RecruiterLog
Legal

Privacy Policy

Last updated: 7 September 2026. Effective from 14 July 2026.

RecruiterLog publishes how employers actually treat applicants. That means personal information is not incidental to what we do, it is the material. This policy sets out exactly what we hold, why, who else sees it, what we publish, and what you can make us do about it.

Who We Are

Bitrora, trading as RecruiterLog, is the responsible party (in other regions, the data controller) for the personal information described here.

Our lead privacy law is the Protection of Personal Information Act 4 of 2013 (POPIA). If you are in the European Economic Area, the United Kingdom, or a United States state with its own privacy statute, the regional sections near the end of this policy give you the additional rights that apply to you.

What We Collect

If You Are a Candidate

  • Your name and email address, and a profile photo if you upload one.
  • Your CV, as a file and as the text extracted from it, plus anything you write in a cover message.
  • Your structured profile: headline, summary, work history, education, skills, links, desired roles, workplace preference, salary expectations, availability, and city and country. We do not ask for your street address, your date of birth, or your phone number.
  • Every application you make through us and how the employer responded, including timestamps, the pipeline stage, and whether the reply window was met.
  • Reviews and ratings you leave about an employer, and any messages you exchange with a recruiter through us.
  • Your rewards activity: points, badges, referrals, giveaway entries, and Brand Academy course results.
  • Your privacy choices, including whether your name is anonymised on public records and whether your profile is discoverable in Candidate Search.

If You Are a Recruiter or Agency

  • Your name, work email, job title, and the company you belong to.
  • Your professional profile: bio, LinkedIn URL, previous companies, sectors, employment status and history with the company on our platform.
  • Billing information. Card and bank details go straight to our payment providers and are never stored on our systems; we keep the plan, the amounts, the invoices and the last four digits our provider returns.
  • If you choose to become a Verified Recruiter, the identity information described under Special Categories below.
  • If you connect an ATS or a calendar, the access credentials for that connection, held encrypted, and the candidate records you choose to pull in.

Everyone

  • Log data. IP address, browser type and version, pages visited, timestamps, and referring page. If something errors, technical detail about the failure.
  • Device data. Device type, operating system, and browser settings your device reports.
  • Approximate location. Derived from your IP address at country level, used to choose a default currency and payment method. We do not collect GPS location.
  • Cookies and similar technologies. Listed individually in our Cookie Policy.
  • Support correspondence. What you send us and what we reply.

Special Categories of Personal Information

Some information carries a higher level of protection under POPIA and equivalent laws. We collect two kinds, and only in the circumstances described.

Identity documents and a biometric liveness check. Only if you choose to become a Verified Recruiter. You submit a government identity document, or consent to a check against a national identity database, together with a short selfie video used to confirm a live person is present. This is processed on our behalf by Sumsub, an independent identity verification provider. We ask for your explicit consent first, the check is entirely optional, and declining it costs you nothing except the verified badge. We receive the outcome, the country, the method used, and the reason for any rejection. We never receive or store the images themselves.

Whatever is in your CV. A CV is a free-form document. Yours may mention health, religion, union membership, nationality or other protected characteristics, and if it does we will hold that information because you sent it to us. We do not ask for it, we do not extract it into structured fields, and we do not use it to rank or filter you. If you would rather it were not on our systems, remove it from your CV and upload the CV again.

We do not collect racial or ethnic origin, political opinions, religious beliefs, sexual orientation, health information or criminal records as data points in their own right, and we do not ask you for them anywhere on the platform.

Why We Process It, and On What Basis

Every use below is tied to a lawful basis. Where we rely on legitimate interests, we have weighed our interest against your rights and only proceed where yours are not overridden.

