Privacy policy
Scoutfy is hiring software operated by Katsiaryna Andryianava, a sole trader (autónoma) registered in Spain ("we", "us"). This page explains what personal data Scoutfy handles and what your rights are — written for the two kinds of people who use it: candidates applying to a job, and employer users running hiring in a Scoutfy workspace. Privacy questions: [privacy contact email].
Effective 25 July 2026.
If you applied to a job (candidates)
The company whose job you applied to — the employer — decides why and how your application is handled. Under the GDPR the employer is the data controller of your application; Scoutfy stores and processes it on the employer's behalf and instructions as their data processor. The employer is responsible for its hiring decisions and for the lawfulness of its own recruitment — including any data it adds about you outside the apply form and how long it keeps applications.
What we collect. Exactly what you enter on the application form: your name, email address, resume file, and optional cover letter — plus the time you applied and your acknowledgment of the automated-review notice. Applying requires no account and no password. Re-applying to the same job with the same email updates your earlier application rather than duplicating it, once you confirm the update from a link emailed to that address (the held re-submission is deleted after 7 days if never confirmed). We never collect data about you from other sources, social profiles, or the web.
The automated review. After you apply, an automated system reads your resume, your cover letter, and the job description, and prepares a suggestion for the hiring team: a category, a fit score, and an explanation of matched and missing requirements. To produce this, those documents are sent to Anthropic, our AI provider (see subprocessors below); Anthropic does not use them to train AI models. The system only suggests — a person on the hiring team makes every decision about your application, and nothing is ever rejected or filtered automatically. How the AI works explains this in plain language.
Who sees your application. The hiring team at the company you applied to, and us only as strictly needed to operate and support the service. Your data is never sold, never used for advertising, and never used to train AI models.
Emails you may receive. A confirmation when you apply, a private link if you ask to track your applications, and messages a person on the hiring team chooses to send you. Nothing else — no marketing.
Tracking your applications. If you request a tracking link at /track, we verify your email and show you your own applications and their current stage, across every company you applied to through Scoutfy. This uses a signed cookie that lasts 30 days, shows nothing beyond what the employer would tell you by email, and we act as the controller of this verification service.
How long it is kept. For as long as the employer keeps it — the employer sets retention and instructs deletion, and legal retention duties differ by country. Ask the employer about their retention period. If you tick the optional "keep my application on file" box when applying, the employer may keep and consider your application for other roles for up to 24 months from that consent; deleting your data from the tracking portal withdraws it.
Your rights. You can ask for access to your data, correction, deletion, restriction, objection, or a portable copy. Address requests to the employer you applied to — they control your application and make the decisions; we assist them in fulfilling your request. You can also complain to a supervisory authority: in Spain the AEPD (www.aepd.es), or the authority of your own country.
If you use Scoutfy at work (employer users)
For your account we are the data controller.
What we collect. Your name, work email, company, and role; sign-in sessions (Scoutfy is passwordless — you sign in via emailed magic links, so there is no password to store); and the content you create while hiring (comments, scorecards, stage changes), which belongs to your company's workspace. Server logs (IP address, browser type) are kept briefly for security. We use this to provide the service under our contract with your company, to meet legal obligations such as invoicing, and in our legitimate interest of keeping the service secure.
Billing. Subscriptions are paid through Stripe. Your card details go directly to Stripe — we never see or store them; we keep your company's subscription status and invoice history.
Email. Transactional only: sign-in links and notifications about candidates assigned to you, with one-click unsubscribe for notifications. No marketing.
Abuse screening of the email you send candidates. Email your company sends to applicants through Scoutfy passes an automated check for fraud — requests for payment, credential phishing, and other misuse of a hiring pretext. The check is automated and reads every such message; a member of Scoutfy staff sees the content only where a message is flagged, and only to decide whether to act on it. We do this in our legitimate interest, and yours, in keeping the service and its recipients safe from fraud, and it is part of the acceptable-use terms your company agreed to. Nothing is suspended automatically — a person decides, and the decision is recorded.
Cookies
Scoutfy sets essential cookies only — the ones that keep you signed in and protect forms — and no tracking or third-party cookies of any kind. That is why there is no consent banner: none is required for essential cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
session_id | Keeps employer users signed in | Until sign-out |
_scoutfy_session | Blocks forged form submissions | While the browser is open |
candidate_account_id | Keeps candidates signed in to application tracking | 30 days |
cookie_notice_dismissed | Remembers you closed the cookie notice | 1 year |
locale | Remembers the language you picked | 1 year |
Subprocessors
We use a small number of service providers to run Scoutfy:
| Provider | What for | Where |
|---|---|---|
| Anthropic | The automated resume reading — resume, cover letter, and job description are sent to its API; not used for AI model training | USA |
| Stripe | Subscription payments — card details are handled entirely by Stripe | USA / EU |
| Fly.io | Hosting the application and database | USA / EU regions |
| [Email provider — to be confirmed before launch] | Delivering sign-in links and application emails | — |
International transfers
Some providers above are in the United States. Where data leaves the European Economic Area, the transfer is protected by the EU–US Data Privacy Framework where the provider is certified, and otherwise by the European Commission's Standard Contractual Clauses.
Security
All traffic is encrypted in transit (TLS). Access to candidate data is scoped to the employer's own workspace, employer accounts are role-based, and departed team members are deactivated with their API credentials revoked automatically. If a breach ever affects your data, we will notify the affected employers without undue delay so they can meet their obligations, and notify authorities where the law requires it.
Changes
If this policy changes materially, we will update this page and its effective date, and notify employer accounts by email.
Draft pending legal review — this policy describes the product accurately but has not yet been reviewed by a lawyer.