Updated 23 September 2026

Privacy policy

This policy describes the personal information Krinoa collects, why we collect it, and who else receives it. It applies to the website, the signed-in product, and sign-in with Google or Microsoft. It does not describe companies we do not control. Your use of Krinoa is also covered by our terms.

1. What this policy covers

Krinoa is a hiring product. An employer (a workspace) uses it to post jobs, read applications, and write to candidates. Krinoa is responsible for team accounts, including an account created with Google or Microsoft. The employer is responsible for the applications it receives.

A candidate can also open a separate Krinoa account at /me to see applications they have sent. That account is described on the candidate privacy notice. Applying to a job does not create it.

2. Information we collect

We collect information in four ways.

Information you give us

  • Account details: your name, email address, and, if you set one, a password. We store a hash of the password, not the password.
  • Workspace details: the workspace name, the jobs you post, the people you invite, and the messages you send.
  • Anything you type into a form, including a support email to privacy@krinoa.com.

Information from Google or Microsoft

If you choose Google, Google sends us your name, email address, and profile photo, and tells us whether it has verified that email. We do not request Gmail, Google Calendar, Drive, or Contacts.

If you choose Microsoft, Microsoft sends us the same basic profile: your name, email address, and profile photo, and whether that email is verified. We do not request Outlook, your calendar, OneDrive, or your contacts.

We use that profile to create your Krinoa account, to sign you in, and to show your name and photo to people in your workspace. We store it with the account. We do not sell it, use it for advertising, or use it to train a model.

Krinoa's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Our use of information from Microsoft is limited to providing the account, under the Microsoft APIs Terms of Use.

Information a workspace holds about candidates

When someone applies, the workspace stores their name, email, phone, location, links, résumé, answers, cover letter, messages, and interviews. If a screening model is turned on, each read also keeps the score and the text the model was shown. One workspace cannot see another's candidates.

Information collected automatically

A session cookie keeps a team member signed in. A separate cookie keeps a candidate signed in at /me for thirty days. Server logs may include the page requested, the time, and a browser type. The applicant's IP address is hashed for rate limiting and is not stored on the application.

3. How we use information

  • To create and secure your account, and to sign you in.
  • To run the product: careers pages, the pipeline, mail, scheduling, and the command line.
  • To produce a read when a workspace has a screening model turned on. The output is a draft for the people in that workspace. Krinoa does not decide who is interviewed, rejected, or hired.
  • To answer a request you send us, and to keep the service reliable.

4. Who else receives information

We share information with service providers that perform a function for Krinoa, and only for that function.

  • Google, when you sign in with Google. Google Cloud, when a workspace has a screening model turned on: the job text, the résumé, the cover letter, and the answers.
  • Microsoft, when you sign in with Microsoft.
  • The mail provider this deployment uses, either Cloudflare or an SMTP server, for mail the product sends.
  • Meta, only if a workspace connects WhatsApp and the candidate has opted in: the phone number and the message.
  • Cloudflare, only if the apply form's captcha is on: the challenge token and the client IP.
  • Vercel, which hosts the product and counts anonymous pageviews on the marketing site, the docs, and the signed-in app. That count does not run on a careers page.
  • PostHog, only if the operator has turned product analytics on. It does not record clicks, typed text, or sessions.

We may also disclose information if the law requires it, or to protect the service and the people who use it.

5. Cookies

The marketing site does not set an analytics cookie. The signed-in product sets a session cookie so you stay signed in. The candidate account at /me sets its own cookie, for thirty days. You can clear cookies in your browser. The product will ask you to sign in again.

6. How long we keep it

We keep account information for as long as the account is open. Automatic deletion of closed applications is off until a workspace sets a retention window. The text a model was shown is removed after four years. An anonymised record of the score can remain, with the candidate's words removed.

7. Security

We use HTTPS, access control by workspace role, and hashed passwords. No method of transmission or storage is perfectly secure. You are responsible for the Google or Microsoft account you sign in with, and for the people you invite into a workspace.

8. Your choices

A candidate can export or delete what one employer holds from that application's page, and can delete their Krinoa account at /me. Deleting that account does not delete applications an employer still holds.

There is no button yet to close a team account. Email privacy@krinoa.com to close it, or to ask for a copy of what we hold about you. You can also disconnect Krinoa from your Google or Microsoft account in that provider's own security settings. Disconnecting it there does not by itself delete the Krinoa account.

9. Children

Krinoa is a hiring tool for employers. It is not directed at anyone under 16, and we do not knowingly collect information from children.

10. Changes

When this policy changes, the date at the top changes with it. The version on this page is the current one.

11. Contact

Privacy questions and deletion requests: privacy@krinoa.com.