  • To run your account and provide the service. Necessary for the performance of our contract with you.
  • To take payment and prevent payment fraud. Necessary for our contract, and for compliance with financial and tax obligations.
  • To publish the Public Ledger and compute employer reply-time statistics. Our legitimate interest, and the public interest, in an accurate record of hiring conduct. See the section on what we publish for exactly what appears and what does not.
  • To operate AI features you invoke. Necessary for our contract where you ask for the output; legitimate interest where the feature protects the platform, such as content moderation.
  • To verify a recruiter's identity. Your explicit consent, which you can withdraw.
  • To keep the platform safe and detect abuse. Our legitimate interest, and compliance with our legal obligations.
  • To send you service messages about your own account. Necessary for our contract. These are not marketing and cannot be switched off while your account is open.
  • To send marketing. Your consent, given at signup or later, withdrawable at any time from any such message.
  • To run giveaways and rewards. Necessary to perform the promotion you entered. Separate terms are in our Sweepstakes Rules.
  • To produce aggregate market statistics. Our legitimate interest. This output is aggregated and does not identify you; see Aggregate Data below.
  • To comply with law and to establish or defend legal claims. Compliance with a legal obligation, and our legitimate interest.

We do not sell your personal information. We do not build advertising profiles from your applications, your CV or your messages.

What We Publish, and What We Do Not

Our Public Ledger is a public page. This is the part of the service most likely to surprise you, so it is set out in full.

Published for each record: the employer, the role title, the recruiter named on the listing, the stage reached, how long a reply took or whether the reply window was breached, the date, and the review text and ratings if you left any.

Your name is masked by default. Public records show an abbreviated form rather than your full name. You can choose to un-mask yourself in your Privacy and Consent Controls, and you can change that back.

Never published: your CV, the file it came in, your cover message, your email address, your contact details, your salary expectations, your messages with a recruiter, and your structured profile. Those are visible to the employer you applied to, and to you.

Recruiters are named because accountability for a reply is the point of the record. If you are a recruiter who has left a company, your departure is recorded and your open work is handed to a colleague; records of what happened while you were there remain, because deleting them would falsify the history.

If you believe a published record is factually wrong, report it from the record itself or contact us. We will investigate and correct or remove it where it is wrong. Correcting the record is a right, not a favour.

Publication to the Solana Blockchain

This section describes processing that cannot be undone, so please read it even if you skip the rest.

Once a record has settled and can no longer change, we compute a cryptographic fingerprint of the conduct facts in it, combine all of that day's fingerprints into a single value, and publish only that single value to the Solana public blockchain. Anyone can then check that a record was not altered after the fact.

  • No personal information is published on the blockchain. Not your name, not the masked form of it, not the employer, not the role. A fingerprint is a one-way value and cannot be reversed into the record.
  • One value covers an entire day of settled records, not one entry per person.
  • What is published cannot be deleted by anyone, including us. That is what makes it evidence.
  • Erasure still works. Each record's fingerprint depends on a secret value stored only beside that record in our own database. Delete the record and that secret goes with it, which permanently strips the published fingerprint of any way to connect it to anything. The published value stays; its link to you does not survive.
  • If you are a Verified Recruiter who chose to hold your credential in your own wallet, your wallet address and the fact and method of verification are published on-chain, because you asked us to issue it to you. Your identity documents are not.

AI Features and Automated Processing

We use AI in the product. Where it touches your personal information, this is what it does.

  • CV parsing and rewriting. Turns your uploaded CV into structured fields and can produce a cleaner version for you to download.
  • Applicant triage and match insight. Produces a suggested ranking and a match summary to help a recruiter read a large pile of applications.
  • Scout. Our in-product assistant, which answers questions using our own Help Centre content and, for a signed-in user, that user's own data.
  • Outreach drafting. Drafts a message a recruiter then edits and sends.
  • Content moderation. Screens job postings and chat messages for prohibited content before they publish.

These features are provided using Anthropic's models. Your inputs are sent to Anthropic to generate the output and are not used to train any model, ours or theirs. Data obtained through a Google Workspace integration is additionally never shared for model training, in line with the Limited Use requirements below.

No decision about you is made by a machine alone. A triage ranking is a suggestion presented to a recruiter, who decides. Our Ghost Index and reply-time statistics are arithmetic on recorded timestamps, not predictions, and they describe employers rather than candidates. An account is only suspended or banned by a human.

Where any automated processing does have a significant effect on you, you may ask for a human to review it, contest the outcome, and receive an explanation. Write to us and we will do that.

