Privacy Policy
Last updated September 29, 2026
The short version: MagflowAI is built for independent recruiting firms to turn resumes into anonymised candidate briefs. We never store the resume file, the candidate's name, email or phone number — there is no column in our database to put them in. What we do store is described below, in full, with no part of it hidden in a separate document.
1. Who we are
MagflowAI ("MagflowAI", "we", "us") provides a web application, at magflowai.com, that recruiting firms use to generate anonymised candidate submission documents. This policy covers the main application, the free tools at /tools, and the marketing site. It applies to two different groups of people, and it says clearly which parts apply to which:
- Firm users — the recruiters, admins and owners who create an account and use the product. We hold real account data on these people, described in Section 2.
- Candidates — the people whose resumes a firm user uploads. We deliberately hold almost nothing on these people, described in Section 3.
- Website visitors — people who give us an email address before creating an account, for example through a pop-up offering a free resource. We hold that email (and a name, if given) so we can send what was offered — described in Section 2.
2. What we collect
From website visitors, before you have an account
If you give us your email address on the marketing site — for example through a pop-up offering a free resource — we store that email (and your name, if you give one) and use it to send you what was offered and to let you know about MagflowAI. See Section 6 for the marketing tool we use to send that.
Account and firm data
- Email address, hashed password (we never store or can retrieve your plaintext password), name, role.
- Firm name, branding (logo, colours, chosen document style) if you set any.
- Billing information — handled entirely by Stripe. We store your Stripe customer and subscription IDs and your plan status; we never receive or store your card number.
- Usage data: when you signed in, how many briefs you've generated, which features you've used.
Client (hiring company) data
If you add a client — a company you submit candidates to — we store what you enter about them: name, a contact name and email, and any notes you write. This is your business data, entered by you, about companies, not candidates.
Feedback you give us
If you respond to an in-app check-in prompt or otherwise send us feedback, we store your rating and any comment you write, tied to your account, and it is reviewed directly by our team.
Support messages you send us
If you contact us through the in-app support form, we store the subject and message you write, tied to your account, and email a copy to our team so we can reply.
3. Candidate data — the part we deliberately don't hold
What we do store, once a firm user generates a brief, is the anonymised output itself:
- A professional headline (e.g. "Senior Backend Engineer"), stripped of any name.
- A profile summary, strengths, achievements, work history and education — written to exclude names, employer names (replaced with industry descriptions), contact details and any other directly identifying detail.
- The original file's name as uploaded (e.g. "resume_final_v2.pdf") — kept only as a reference label inside the firm's own workspace, since it sometimes contains a name. We recommend firms rename files before upload if this is a concern; it is never shown to anyone outside the firm.
This anonymised content can still, in principle, be identifying in a small labour market or a very unusual career history — anonymisation reduces re-identification risk, it does not mathematically guarantee it is impossible. Firms remain responsible for using judgement about what they share and with whom.
4. How we use what we collect
- To provide the service: generate briefs, render documents, manage your account, team and billing.
- To secure the service: detect and prevent abuse of the free trial (see Section 7 for what this involves), rate-limit the free public tools, and protect accounts from unauthorised access.
- To communicate with you: transactional emails (invites, receipts, password resets) and, if you respond to a check-in, to act on your feedback.
- To send marketing email: your trial welcome sequence, and — if you gave us your email before signing up — the resource you asked for and occasional updates about MagflowAI. Every marketing email includes an unsubscribe link.
- We do not sell personal data. We do not use candidate resume content, or firm data, to train any AI model of our own.
