Privacy Policy

Last updated: June 2026

1. Scope

This Privacy Policy explains what personal data Sourced AI Inc. ("Sourced", "we") collects, how we use it, and the choices you have. It applies to visitors, Hiring Companies, and Candidates of the Service at sourced.la. For data we process on behalf of a Hiring Company (e.g., notes they take on a Candidate), the Hiring Company is the controller and their own privacy policy applies.

2. Data we collect

  • Account data. Email, optional name and profile photo, Google account ID if you sign in with Google, IP address, browser metadata.
  • Candidate profile data. The original CV file you upload, plus the data we derive from it: work history, education, skills, English level (CEFR + evidence), salary expectation, country, city, optional photo.
  • Candidate contact details. Email, LinkedIn URL, phone — stored separately and revealed to a Hiring Company only after they unlock your profile.
  • Hiring Company data. Company name, role descriptions you submit, searches and unlocks you perform, notes and shortlists you create.
  • Usage data. Pages viewed, searches, clicks — to operate and improve the Service.
  • Billing data. Stripe processes card details; we see only the last four digits and billing country.

3. How we use it

  • Authenticate you and operate the Service.
  • Match Candidates with Hiring Companies — including AI parsing, summarization, classification, and search.
  • Reveal Candidate contact details to a Hiring Company after that Hiring Company has unlocked the Candidate.
  • Send transactional emails (sign-in codes, receipts, unlock notifications).
  • Detect abuse, debug, and improve product quality.
  • Comply with applicable law.

We do not use Candidate data to train Sourced's own machine-learning models without explicit opt-in. We do not sell personal data.

4. AI sub-processors

We send relevant snippets of profile and query data to: OpenAI (parsing, embeddings), Anthropic (Claude — agent reasoning), Google Gemini (parsing, summarization), and AssemblyAI (audio transcription for any voice features). We use enterprise/API tiers where the provider does not train on our data. Each sub-processor is bound by a data-processing agreement.

5. Other sub-processors

  • Supabase (US) — database, auth, storage.
  • Vercel (US) — hosting and edge functions.
  • Stripe (US) — payments.
  • Resend or equivalent (US) — transactional email.
  • Sentry or equivalent (US/EU) — error monitoring (PII scrubbed).

A current sub-processor list is available at legal@sourced.la on request.

6. Sharing

  • With Hiring Companies. A Candidate's full profile and contact details are shared with a Hiring Company after the Hiring Company unlocks that Candidate. Once unlocked, the Hiring Company becomes an independent controller of that copy of the data and may use it to evaluate and contact the Candidate for roles at the Hiring Company. Hiring Companies are contractually prohibited from reselling Candidate data, using it to train ML models, or sharing it with third parties unrelated to the role.
  • With service providers. As described in Sections 4 and 5.
  • For legal reasons. When required by law, court order, or to protect rights and safety.

We do not sell personal data and do not share it for cross-context behavioral advertising.

7. Cross-border transfers

Candidates are in Latin America; the Service and most sub-processors are in the United States. Where required by local law (Argentina Law 25.326, Brazil LGPD, Mexico LFPDPPP, Colombia Law 1581, Chile Law 21.719), we use Standard Contractual Clauses and obtain consent at sign-up for the transfer.

8. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, port it, restrict processing, or object to processing. To exercise any of these, email legal@sourced.la. We respond within 30 days.

California residents: you also have CCPA/CPRA rights to know, delete, correct, and limit the use of sensitive personal information, and you have the right to non-discrimination for exercising those rights.

9. Retention

  • Active Candidate profile (derived data from your CV: work history, education, skills, English level, salary expectation, AI summary and highlights, contact details): retained while the account is active.
  • Original CV file uploaded by the Candidate: retained while the account is active so Hiring Companies who have unlocked the Candidate can download it. The Candidate may delete the file from their account at any time; deleting the file does not remove the derived profile data.
  • Account closure / deletion request. Both the original CV file and the derived profile data are removed from active systems within 7 days and purged from encrypted backups within 90 days.
  • Records already shared with a Hiring Company via unlock. Once a Hiring Company has unlocked a Candidate, they hold an independent copy of the profile and any downloaded CV file. That copy is governed by the Hiring Company's own retention policy and is no longer under Sourced's control. Closing your Sourced account does not retroactively delete those copies.
  • Hiring Company accounts: retained while active and up to 7 years for billing and tax records (US IRS retention floor).
  • Search-event logs: 12 months.

10. Security

TLS in transit, encryption at rest, principle-of-least-privilege access, RLS at the database layer, audit logs. No system is 100% secure; we will notify affected users of a breach as required by law.

11. Children

The Service is not directed to anyone under 18. We do not knowingly collect data from children.

12. Changes

Material changes will be announced by email or in-product notice at least 14 days before they take effect.

13. Contact

legal@sourced.la — for any privacy question or data-subject access request.