about its limits.
5.2 What is excluded
Everything behind sign-in is masked. Your profile, your CV, the job descriptions you paste, the letters and CVs drafted for you, and everything on your drafts and account pages are excluded from the recording. Clarity can see that a page was visited and where the pointer went; it cannot see the text.
That exclusion is applied in this application's own code, on every page inside the signed-in area, not as a setting in a dashboard somebody could switch off by mistake.
The pages that are recorded in full are the public ones: the home page, the sign-in screen, this policy and the terms. There is nothing personal on them beyond what you type into the sign-in field, which is masked as a form input.
5.3 Where it goes, and for how long
Microsoft processes this data outside Switzerland and the EEA, including in the United States. That transfer relies on the European Commission's Standard Contractual Clauses together with the Microsoft Data Protection Addendum, and on our own assessment of the destination.
Clarity retains what it collects for up to 13 months. We do not export it, combine it with your profile, or use it to identify you. We could not link a recording to your account even if we wanted to, because the recorded pages are the ones you see before signing in.
5.4 Withdrawing
Turn it off at /cookies and nothing further is recorded. Recordings already made age out on Microsoft's retention schedule; if you want them removed sooner, write to support@earlihire.com and we will ask Microsoft to delete them.
5.5 Advertising
We run none. No advertising network, no remarketing, no conversion tracking, no affiliate pixels, and no sale or sharing of personal information for advertising purposes. If that ever changes it will be a new version of this policy and we will ask you again rather than assume.
6. Automated processing
6.1 Job matching
Every posting is scored against your profile by a deterministic calculation — a weighted combination of skill overlap, role similarity, location, seniority, language, contract type and salary fit. No language model judges you. The same profile and posting always produce the same score, and every score comes with a breakdown naming what matched and what did not.
Matching ranks and annotates what you see; it never hides a posting. Search returns everything that matches your filters regardless of score, so you are never confined to what the system thinks suits you.
We make no employment decision about you. We are not an employer and we do not screen candidates on an employer's behalf.
6.2 Drafting documents, and what is sent for it
Reading an uploaded CV, and drafting a cover letter or a tailored CV, are done with the help of a third-party AI inference provider. This happens only if you have granted the document-drafting permission, and only at the moment you ask for it.
What is sent has your identifying details removed first.
When you upload a CV, we find and strip out your email address, phone number, postal address, and any web or social links before the document is sent. They are held on our own servers and written back into your profile afterwards, so you still get your own contact details in your profile without the provider ever having received them.
When you ask for a cover letter or a tailored CV, what is sent is a fact sheet built from your profile — job titles, employers, locations, dates, achievements, education, certifications, skills and languages, together with the job description. Your name, email address, phone number, home address and links are not part of it and are not sent.
One limit, stated plainly rather than left for you to discover. A name has no fixed pattern the way an email address does. If you have already told us your name, we remove it from an uploaded CV before sending. On a first upload, before we know your name, a name written in the document may reach the provider along with the rest of the text. If you would rather that never happened, enter your name in your profile before uploading, or build your profile by answering questions instead of uploading a CV.
Where it goes. The provider operates outside Switzerland and the EEA, so this is a transfer of personal data abroad. It takes place under the European Commission's Standard Contractual Clauses together with our own assessment of the destination, and the material transferred is limited to what is described above. Your right-to-work status, your contact details and the raw uploaded file are never included.
We do not permit your material to be used to train models.
Generated text is checked against your profile before you see it: claims that do not trace to something you actually wrote are rejected and the draft is regenerated. Every draft is editable, and nothing is ever sent to an employer by us. Applications go to the employer directly, through their own site.
7. Where your data is kept
- Servers in Switzerland, on infrastructure we operate.
- Uploaded CVs are encrypted at rest with AES-256-GCM. The key is held separately from the files.
- Backups are encrypted, retained 14 days, and stored on the same infrastructure in Switzerland. We hold no off-site copy, so backups create no further transfer abroad.