5. Legal basis for processing (GDPR)
If you are located in the UK or EEA, or process personal data of people who are, this is the basis we rely on for each category:
| Processing | Legal basis |
|---|---|
| Providing the account and generating briefs | Performance of a contract with you |
| Billing and subscriptions | Performance of a contract; legal obligation (tax/accounting records) |
| Fraud and abuse prevention (Section 7) | Legitimate interest — preventing free-trial abuse that would make the product unsustainable to offer |
| Transactional email (invites, receipts) | Performance of a contract |
| Check-in feedback you choose to submit | Consent — you decide whether to respond |
6. Who else sees your data (subprocessors)
We use a small number of specialist providers to run the service. None of them are permitted to use your data for their own purposes.
| Provider | What for | What they see |
|---|---|---|
| Vercel | Application hosting and compute | All request traffic passes through it, as with any host |
| Neon (Postgres) | Database hosting | Everything stored in our database, described above |
| Stripe | Payment processing | Your card and billing details — we never receive these ourselves |
| Resend | Transactional email delivery | Recipient email address and message content for emails we send you |
| MailerLite | Marketing email — your trial welcome sequence, and delivery of any resource you request before signing up | Email address, and name if you give one |
| Our AI processing provider | AI text generation — turns extracted resume text into an anonymised brief | The extracted text of the resume you upload, transiently, for the duration of one generation request. See Section 7 — this is the one subprocessor that necessarily sees pre-anonymisation resume content, because it is what performs the anonymisation. |
7. International transfers
We have not requested Zero Data Retention on our AI provider account. If your firm handles particularly sensitive candidate data and this matters to you, contact us — this is a request we can make on your behalf, or you can ask us to hold off using MagflowAI for that specific data until we have. We can confirm which specific provider we use on request — it isn't a secret, we just don't tie this page to one vendor's name so it doesn't need an edit every time our infrastructure does.
If you are a firm subject to the UK GDPR or EU GDPR and this matters to your own compliance obligations — for example, because you submit candidates who are EU or UK residents — please contact us at the address in Section 13 before relying on MagflowAI for that data, so we can discuss it with you directly rather than you discovering it after the fact. This page is not a substitute for your own legal advice on whether our safeguards meet your specific obligations.
Vercel and Neon host infrastructure in the United States (specifically, our primary database region is AWS us-east-1). Stripe and Resend similarly process data as US-headquartered providers with their own international-transfer safeguards in place.
8. How long we keep things
| Data | Retention |
|---|---|
| Resume file / raw text | Not retained at all — discarded at the end of the request that generated the brief |
| Generated anonymised briefs | Deleted automatically after your firm's configured retention window (default 90 days, adjustable in Settings), by an automated daily job |
| Account data | Kept while your account is active, and for a limited period after closure for legal/accounting purposes |
| Free-tool results (used before signing up) | 24 hours, then permanently deleted whether claimed or not |
| Signup-throttling records (IP hash only) | 30 days, used only to detect rapid repeat signups |
| Check-in feedback | Kept as internal product feedback unless you ask us to delete it |
| Support messages | Kept as an internal support record unless you ask us to delete it |
| Email given before signing up (via a pop-up or similar) | Kept in our marketing tool until you unsubscribe or ask us to delete it |
9. Your rights
Depending on where you are, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Object to or restrict certain processing
- Receive your data in a portable format
- Withdraw consent, where processing is based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these, email us — see Section 13. We will respond within 30 days.
10. Security
Covered in full on our Security & data handling page. In short: passwords are hashed (never stored in plaintext or reversible form), all traffic is encrypted in transit, access to firm data is scoped and isolated per firm in every database query, and card payment details never reach our servers at all — Stripe's own hosted checkout handles that.
11. Cookies
We use a small number of strictly-necessary cookies — to keep you signed in, and to remember that you've unlocked a password-gated page. We do not use analytics, advertising or tracking cookies of any kind today. Full detail on our Cookie Policy.
12. Children's data
MagflowAI is a business tool for recruiting firms and is not directed at, or knowingly used to collect data from, children. We do not knowingly collect personal data from anyone under 16.
13. Changes to this policy
If we make a material change — particularly to Section 6 or 7 (subprocessors and international transfers) — we will notify account owners by email before it takes effect, not just update this page silently.