Aggregate and Anonymised Data

We produce market statistics: reply times by sector, salary bands, hiring volumes and similar. These are computed across many records and published or licensed, including through our Data Partner API. They are aggregated so that no individual can be identified, they contain no CV content and no personal identifiers, and re-identifying an individual from them is prohibited by the Data Partner terms. Once data is genuinely anonymised it stops being personal information and this policy stops applying to it.

Who Else Sees Your Information

We share personal information with the service providers below, each for a stated purpose, under contract, and only with what they need. This is the full list, not an illustrative one.

  • Supabase. Database, authentication and file storage. Holds essentially everything described in this policy.
  • Vercel. Application hosting and delivery. Processes requests and log data.
  • Stripe. Card payments in US dollars. Receives your billing details directly.
  • PayFast. Instant EFT and card payments in South African rands. Receives your billing details directly.
  • Sumsub. Identity verification for Verified Recruiter only. Receives identity documents and the liveness check.
  • Anthropic. The AI features listed above. Receives the inputs to those features. No training use.
  • Google. Sign-in with Google, Calendar sync if you connect it, reCAPTCHA on protected forms, and Google Analytics.
  • LinkedIn. Sign-in and profile import, if you choose it.
  • OneSignal. Browser and mobile push notifications, if you enable them.
  • Telegram. Only if you opt in to job alerts on that channel.
  • GetTerms. Our cookie consent manager. Stores your consent choice.
  • The Solana public network. Receives only the daily fingerprint described above.
  • Greenhouse and Lever. Only when a recruiter connects their own ATS, and only for that company's own candidate data.

Email is sent from our own mail infrastructure rather than a third-party marketing platform.

We also disclose personal information where we must: to courts, regulators and law enforcement where the law requires it or to establish, exercise or defend legal claims; to our professional advisers under duty of confidence; and to an acquirer if our business is bought, in which case that acquirer takes on this policy.

We do not sell personal information, and we do not disclose it to debt collectors or credit bureaux.

International Transfers

We are based in South Africa and our providers operate internationally, so your personal information is processed outside South Africa, principally in the United States and the European Union, depending on the provider. Where we transfer personal information across a border we do so on a lawful basis: your consent where required, the necessity of the transfer to perform our contract with you, or a written agreement with the recipient that upholds a standard of protection substantially similar to POPIA, together with the European Commission's Standard Contractual Clauses where the transfer is from the EEA or the United Kingdom.

How Long We Keep It

  • Account and profile data: for as long as your account exists.
  • Application records: while your account exists, because they are the record the service is built on. Deleting your account removes them.
  • CV files and extracted text: until you replace or delete them, or close your account.
  • Identity verification outcomes: for as long as the verification is relied on, then for the period we must keep proof that a check was carried out.
  • Billing and tax records: for the period tax law requires, which is longer than your account may last.
  • Support correspondence: up to 3 years.
  • Log data: up to 12 months.
  • The published on-chain fingerprint: permanently, as described above, with the link to any record severable and severed on deletion.

Before we permanently delete an account's data we give you at least 30 days from notification to export it, unless immediate deletion is required for legal, security or fraud reasons.

Security

We protect personal information with measures appropriate to its sensitivity: encryption in transit, row-level access rules in the database, encrypted storage of any third-party credentials you entrust to us, mandatory multi-factor authentication for administrative access, and a single pinned administrative identity. Payment card details never touch our systems.

No system is perfectly secure, and we will not claim otherwise. You are responsible for the strength and secrecy of your own password. If a breach occurs that creates a risk to you, we will notify you and the Information Regulator as POPIA requires, and any other regulator we must.

Your Rights

Wherever you are, you can ask us to do all of the following, free of charge, and we will respond within 30 days.

  • Access. Get a copy of the personal information we hold about you, and be told where it came from and who we shared it with.
  • Correction. Have inaccurate or incomplete information fixed. This includes a published record you believe is wrong.
  • Deletion. Have your information deleted, subject to what we must keep by law.
  • Objection. Object to processing based on legitimate interests, including publication of a record, and we will stop unless we can show compelling grounds that override your objection.
  • Portability. Get your data in a machine-readable form. Candidates can also download their own CV and profile from the dashboard at any time.
  • Withdraw consent. Including for marketing, identity verification, and optional cookies, without affecting anything done lawfully before you withdrew.
  • Human review. Of any automated processing with a significant effect on you.
  • Not be discriminated against for exercising any of these rights. We will not withdraw service, change your price, or degrade what you get because you asked.

