Legal
Privacy Policy
Last updated: 12 August 2026
Short version. Employers use InstaCruit to screen job applicants. If you applied for a job and were invited to an InstaCruit interview, the employer decides what happens to your application, and InstaCruit processes your data on their instructions. Your interview audio, video and transcript are sent to AI providers to produce a transcript and a written assessment. InstaCruit does not decide who gets hired. Interview recordings are deleted automatically 15 days after the interview.
1. Who we are
InstaCruit is an AI recruitment platform operated by a limited liability company registered in the United States (referred to here as "InstaCruit", "we", "us"). We provide software that employers use to screen job applicants using AI voice interviews, asynchronous video interviews and resume analysis.
Registered entity name and address: Miracle Offers LLC, 340 S Lemon Ave #3696, Walnut, CA 91789, United States.
Privacy contact: [email protected].
2. Controller and processor roles
InstaCruit is a business to business service. Our customers are employers and recruitment teams. This split matters, because it determines who you should contact about your data.
- Candidate data. The employer that invited you to apply is the data controller. They decide why your data is collected, how it is assessed and how long they keep it in their own systems. InstaCruit acts as a data processor and only handles candidate data on that employer's instructions.
- Employer account data. For the accounts of the recruiters and hiring managers who sign in to InstaCruit, and for billing data, we act as a controller.
- Website visitors. For people who simply browse our marketing site, we act as a controller.
If you are a candidate and you want your data corrected or deleted, the fastest route is to contact the employer you applied to. You can also contact us directly and we will act on the request or route it to the employer.
3. Data we process
Employer account data
- Name, work email address, organisation name, job title and role within the account
- Authentication data held by our auth provider, including password hashes and any two factor authentication factors you enrol
- Organisation settings such as branding, session timeout and integration configuration
- Billing contact details and subscription state. Card details are handled by Stripe and never reach our servers
- Product usage records such as interviews started, credits consumed and API calls
Candidate data
- Name, email address and, where provided, phone number
- Resume or CV file and the text extracted from it
- Free text information such as experience, education and skills, where the employer records it
- Audio of a live AI voice interview, and video and audio of a recorded interview session
- Asynchronous video answers recorded by the candidate for each interview question
- Interview transcripts
- AI generated output: an overall score, a written summary, listed strengths and weaknesses, per criterion assessment scores with reasoning, and suggested follow up questions
- Numerical embeddings derived from resume and job text, used for semantic matching and search inside the employer's own account
- Application status and stage within the employer's pipeline, plus notes and tags added by the employer's team
- Technical metadata generated by taking the interview, such as timestamps and the IP address recorded when an interview session starts
We do not ask candidates for special category data such as health, ethnicity, religion or biometric identifiers, and the platform has no field for it. Interviews are open ended conversations, so a candidate could volunteer such information in an answer. Employers are responsible for the questions they configure and for not soliciting information they are not allowed to collect.
We do not perform facial recognition, identity verification from imagery, or emotion inference during live interviews. Optional behavioural analysis of asynchronous video answers is available to employers as a paid, per response action and runs only when an employer explicitly triggers it.
4. How we collect it
- Directly from candidates. Through the employer's application form, the interview lobby and the interview itself. Candidates enter their own name, email, phone and resume, and record their own audio and video.
- From the employer. Employers can add candidates manually or import them in bulk, and they can connect their existing applicant tracking system so that candidate records sync into InstaCruit.
- Generated by the service. Transcripts, scores, summaries and embeddings are produced by the platform from the material above.
Before a live interview begins, the candidate must grant camera and microphone permission in the browser and tick a consent box confirming that they consent to the session being recorded for evaluation purposes. The interview cannot start until both are done.
5. Purposes and legal bases
Where the GDPR or UK GDPR applies, the legal bases below are the ones we or our customers rely on. Because the employer is the controller for candidate data, the employer is ultimately responsible for confirming its own legal basis.
| Purpose | Legal basis (Art. 6) |
|---|---|
| Providing the platform to the employer under our agreement with them | Contract, Art. 6(1)(b), between InstaCruit and the employer |
| Assessing an application, producing transcripts and written assessments | Legitimate interests of the employer in evaluating applicants, Art. 6(1)(f), or steps prior to entering a contract, Art. 6(1)(b) |
| Recording interview audio and video | Consent, Art. 6(1)(a), collected in the interview lobby before recording starts |
| Account creation, authentication and support for employer users | Contract, Art. 6(1)(b) |
| Billing, invoicing and fraud prevention | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c) |
| Service security, abuse prevention, debugging and operational logging | Legitimate interests, Art. 6(1)(f) |
| Responding to enquiries sent to our published email addresses | Legitimate interests, Art. 6(1)(f) |
A candidate can withdraw consent to recording at any time by leaving the interview or by contacting the employer or us. Withdrawing consent does not affect the lawfulness of processing that already happened, and it may mean the employer cannot complete the screening step.