- Database access is restricted to the application and to named operators.
What encryption at rest does and does not do, stated plainly because it is routinely overclaimed: it protects the data if a disk, a snapshot or a backup is taken away from the running system. It does not protect against someone who compromises the running application, which must be able to read your files in order to work.
8. How long we keep it
These are enforced automatically, not by policy alone:
| Data | Kept for |
|---|---|
| Match history | 180 days |
| Inactive accounts | Warned at 540 days, deleted at 730 days |
| Sign-in codes | 15 minutes |
| Sessions | 30 days, or until you sign out |
| Your cookie choice | 12 months, then we ask again |
| Analytics recordings, if you accepted | Up to 13 months, on Microsoft's schedule |
| Text extracted from an uploaded CV | Deleted as soon as you apply the import |
| Records of operator access to your data | 24 months |
| Consent records | 3 years after the account closes, as evidence of what was agreed |
| Your profile and documents | Until you delete them or the account |
9. Your rights
You can exercise these yourself, immediately, from your profile page:
- A copy of everything (Art. 15, Art. 20) — a single download containing your profile, documents, match history, consent record and the log of every AI generation made for you. Machine-readable JSON.
- Correction (Art. 16) — the profile editor.
- Deletion (Art. 17) — removes your profile, documents and uploaded files. You are signed out immediately; the files are removed by the next nightly sweep. It cannot be undone.
- Withdrawing a permission (Art. 7(3)) — the toggles on your profile.
For restriction (Art. 18) or objection (Art. 21), write to support@earlihire.com. These need a person to consider them and are recorded as requests with a one-month response deadline.
If you are not satisfied with how we have handled your data, you may complain to the Federal Data Protection and Information Commissioner (FDPIC) in Bern. If you are in the EEA, you may instead complain to the supervisory authority where you live or work.
10. Who else sees your data
| Recipient | What they get | Why |
|---|---|---|
| Third-party AI inference provider (outside Switzerland/EEA) | Your career facts and the job description, with contact details removed as described in §6.2, at the moment you request a document | Generating that document |
| Email delivery provider | Your email address and the message | Sign-in codes and match alerts |
| Microsoft (Clarity, US) — only if you accepted analytics | How the public pages are used: pointer movement, clicks, scrolling, page addresses, approximate location from your IP, browser and device. Never anything from a signed-in page (§5.2) | Finding where the site is confusing |
| Our infrastructure provider | Encrypted data at rest | Hosting |
We do not sell your data. We do not share it with employers. An employer cannot see that you exist on this service, and nothing you do here is visible to your current employer.
11. Operator access
Staff can see operational information — whether your import failed, how complete your profile is, whether alerts reached you. This does not include the text of your CV, your summary or your achievements.
Reading your actual personal data requires a deliberate action with a stated reason, and is recorded — who looked, when, at what, and why. That record is shown on your account page in the operations tools, so any operator can see who else has looked at you. We keep those records for 24 months.
12. Security
- Sign-in is by a six-digit code sent to your email address. We never store a password, because we never ask for one.
- Only keyed hashes of session tokens and sign-in codes are stored. A code allows five attempts and then stops working.
- IP addresses are stored only as salted hashes.
- The session and cookie-choice cookies are
HttpOnlyandSameSite=Lax, so page scripts cannot read or alter them. - Uploaded files are encrypted at rest; transport is over TLS.
- Backups are encrypted and verified nightly.
If a breach occurs that is likely to result in a risk to you, we will notify the FDPIC — and, where GDPR applies, the relevant supervisory authority within 72 hours of becoming aware — and we will tell you directly where the risk to you is high. The data protection contact in §1 is responsible for that assessment and for the clock.
13. Changes
Each consent you give is stamped with the policy version in force at the time, so we can always tell what you actually agreed to. If we change this policy in a way that affects what you agreed to, we will ask again rather than assume.