To exercise any of these, write to support@recruiterlog.com or use recruiterlog.com/contact. We may ask you to confirm your identity first, so that we are not handing your data to someone else.

Complaints. Tell us first and we will investigate and respond in writing. You can also complain to a regulator. In South Africa that is the Information Regulator, at inforegulator.org.za. In the EEA or United Kingdom, your national data protection authority. Nothing requires you to come to us first.

Children

RecruiterLog is for people aged 18 or older, matching our Terms and Conditions. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete the account and its data. If you believe a child has given us information, tell us and we will remove it.

Cookies and Tracking

Every cookie and local storage item we use is named individually, by category, in our Cookie Policy, along with how to refuse the optional ones. Analytics is optional and consent-based, and is denied until you accept: until then Google Analytics stores nothing on your device. Strictly necessary cookies are not optional, because the service cannot run without them. We run no advertising tags at all.

Google API Limited Use

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google Workspace integrations, including Calendar, is never used to train, fine-tune or improve any AI or machine learning model, and is never shared with our AI provider for that purpose.

Regional Rights: South Africa

POPIA gives you the rights listed above, and in addition: the right to be notified that we are collecting your information and if it has been accessed unlawfully; the right not to have your information used for unsolicited direct marketing without your consent; and the right to institute civil proceedings for a breach. Our Information Officer is contactable at the address above. You may lodge a complaint with the Information Regulator using its own complaint form.

Regional Rights: European Economic Area and United Kingdom

If the GDPR or UK GDPR applies to you, our lawful bases are named in the section on why we process. In addition to the rights above you have the right to restrict processing, and the right to lodge a complaint with your national supervisory authority. Transfers out of the EEA or United Kingdom rely on the Standard Contractual Clauses, a copy of which we will provide on request. Where a decision is based solely on automated processing and has legal or similarly significant effects, you may require human intervention; as set out above, we do not make such decisions by machine alone.

Regional Rights: United States

This section applies to residents of California, Colorado, Connecticut, Delaware, Florida, Oregon, Texas, Utah and Virginia, and any other state with a comparable statute. A reference to one state's law applies only to residents of that state.

Categories we collect. Identifiers (name, email, account identifier, IP address); commercial information (purchases and subscription history); internet activity (interactions with our service); geolocation at country level; professional and employment information (your CV, work history, applications); visual information (a profile photo you upload, and for Verified Recruiter only, an identity check performed by our provider); and inferences drawn from the above, such as suggested role matches. The purposes are those set out in this policy.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We ran a Meta advertising pixel until September 2026, when it was removed; nothing has replaced it and we run no advertising or cross-site tracking tag today. There is accordingly no sharing for you to opt out of. Should that ever change, we will say so here and provide the opt-out before the tag runs. We honour a Global Privacy Control signal regardless, as a refusal of every optional category.

Your rights. To know what we collect and the specific pieces we hold; to delete it; to correct it; to opt out of sharing for advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these. Exercise them at the contact details above. You may use an authorised agent, and we will verify their authority.

Shine the Light. California residents may request the categories of personal information we disclosed to third parties for their own direct marketing purposes in the previous calendar year. We do not make such disclosures, and will confirm that in writing on request.

Business Transfers

If our business or assets are acquired, or if we wind up, personal information may transfer with the business. Any acquirer is required to assume this policy for information transferred to it, and we will tell you if the transfer changes who is responsible for your data.

Other Sites

We link to sites we do not run, including employer websites and our providers. We are not responsible for their privacy practices, and this policy stops applying the moment you leave ours.

Changes to This Policy

We may update this policy to reflect changes in the product, our providers, or the law. Changes are posted here with a new date at the top. If a change is significant we will tell registered users by email. Where the law requires your consent for a new use, we will ask for it rather than assume it.

Contact Us

Bitrora, trading as RecruiterLog
Head office: Cape Town, South Africa
Information Officer: support@recruiterlog.com
recruiterlog.com/contact