6. AI processing
Candidate material is sent to third party AI providers. Specifically:
- Live voice interviews. The candidate's browser connects directly to the OpenAI Realtime API over an encrypted WebRTC connection using a short lived session credential minted by our server. Candidate speech is streamed to OpenAI, and OpenAI generates the interviewer's spoken replies.
- Recording. Separately from the AI conversation, the session is recorded through LiveKit and the resulting file is stored in our Supabase storage.
- Assessment. The transcript and the text extracted from the resume are sent to OpenAI to produce the score, summary, strengths, weaknesses and per criterion assessment. If that request fails, the same content is sent to Google's Gemini API as a fallback so the assessment can still complete.
- Search and matching. Resume and job text is sent to OpenAI to produce numerical embeddings, which power candidate to job matching inside the employer's own account.
- The in-product AI assistant. When an employer asks the assistant a question, the records it reads to answer, which can include candidate names, application details and resume derived summaries, are sent to OpenAI. It reads only that employer's own account.
- What the providers keep. OpenAI does not train on content submitted through its API. It retains API content for up to 30 days for abuse monitoring and then deletes it, unless a longer period is required by law. Zero retention is available on approval from the provider, and this page will say so once it is in place rather than before.
- Optional video behaviour analysis. If an employer chooses to run advanced analysis on an asynchronous video answer, that video is sent to Hume AI. This is off unless the employer triggers it.
We do not train AI models on your data. InstaCruit does not build, fine tune or train any model using employer or candidate data, and we do not permit our AI providers to use data submitted through their APIs to train their models. We use these providers through their business and API offerings, under which submitted content is not used for model training by default.
7. Automated decision making
This section matters, so we are being precise rather than reassuring.
InstaCruit does not make hiring decisions. The scores, summaries, strengths, weaknesses and suggested questions the platform produces are decision support. They are shown to a human recruiter, who reviews the transcript and the recording and decides whether to advance, hold or reject the application. The platform does not extend offers, and it does not rank applicants into a final hiring outcome.
No application is ever rejected automatically. Employers can configure "knockout" questions, which are mandatory requirements such as a right to work in a given country or possession of a specific licence. If the interview record suggests a candidate did not meet one of those requirements, the platform flags the application for review and shows the recruiter the specific requirement and what the candidate said. A person then decides. The platform never changes an application to a rejected status on its own, and it never sends a rejection message to a candidate.
If you are a candidate and you believe an assessment or a knockout outcome was wrong, you can ask for human review, express your point of view and contest the outcome. Contact the employer you applied to, or write to [email protected] and we will pass the request to them.
AI assessment of candidates is regulated in a growing number of places, including New York City Local Law 144, the Illinois Artificial Intelligence Video Interview Act, the Colorado AI Act and the EU AI Act. Because the employer is the controller and the deployer of the system, the employer is responsible for the notices, bias audits and disclosures those laws require of them. We provide the underlying tooling and the records they need. We do not provide legal advice.
8. Retention
- Interview recordings: 15 days. A daily job deletes the stored audio and video file for any completed or cancelled interview that is older than 15 days, and clears the reference to it. This runs automatically and is not something an employer has to remember to do.
- Transcripts and AI assessments. These are kept for as long as the employer keeps the candidate record, because they are the written evidence behind a screening decision. They are deleted when the candidate record or the account is deleted.
- Resumes and asynchronous video answers. Kept for as long as the employer keeps the candidate record.
- Candidate records. Retained for the life of the employer's account, or until the employer or the candidate asks us to delete them. Employers are responsible for setting a retention period that fits their own legal obligations, which in some jurisdictions require records to be kept for a defined period after a hiring decision.
- Employer account data. Retained for the life of the account. When an organisation is deleted, its candidate, interview, transcript and assessment records are deleted with it.
- Billing records. Retained by Stripe and by us for as long as tax and accounting law requires, typically seven years.
- Server and platform logs. Retained by our hosting provider on their standard rolling schedule and used only for operations, security and debugging.
9. Sub-processors
We use the providers below to run the service. Each one is bound by its own data processing terms. We will update this list before adding a new sub-processor that handles candidate data.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| OpenAI | Live voice interview (Realtime API), transcript analysis, resume analysis, semantic search embeddings, and the in-product AI assistant | Candidate audio, transcripts, resume text, job descriptions, and the records the AI assistant reads to answer a question | United States |
| Google (Gemini API) | Fallback analysis provider, used only when the primary provider fails | Transcripts, resume text, job descriptions | United States |
| Supabase | Managed Postgres database, authentication, file storage (resumes, recordings) | All account and candidate records, uploaded files, recordings | United States |
| LiveKit | Real-time audio and video transport and interview recording | Candidate audio and video streams | United States |
| Vercel | Application hosting, edge routing, logging | Request metadata, IP addresses in server logs | United States |
| Upstash (QStash) | Background job queue for analysis and integration sync | Job identifiers and payload references | United States |
| Postmark | Transactional email (invitations, interview links, notifications) | Name, email address, email content | United States |
| Resend | Fallback transactional email provider, used only when the primary provider is unavailable | Name, email address, email content | United States |
| Stripe | Subscription billing and payment processing for employer accounts | Employer billing contact and payment details. Candidate data is never sent to Stripe. | United States |
| Hume AI (optional) | Optional behavioural analysis of asynchronous video answers. Only used when an employer explicitly runs advanced video analysis on a response. | Recorded video answer | United States |
Employers may also connect optional third party integrations of their own, such as an applicant tracking system, a calendar provider or a background check provider. When an employer connects one of these, data flows to that provider on the employer's instruction and under the employer's agreement with them. We are not a sub-processor of those services.
10. International transfers
InstaCruit is operated from the United States and all of the providers listed above process data in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data will be transferred outside your country.
Where those transfers require a safeguard, we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where the UK GDPR applies, together with the equivalent terms our providers offer. Employers who need a data processing agreement with these clauses annexed can request one at [email protected].
We do not currently offer data residency in the EU. If that is a requirement for you, tell us before you sign up rather than after.
11. Your rights
Depending on where you live, you may have the following rights over your personal data:
- Access. A copy of the personal data we hold about you.
- Rectification. Correction of data that is wrong or incomplete.
- Erasure. Deletion of your data, subject to the employer's own legal retention obligations.
- Restriction. A pause on processing while a dispute is resolved.
- Portability. Your data in a structured, machine readable format.
- Objection. An objection to processing based on legitimate interests.
- Withdrawal of consent. Withdrawal of consent to recording, at any time.
- Human review. Human review of, and the ability to contest, an assessment or knockout outcome. See section 7.
How to exercise them. There is no self service privacy portal today. Requests are handled by a person. Email [email protected] with your request and enough detail for us to find your record, such as the email address you applied with and the employer or role you applied to. We aim to acknowledge within 2 business days and to complete the request within 30 days.
If you are a candidate, we will normally need to forward your request to the employer who controls your data, and we will tell you when we have done so. If you are unhappy with how your request was handled, you can complain to your local data protection authority.
We do not sell personal data, we do not share it for cross context behavioural advertising, and we do not use it for advertising of any kind.
13. Connected accounts and Google user data
You can connect your own Google or Microsoft calendar so that InstaCruit can check your availability and put interviews on your calendar. Connecting is optional, and the product works without it.
When you connect a Google account we request only these permissions, and we use them only for the purposes described here:
- See events on your calendar. Used to read busy periods so we can offer interview times that do not clash. We read the timing of events, not their contents, and we do not store your calendar events.
- Create and update events on your calendar.Used to create the interview, add the candidate as a guest, attach a video meeting link, and update or cancel that event if the interview is rescheduled or called off. We only create and modify events that InstaCruit created.
InstaCruit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not use Google user data to serve advertising, we do not sell it, and we do not transfer it to third parties except as needed to provide the feature you asked for, to comply with the law, or as part of a merger or acquisition with notice to you. No human at InstaCruit reads your calendar data except with your explicit permission, to resolve a support issue you raised, for security purposes, or where the law requires it.
Access tokens are encrypted at rest. You can disconnect at any time in Settings, Calendar, which deletes the stored tokens, and you can revoke our access directly from your Google Account permissions page.
14. Security
Data is encrypted in transit with TLS and encrypted at rest by our database and storage provider. Stored third party credentials are additionally encrypted at the application layer with AES-256-GCM. Accounts support two factor authentication using a time based one time password app. A full description of our controls, including what we do not yet have, is on our security page.
15. Children
InstaCruit is a workplace hiring tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has been submitted through the platform, contact us and we will delete it. Employers running early careers or apprenticeship hiring involving minors are responsible for obtaining any additional consent their local law requires.
16. Changes to this policy
We may update this policy as the product changes. The date at the top of the page always reflects the current version. If a change materially affects how we handle candidate data, we will notify account owners by email before it takes effect.
17. Contact us
- Privacy and data requests: [email protected]
- Security reports: [email protected]
- General support: [email protected]
Postal address: Miracle Offers LLC, 340 S Lemon Ave #3696, Walnut, CA 91789, United States
EU or UK representative under Art. 27 GDPR: we have not appointed a representative at this time. Data subjects in the EU and UK can contact us directly at [email protected] and we will respond within the statutory timeframes.